5 ms·
Protecting your password db with a physical key sounds pretty stupid. I was always wary of 2FA for exactly this reason. It's something that you can lose or dama
by atleta 4y ago
Protecting your password db with a physical key sounds pretty stupid. I was always wary of 2FA for exactly this reason. It's something that you can lose or damage. Actually, it's pretty common to kill your most used 2nd factor, your mobile.
The solution here is pretty simple: learn 2-3 strong passwords. Definitely learn the strong password for your password manager and a primary email account, that you can usually use to reset the password to all the other accounts anyway. And don't use 2FA for those. I only ever use 2FA if it is enforced by a service. The real danger of not using 2FA is in your password being stolen. (Using strong passwords protect against brute forcing them.)
Also, about the hypotheticals: offline IDs (like passport and ID card) should be relatively easy to get hold of and once you have those you can have your bank account back. You obviously don't need to know your bank account numbers (that's not a password) and you can't fake your mother's name when you submit your data to a bank (because that's part of your ID information and it's almost certainly in your ID document anyway). Otherwise yes, use a random string whenever stupid sites ask for 'password reminders' or security questions.
EDIT: fix typo.
- bergenty 4y agoYep lost my phone when I was outside the US. Couldn’t get it replaced for a month and lost all access to any accounts that had 2FA set up for that amount of time. It’s also almost impossible to get your sim replaced when you can’t show up in person and show identification I learned.
- evouga 4y agoEvery article about 2FA lists the primary email account as the most important account to secure with 2FA, precisely because it can be used to reset all other passwords. And yet interestingly when I Google "why use 2FA?" the entire first page of results lists only spurious reasons (protection against phishing, brute-force cracking, social engineering, password reuse) and not the actual reason 2FA is potentially useful for securing a single-use, strong password (protection from keylogging and MITM attacks). The thought experiment in the linked article makes it clear that using "something you own" as the second factor for your primary email account is not a good idea. I'm not sure what the best solution is, but I agree that the risk of having your single, strong email password intercepted is lower than that of losing your stuff.
- atleta 4y agoLooking at one everyone say, using backup codes and asking friends to store them (preferably on a USB drive in an encrypted password store) can be a good solution. I don't think most people need to worry about criminals (or the state) tracking down their connections and extort the backup keys from them. I would never enter my email password into anyone else's computer, though. And this is also true for all of the other important passwords too.
- Avamander 4y agoOr just print those keys out. You have other documents you are securing physically, why not those as well. Saves so much trouble and you're not keeping everything digitally in one basket.