9 ms·
Help me understand one thing. More and more services are moving towards 2FA/MFA. The 2nd factor is in a phone app. What happens if I lose my phone? Without my o
by ctrlmeta 4y ago
Help me understand one thing. More and more services are moving towards 2FA/MFA. The 2nd factor is in a phone app. What happens if I lose my phone? Without my old phone I cannot log into the services. How do I get access to my accounts again? How do I move the 2FA setup to new phone again? Do I have to do this one by one for all 50 2FAed services I use?
I am forever worried that if I sign myself for 2FA in 50 different services and then I lose my phone I may permanently lose access to my accounts.
- chrisseaton 4y ago> What happens if I lose my phone? Backup code (very long, one-time-use password.)
- lupire 4y ago6 digits is very long?
- chrisseaton 4y agoNo that’s the normal codes, which are time limited. A backup code could be 40 digits or something like that.
- 8organicbits 4y agoMost I've seen are 6 digits for both the TOTP and the recovery. Who is using 40 digits for an MFA recovery code?
- MiguelX413 4y agoMost services I use give several 6~8 digit recovery codes, I've never had discretion with them. I have no idea what they're talking about.
- chrisseaton 4y ago> Most services I use give several 6~8 digit recovery codes Well RubyGems itself, subject of this post, has 12 for a start.
- tialaramex 4y agoThe most you've seen for a recovery code is 6 digits? Where have you seen these "never more than 6 digits" codes ? GitHub's codes are 8 alphanumerics, Dropbox 8 alphanumerics, Live.com offers a 25 alphanumerics Google 8 numeric Facebook 8 numeric Nintendo 8 numeric Login.gov 12 alphanumerics Gitlab 16 hexadecimal I'm sure some fool somewhere used a six digit numeric "recovery code" but the usual, while it isn't 40 is certainly more than 6.
- 8organicbits 4y agoI must be mistaken, looks like 8, those are the sites I use.
- tmarice 4y agoYou probably get recovery codes you have to store somewhere. Major 2fa code apps support migration between phones, and backing up the encrypted database to the cloud.
- dsabanin 4y agoCheck out the Authy app. It lets you have an encrypted backup with which you can restore the MFA codes on another device. Another option is using a password manager with MFA capabilities, like 1Password.
- devoutsalsa 4y agoI've used Google Authenticator, Authy, and 1Password. 1Password has been far superior in my experience, the only downside being that it is a paid subscription, which won't work for everyone. My 2nd choice would be Authy. Entertaining related story... a few months ago, I tried signing up for Celsius, the crypto exchange that went bankrupt. Their sign up process required MFA, and for some reason the only app they supported was Authy. Unlike most any other site, instead of giving you a QR Code to scan, Celsius would do something weird where they have some sort of push message mechanism that's supposed to initiate the MFA setup process from within the Authy app. I never did get it to work. I have a personal rule that if the signup/signin process for a service is too arduous, I simply won't use that service if I have viable alternatives. So I didn't lose any crypto in the Celsius bankruptcy because their MFA signup processes sucked.
- _joel 4y agoI have 1password too but that seemed a little incestuous to have the password and the TOTP in the same app, it's not exactly MFA. I use Authy, personally, with backups and encryption.
- jibe 4y agoI have the same 1Password / Authy setup, for the same reason. But I have my Authy password in 1Password, so it is kind of an illusion of extra security. I’m strongly considering moving it all into 1Password at this point.
- _joel 4y agoThankfully I can just about remember 2 passwords :) Also you can use biometrics in Authy, fwiw. Then write down the password and put it in a safe. Then there's only 1 to remember but you can use biometrics in 1password too, so unless your threat model includes someone using your freshly chopped thumb then it should be ok.
- miohtama 4y agoTwo-factor reset is usually a slow manual process where the service provider checks that you are who you really claim to be. It is not automated so that it cannot be abused. If you have 50 two-factor authentication tokens you can use apps like Authy that allows you to do a local or remote back up of the tokens. TOTP is an RFC standard and you will find lots of apps for advanced users.
