12 ms·
PSA: you should ALWAYS download the recovery codes when you enable 2FA. Reading a lot of "phone broken; locked out of account" comments here and I don't know w
by danirod 4y ago
PSA: you should ALWAYS download the recovery codes when you enable 2FA.
Reading a lot of "phone broken; locked out of account" comments here and I don't know whether they understand that local one-time only recovery codes should be downloaded and stored safely (maybe even printed and stored in a safe, I do not know). If you lose access to your 2FA device, use the "recovery code" option and use one of your recovery codes to unlock your account.
- kmlx 4y agoisn't it just better to use an app such as 1Password that can keep all your one-time passwords?
- photon-torpedo 4y agoThen if the password manager is compromised, the second factor wouldn't add any protection over just a password. Then again, people that use password managers at all usually have stronger passwords and less password reuse, so it can be an acceptable tradeoff.
- tomrod 4y agoAye, but it assumes the company isn't keep the password in plain text.
- tarentel 4y agoIn my case it wouldn't anyway. Almost all of my 2FA is tied to my password manager as well. I am sure I am not alone in this. It is kind of scary to think about though.
- tuckerman 4y agoI do the same but, for me, the threat of my password manager being compromised is much much smaller than the threat me not enabling 2FA out of laziness or the concern I might lose my 2FA codes. I keep my main email codes out of the password vault and that is enough to calm my nerves. Not everyone has the same risk profile/tolerance, but I just wanted to say that I don't think anyone should feel bad about doing the best they can, even if that stops short of the absolute best.
- tjoff 4y agoThis is why passwords are still king for many of us. And that the very same reason people can't be trusted with passwords is the same as why they can't be expected to keep backups of their recovery codes. Passwords suck. But so does every form of 2FA.
- eastbound 4y agoBesides, where do you store your 2FA backup codes? At home?? Where they could be stolen without your knowledge? Most people’s homes are less safe than their online life.
- danuker 4y agoMaybe a safe or cameras would be useful for when you're not home. I sometimes leave my laptop on with motion started: https://motion-project.github.io/ https://motion-project.github.io/
- pmoriarty 4y agoYou could store them encrypted with a passphrase that only you know, so even if they're stolen they would be useless without your passphrase.
- TedDoesntTalk 4y agoYou could also encode them in DNA nucleotides and use CRISPR to modify your own DNA with your GitHub codes. /s
- bcrosby95 4y agoI would be more concerned about fire or natural disaster. If your house catches on fire while you're asleep, there's decent odds both your phone and any printed codes are gone.
- joshvm 4y agoThe historic solution is in a safety deposit box at a bank. If you're talking about things like crypto cold wallets which might be extremely valuable, why risk leaving it at home? The cost for small items like documents tends to be reasonable. Good practice for things like ownership deeds and wills. I don't think the average home thief would know what to do with a printout of your 2FA recovery code especially if it's buried in other paperwork. The real risk is loss from negligence or natural disaster.
- VWWHFSfQ 4y agoI made this mistake when I enabled 2FA for Uber some years ago. Same old story. Somehow forgot to grab my recovery codes for Uber even though I had for everything else. I got a new phone, manually transferred all my google auth codes from my old phone, somehow missed Uber. And then a few months later after I had already reset my old phone I installed the Uber app and oops, I needed a 2FA code. Couldn't get one. And because Uber is tied to your phone number I couldn't even just create a new account without getting a new phone number. So I emailed their support (which is useless), got a bunch of bot responses about how to reset your password, finally got one real person to respond after several weeks. But they had no idea what I was talking about and clearly had no ability to actually do anything about the 2FA issue. So I gave up and now I'm just permanently locked out of using Uber. Which is fine, cuz fuck 'em. Now I use Lyft exclusively. Which doesn't matter because in my experience every Uber driver is also a Lyft driver.
- pmoriarty 4y ago"they had no idea what I was talking about and clearly had no ability to actually do anything about the 2FA issue" What are they supposed to do to fix your issue without compromising their security model? What you describe sounds like 2FA working like it's supposed to.
- zackees 4y agoTheir security model locks users out. I nearly lost all my passwords with LastPass when something similar happened to me. Is grandma supposed to file her 128 character recovery code in a safe vault when she just wants to get from the airport? Stop blaming users for them not adapting to terrible authentication experience.
- pmoriarty 4y agoI'd be interested in hearing about a better model. To me they're all terrible in one way or another.
- 4y ago
- skrebbel 4y agoBut then where did the 2nd factor go? I mean how is a recovery key meaningfully different from a password, except that it's a random string chosen by the service instead of by me? Fear is being locked out is exactly why I'm reluctant to enable 2FA. To enable it and then just store the password (err, I mean, recovery key) in my password manager seems to just get me more hassle for exactly no additional security. What am I missing?
- Arnavion 4y agoThe recovery key is different because it's "locked in a safe" and used rarely, if ever, instead of being used constantly.
- skrebbel 4y agoBut.. is passwords being used a common way for them to leak? I've never heard of this before but I'm no expert. Isn't the threat model either company databases being (badly hashed and) leaked, or password managers being hacked wholesale? I mean where am I supposed to store the recovery key if not in my password manager? My dropbox surely isn't better encrypted than my bitwarden. I work with the assumption that my password manager is the least insecure piece of data storage I use. I really don't get it. How isn't 2FA just security theater if we're all supposed to store the recovery keys "somewhere safe"? Can we really expect people to deal with recovery keys in a more responsible way than they do with passwords?
- Arnavion 4y ago>I mean where am I supposed to store the recovery key if not in my password manager? My password manager (keepassxc) supports multiple databases. I store all TOTP recovery codes in a separate database (and with a different unlocking password) from the one that has regular passwords and the TOTP secrets. All my databases are backed up on someone-else's-computer, but I only keep the regular-passwords-and-TOTP-secrets database synced to my devices.
- nighthawk454 4y ago
- oicU00 4y agoFunny story, I did store my Github codes in 1pwd Years go by, I need a code, they don’t work. Github could do nothing but tell me to start a new account. Same old story; Github does not exist for you. It exists to make its workers and owners money. Whether it works or damages you is irrelevant to them. The future has no obligation to the past. Don’t expect the codes to work if they change something that deprecates the old system they used.
- jrochkind1 4y agoI'll be honest. I don't believe I have the capacity to reliably preserve, in a secure location, recovery codes from dozens of different services over many years. I suspect I'm not the only one. There is pretty much nothing else in my personal life I have to do something like this with. The closest might be my physical SSN card or birth certificate. But that's one thing to keep track of, not a new thing every week or month to add to the stash. And even those, if they get lost, there is SOME way to replace them, usually. We are asking people to do something that is not a thing they have practice at or otherwise have to do or are any good at or have the capacity for. And then blaming them when they fail to pull it off, where you're constantly getting locked out of things and/or constantly getting hacked, probably both at once. I understand passwords alone don't work. I don't have a solution. I'm just predicting a very painful digital future for most people. (My own "solution" is using Authy TOTP, installing it on multiple devices, figuring I will retain working access to at least one of these configured devices, and not bothering with backup codes. I don't know how secure it really is, or TOTP is in general, but it lets me keep using services that require it, without living in fear that I'm going to lose my phone and misplace the backup codes and lose access forever).
- jopsen 4y agoAlso print print out the QR code used to sign up for TOTP. That way it's easy to enroll a new laptop/phone/yubikey. Once printed out, put in a plastic bottle and bury it in your backyard :)