9 ms·
Sigh. Yep. Don't ever give a company your phone number for 2FA. It's insecure anyways due to SIM swapping. Stick to FIDO (e.g. yubikey) or TOTP (e.g. google aut
by ntoskrnl 4y ago
Sigh. Yep. Don't ever give a company your phone number for 2FA. It's insecure anyways due to SIM swapping. Stick to FIDO (e.g. yubikey) or TOTP (e.g. google authenticator)
- RamRodification 4y agoAny clear reason to go for Google for TOTP? As opposed to Authy or something else.
- ntoskrnl 4y agoThose were examples I thought people were likely to recognize, not vendor recommendations. I edited for clarity.
- jeromegv 4y agoNo, it's all the same.
- encryptluks2 4y agoYou do realize that TOTP is a standard that doesn't require you to use either, that you can use the same secrets for any TOTP app, right?
- RamRodification 4y agoYou did read my comment where I suggested "Authy or something else", as in any TOTP app, right?
- regecks 4y agoThere is a clear reason not to use Authy, which is that making your data portable is extremely annoying. No export function. I ended up writing a 3rd party Authy client just to get my TOTP keys out. For iOS users, I cannot say enough good things about https://apps.apple.com/us/app/otp-auth/id659877384 https://apps.apple.com/us/app/otp-auth/id659877384. Author is responsive, encrypted backups, portable data format.
- Macha 4y agoFor android users, Aegis provides much of these benefits (as does andOTP). Both are open source, I like aegis a bit better.
- SailingCactus33 4y agoandOTP has just worked for me across multiple device migrations for years. Encrypted backups to a git repo for mobile files managed with MGit.
- nicce 4y agoThanks. I have been looking replacement for Authy for quite some time because of no export function.
- RamRodification 4y agoThat's good one. Thanks.
- davis 4y agoThere's actually a very good reason to not use Google Authenticator actually. They don't offer any backups (at least on iOS) and as a result, if you lose your phone, you are hosed. Google Authenticator also doesn't use iCloud for backup for files like other apps. I also just assume at this point no one owns that app and that it'll never get backups because that's how Google operates. I've seen multiple people lose their TOTP codes this way and have been locked out of their accounts. Or even the more simple case, they buy a new phone, restore from backup and just assume everything is peachy then send their old phone back and then don't realize it until they open the app for the first time. Use something with cloud backups for your safety.
- bogwog 4y agoI got scared as hell a few years ago when an update bricked the app, so launching it caused it to immediately crash. Fortunately, reinstalling the app fixed it without losing any data. But since then I started actually backing up my recovery codes, and whenever I create a new account somewhere, I set up 2FA on three separate apps on my phone just in case.
- nicce 4y agoAuthy does not allow to make local backup (export) and it is fully closed source, not really transparent. I wish there were better alternatives.
- PausGreat 4y agoRavio OTP on iOS
- SoftTalker 4y agoThey offer one-time backup codes that can be used if a device is lost. I'm not sure if this is Google or the site, but for every login where I've set up Google Authenticator I have copied the backup codes to my password manager for that account. I'd agree that a lot of people might not do that however.
- 4y ago
- jazzythom 4y agoActually its more secure to use NFC yubikey w/ their app than google authenticator for TOTP bc the key is in the yubikey enclave vs the phones
- drivers99 4y agoI just started using that and would recommend it. When you set it up you add each key you own from the same QR code.
- cheeze 4y agoThe tradeoff is usability though. I can have a TOTP code stored on two separate phones in two separate locations versus needing a yubikey always present. To me, I'm too forgetful and dumb to not lose a yubikey, but I manage to not lose my phone.
- rvz 4y agoExactly. I did tell them many times before [0], [1]. They just won't listen. So give them a fine instead, that will make them listen. The second 'wake up call' after the last one I've seen today: [2] [0] https://news.ycombinator.com/item?id=29264937 https://news.ycombinator.com/item?id=29264937 [1] https://news.ycombinator.com/item?id=30010434 https://news.ycombinator.com/item?id=30010434 [2] https://news.ycombinator.com/item?id=31510868 https://news.ycombinator.com/item?id=31510868
- minsc_and_boo 4y agoOr just get a phone and service provider who doesn't allow SIM swapping (e.g. Google Fi, etc.), since many more services only do 2FA with SMS than allow hardware authentication.
- skybrian 4y agoYou probably want both, as well as printing out some backup codes, to avoid the risk of getting locked out when something breaks.
- sedatk 4y agoUnlike FIDO/U2F, TOTP is susceptible to phishing. Getting locked out a serious problem and should be addressed with printed recovery codes probably.
- ClumsyPilot 4y agoMy passwors manager has close to 200 records, thats a lot of peinted codes, id need a filing cabinet. What I ia m in a different country, visiting damily, and the ubikey is lost - am i locked out of everything?
- iotku 4y agoYeah I'm extra upset about this because I would have chosen TOTP if I was given the option, but only sms authentication was available for 2FA for the longest time (until it became such a big issue with account takeovers including jack's I believe that they had no choice but to change that)
- davesque 4y agoYep, it's almost more accurate to describe using phone numbers for 2FA as being anti-secure, not just insecure. That's because it's effectively no better than having no 2FA and it's possibly even harder to detect when your account has been compromised by a SIM swap. And many companies that use phone numbers for 2FA also allow resetting one's password via that phone number. It's really just a tragedy that companies do this, rather like when login screens prevent copy/paste. If you're ever prompted to add a phone number to your account on some web service for "extra security", just click "remind me later" or "skip" as many times as possible.