- MiguelX413 4y agoServices often give recovery codes too.
- __s 4y agoServices usually offer a tokens which should be saved somewhere in order to reset 2FA. I agree, requiring users to keep tokens for every service is painful (see how many people had trouble not losing their btc keys when btc wasn't particularly valuable) I've only gotten a new phone once. Was android to android. I was able to transfer everything from the old phone to the new phone as part of setup process Granted, yesterday I had some trouble: my phone service failed to process a payment, so they disabled my service. Meanwhile I couldn't go in & review my bank info because I needed 2FA in order to login.. To make matters worse, the bank told me I needed to call a number for Loss Prevention Services to reenable sending money out of my account, & made me run around a bit looking for pay phones (surprise, they were out of order) before they let me use their phone
- Hendrikto 4y ago> Services usually offer a tokens In my experience, ”rarely“ is more accurate than ”usually“.
- seized 4y agoFor SMS 2FA maybe, but I've gotten between one and ten codes for every service I've enabled proper TOTP 2FA on.
- em-bee 4y agowhat can you do now to prevent this from happening again?
- __s 4y agoI've tried putting an extra 2 months of payments on my phone plan so that if a payment doesn't go through service won't expire. Hopefully the automatic payments continue so I don't have to think about it
- 1123581321 4y agoIt’s a good question. A lot of 2FA apps have manual backup/restore functionality. Some have cloud sync (e.g. iCloud sync so your new iPhone has the same app and codes, or 1Password/Bitwarden which has you log back into the app on the new phone with their service login.) These 2FA syncs can be a point of weakness so not everyone uses them. The services themselves (rubygems etc.) also provide a short list of one-time account recovery codes. You’re supposed to essentially print them and put them in a safe. I wonder how many people both keep those codes and keep them somewhere secure…
- evolve2k 4y agoAuthy for example enable you to have a cloud backup - https://authy.com/features/backup/ https://authy.com/features/backup/ 1Password offers MFA and would still be available on your other devices if you lost your phone. As to if storing passwords with MFA codes is fine or a problem, I’ll let smarter people than me decided what’s best practice.
- 1123581321 4y agoAh, yes. Authy was the iCloud one I was thinking of. IIRC they provided plenty of warnings about the tradeoffs of enabling that.
- JoaoCostaIFG 4y agoApps like the Microsoft authenticator and freeotp+ allow you to backup your codes. With freeotp+, you can export the codes as a json file and import them in another phone in case something happens. With the Microsoft one, you save the codes in the cloud (your Microsoft account).
- Avamander 4y agoAre there any good and not ugly TOTP apps on iOS that have export/import functionality?
- deleted 4y ago[deleted]
- striking 4y agoYour second factor could be whatever you want it to be. Phone app, keyfob, TOTP program running on your machine. Many services allow for multiple options. Most 2FA apps have a convenient "move all of my codes to another device" function, offer online sync, whatever. And even if they didn't, every service provides recovery codes that you could use in case of an emergency, should you need access to some service and all else fails.
- ctrlmeta 4y agoGenuine question - Which keyfobs support scanning QR code presented by an online service to add the TOTP seed and then generate TOTP codes? Any cross-platform recommendations for TOTP program that works on Windows, Linux, Mac?
- striking 4y agoYou type the seed in. Services almost unilaterally give you the option to get a seed code instead. Even if they don't, you can scan the QR code and get the seed out of it.
- rgoulter 4y agoQR code scanning is intended for mobile phone cameras as a way of communicating a TOTP secret. When presented with a TOTP secret, every website I've seen has presented the option to show the TOTP secret as text, which can be copied across. A password database like KeepassXC can store the TOTPs. FIDO / U2F hardware like Yubikeys (or various alternatives) are also a convenient second factor.
- zerkten 4y agoMany services seem to offer one-time codes for storage offline in case this happens. Authy can working across multiple devices, but that probably has some security ramifications. Based on https://apple.stackexchange.com/questions/305372/will-my-google-authenticator-codes-work-if-i-restore-my-iphone-from-a-backup https://apple.stackexchange.com/questions/305372/will-my-goo..., you are able to restore Google Authenticator from iCloud. This is the usual security versus convenience problem. The site is forcing you to use an additional factor, but there is flexibility in how that is serviced. Choosing convenience may open paths for attackers, but the impact depends on your threat model.
- ghaff 4y agoI agree but how many people who have 2FA from Google for example have a printed out list of numbers? You can have multiple authentication devices but, again, how many people have this? And it's certainly very easy to be traveling and not have backups with you. One solution with Google at least is that they basically hardly ever require you to reauthenticate on a given device but that obviously doesn't help if the device in question breaks or is lost and is also your soft token. As you say, not an easy problem. The happy medium depends on the threat model and is somewhere between being able to easily social engineer new access and having to show up in Mountain View with a sheaf of notarized proof of identity documents.
- njarboe 4y agoI would like to have the option of only needing the password and no password reset unless you visit an office somewhere in person. For like Google, banks, brokerages, etc. But maybe that is less secure than two-factor online systems? Seems like it wouldn't be.
- ghaff 4y agoHaving to present physical, hard/expensive to reliably forge, government-issued ID at a reputable institution is a pretty good filter against most fraud. It's also a headache even if you live somewhere with a local branch of your bank. I tried to do this during the pandemic and the local bank branch didn't have anyone who could give me the right authentication so I had to spend a couple hours going to my local brokerage office to complete a transaction.
- deleted 4y ago[deleted]
- alain_gilbert 4y agoFunny thing that happened to me recently. I'm having a prepaid plan with att, and I did not pay it for a while. Recently I needed to get a text message so I went on the att prepaid website to reactivate the plan for the month so that I could get the text message. Guess what. The att website wants to send me a text message to ensure that I am the owner of the account... to my phone... that has no plan... fun times!
- DangitBobby 4y agoDid you try it? You might be able to receive messages from certain numbers.
- messe 4y agoNeeding to pay to receive texts is utterly alien to me.
- cortesoft 4y agoWhat? You can get texts to a phone without paying your phone bill?
- londons_explore 4y agoIn most countries outside North America, if you don't pay the phone bill you can still receive texts and calls. You just can't make calls, send texts or use internet. The same applies to prepaid cards - if the balance hits zero, you can only do incoming calls and texts. Obviously, the provider will still send debt collectors if you were on some fixed price per month plan, and those debt collectors will still try to collect moneys for the months the service didn't allow outgoing calls... I always thought it odd that a company was allowed by law to collect money for a service they didn't provide.
- messe 4y agoYes, if I'm on a prepaid plan? If I didn't top up, my phone would still have an active SIM and phone number. I would still be able to receive calls and texts.
- jacques_chester 4y agoFor RubyGems: 1. You get given recovery codes when you enable MFA. Each is a single-use code that stands in for an OTP code. If you kept them, you can use these to login and then change your device. 2. If you lost those too, there's a manual reset process. As you can imagine it's slow and requires careful scrutiny to guard against social engineering attacks on the rubygems.org maintainers. In future it will be possible to use WebAuthn[0] for rubygems.org and, ideally, you will be able to bind multiple hardware tokens or biometric devices to your account, so that you have backup options. [0] https://github.com/rubygems/rubygems.org/pull/2865 https://github.com/rubygems/rubygems.org/pull/2865
- joshmn 4y agoI recently (few days ago) had to do 2. None of my gems are super popular but I have enough that there are some serious production workloads behind. It felt scrutinized enough. I can imagine if I had more popular libraries that it would have been much more so.
- MiguelX413 4y agoI use the TOTP feature of Bitwarden! It syncs across all my devices including desktops. It's very nice.
- tomjen3 4y agoI personally just put them in my bitwarden, which syncs with all logged in devices.
- 8organicbits 4y agoYou got lots of answers about proactive approaches to the issue. In cases where you didn't do those, you'd contact support. If it's a bank account, they ask you security questions and then reset/remove MFA. I've done that over the phone while out of the country once. If they don't have support, or their support doesn't have an alternate authN approach, you could be locked out.
- ylg 4y agoNote that TOTP is not limited to a single authenticator. You can, for example, scan the same TOTP setup QR code once with an app on your phone and again with a different app on your laptop (or scan in one and paste the code in the other). I use this approach with Yubico Authenticator, which stores its data on Yubikeys, so I have all 2FAs on at least two keys even with TOTP-only services that seemingly allow only one authenticator per account, e.g., AWS.
- czbond 4y agoThanks for sharing that, I did not know it.
- londons_explore 4y agoYou can also screenshot the barcode and use it years later if necessary.
- ufmace 4y agoEvery service that I've seen that uses TOTP 2FA will also give you a list of fixed backup codes and strongly encourage you to keep them somewhere safe. There are also TOTP apps that will let you make a backup of your codes, to also be kept somewhere safe. Of course it's the user's responsibility to actually keep backup codes somewhere where they can definitely be accessed in case the phone is lost and also can't be stolen easily. Ditto for a app backup. Sounds straightforward, but easier said than done.
- nucleardog 4y agoOther people have given a lot of options, but I'll throw my solution in the ring. I have a _separate_ KeePassXC database where I store the original OTP secret (if you click "add manually" or "can't scan", etc when the QR code pops up... it will give you the secret that's in the QR code) and recovery codes. If I ever lose my phone/yubikey/etc, I can go unlock my "break glass in case of emergency" database and access accounts directly or recover from there. I keep this in a separate database versus, say, just putting the password + OTP secret + recovery codes all in the same Bitwarden vault because I want to maintain the full security of the second factor. If my e-mail and password for Bitwarden is enough to get you the username/password/otp then I figure it's really only protecting against credential stuffing.
- otachack 4y agoI use andOTP on Android and it has a backup feature that exports all your registered 2FAs into a file which you can import to another andOTP install. You can also export with a password on that file so it's encrypted. Other 2FA apps have backup options like Google Authenticator or Microsoft Authenticator. Bitwarden, if you pay for premium, gives 2FA as a feature and they just handle those codes. Just don't register Bitwarden 2FA under itself :D
- jacobsenscott 4y agoMost services should have a fallback. Often it is just emailing you a code, or texting a code to a phone number. This is because true, strict MFA would become a customer support nightmare - half your users would be locked out from day one. Also realize you can use more than one 2fa device. At the step where it asks you to scan a QR code, you can scan it on multiple devices. Also, you don't need to use a phone to store your codes. 1password can do this for you, and then your codes are available anywhere you are logged into 1pw. The google authenticator app allows you to transfer your codes to another phone, but you need to remember to do that before wiping your old phone.
- filmgirlcw 4y agoI use a password manager to store my credentials, TOTP codes and stored secondary codes. Yes, that does make my password manager more of a risk, but for that reason, I use a strong and unique password for the password manager, have a password manager that has its own security key that is required for access from new devices, etc. When I transfer phones, all that stuff comes with me. For worst case scenarios, I have a few spare YubiKeys setup that I can use in the event that something goes haywire. And in a safe deposit box, I have a YubiKey and a printed out copy of my 1Password emergency kit. So that if someone drives into my house and it burns down, I do have an option. But I agree that this is a lot of stuff to keep track of. That’s why I’m glad that Passkeys are being adopted by the big players (Apple, Microsoft, Google) and that we’ll see consumer rollout of this sort of thing, which should make this a lot better. There’s no such thing as a system without a threat model — and biometrics can be imperfect, but I’m much more comfortable with that or even relying on my current MFA setup than I would be using SMS 2FA or no 2FA!
- jrmg 4y agoAll the answers here boil down to “you’re right, it’s complicated, so a normal person will just completely lose access”.
- adamgordonbell 4y agoAs others are saying, you can store your TOTP code in a password manager, and if you lose you phone re-add it. You can also use something like oathtool do generate these one time passes at the command line. I had a similar question and wrote up how I'm doing it here: https://earthly.dev/blog/multi-factor-auth https://earthly.dev/blog/multi-factor-auth Oathtool: https://www.nongnu.org/oath-toolkit/oathtool.1.html https://www.nongnu.org/oath-toolkit/oathtool.1.html
- tzs 4y agoWhat I'd like to see is for sites to allow setting up two different kinds of 2FA, one of which is TOTP and the other is something hardware-based. TOTP has some limitations which make it not as secure as the better hardware-based approaches. For example if you get fooled into trying to login to a phishing site and the real site uses TOPT, all the phishing site has to do as ask you for the TOTP code. TOTP in this case only protects you from getting phished if the phishing site is just logging credentials for use later use. If they are going to use your credential right away it is no protection. If a site allows both TOTP and a hardware-based system though you can use the hardware-based system normally, and only resort to TOTP if the hardware is lost or broken, and stop using TOTP as soon as you can get replacement hardware enrolled. For TOTP when you are setting up and the site gives you the QR code, scan that in TOTP apps on your phone and if you have one on your tablet. Also save a copy of the QR code somewhere safe. I save an encrypted copy on my desktop computer. If you ever change phones or tablets, you can scan the QR code again. Some sites will also give you the TOTP key in text form. Save that somewhere safe and you can use it with command line TOTP tools such as oathtool [1]. [1] https://www.nongnu.org/oath-toolkit/oathtool.1.html https://www.nongnu.org/oath-toolkit/oathtool.1.html
- woodruffw 4y ago> What I'd like to see is for sites to allow setting up two different kinds of 2FA, one of which is TOTP and the other is something hardware-based. This is exactly what we did for PyPI: we allow the user to enroll as many 2FA factors as they'd like, of both supported types (TOTP and WebAuthn). The post is dated 2019, but the summary of practices we wrote here[1] is still relevant (and IMO, correct). [1]: https://blog.trailofbits.com/2019/06/20/getting-2fa-right-in-2019/ https://blog.trailofbits.com/2019/06/20/getting-2fa-right-in...
- mmis1000 4y agoGoogle authenticator allow you to export codes as qrcode now. You can backup it to other phone or even print it and lock it somewhere if you want.
- nathan_f77 4y agoI use the OTP Auth iOS app. I store encrypted backups of my 2FA code secrets in iCloud, and also in Dropbox. I save recovery / backup codes in LastPass (whenever a service provides them.) When possible, I will set up two or more 2FA options. I always have a small Yubikey plugged in to my laptop, and some services allow me to set up a Yubikey as well as OTP codes. I also have a backup Yubikey that I set up for all the services that support it, and keep this off-site in a safe deposit box. I also store some printed copies of critical 2FA code recovery codes, mainly for my Google and Apple accounts.
- dceddia 4y agoI recently migrated all of my 2FA logins to Raivo [0]. It's iOS-only but open source and very nicely built. The key feature that made me switch is that it can export the 2FA tokens as a backup. I got worried when I started thinking about this scenario, and realized Google Authenticator offers no way to back up the tokens. The only way out is to transfer to a new device using a QR code. They pretty much lock you in to using Google Authenticator. And, crucially, backing up the phone DOESN'T SAVE THE TOKENS. I almost learned this the hard way when I got a new phone, restored from backup, and right before I wiped my old phone I decided on a lark to check that Google Authenticator was working on the new one. The app was there, but the tokens were not. 0: https://raivo-otp.com/ https://raivo-otp.com/