4 ms·
If you use Google accounts with 2FA, please do the following: 1. Setup a backup email for recovery 2. Copy paste and save Backup Codes somewhere remote 3. If
by codegeek 4y ago
If you use Google accounts with 2FA, please do the following:
1. Setup a backup email for recovery
2. Copy paste and save Backup Codes somewhere remote
3. If you are using an app like "Google Authenticator", they have an easy way to Export the settings on another phone. Do it on your wife's/gf's/family/sibling etc phone and that way you have another backup of 2FA codes.
4. Do not use the "Google Prompt" option because that only works on primary device.
- jqpabc123 4y agoSimple solution --- don't use Google Authenticator. Google didn't invent any of this, it is fully standardized (see RFC6238). There are lots of fully compatible alternatives with better options for security and backup and restore. Personally, I use FreeOTP+ with a password lock and secret keys backed up off device. Secondary opinion, why is the Google app lacking? Because they really don't want people to use it. They much prefer you reveal your phone number and use SMS instead. This way they can easily identify you personally. Remember, everything Google does is subtly designed to help violate your privacy in some way. The quickest way to convince me not to use an app is to put a "Google" label on it.
- tgma 4y ago> Secondary opinion, why is the Google app lacking? Because they really don't want people to use it. They much prefer you reveal your phone number and use SMS instead. This way they can easily identify you personally. Sure, companies may do some evil things intentionally, but an app UI sucking is usually the default state of things and not some malice necessarily. In this case, I think part of the neglect of Google Authenticator is them trying for years to pivot to other forms of two-factor authentication that are more phishing-resistant than an OTP (Yubikey-like and smartphone based systems).
- sand500 4y agoSMS 2FA is not secure. Lots of HN posts about it: https://hn.algolia.com/?q=sms+2fa https://hn.algolia.com/?q=sms+2fa
- 2muchcoffeeman 4y agoUnfortunately it’s still better than no other factor especially for most people.
- jqpabc123 4y agoAnyone have any examples of widespread violation of OTP for 2FA --- something other one individual who gave his buddy his phone or something?
- UncleMeat 4y agoSMS 2FA is basically the same as TOTP against phishing. It is worse in that you can be hit with sim-swapping. Phishing is many orders of magnitude more common than sim-swapping. There is a real difference between these two options, but it is wildly overemphasized online. The gap between SMS/TOTP and a Yubikey or equivalent is way larger.
- mehrdada 4y agoI was not suggesting SMS 2FA when I referred to "Smartphone-based solution". I meant relying on Secure Enclave or alike on the smartphone as the second factor in a challenge-response fashion that makes the "OTP" bound to a specific domain and thus unphishable.
- sand500 4y agoSorry I didn't see the SMS part was a quote of the parent.
- jqpabc123 4y agotrying for years to pivot to other forms of two-factor authentication that are more phishing-resistant than an OTP Yes, that probably explains why they prefer OTP over SMS --- because it is more secure --- and it totally violates your privacy.
- onetokeoverthe 4y ago
- arbuge 4y agoRegarding #1: You can set a backup email address for Google accounts if they're using Google email addresses, but you can't do this if they're using non-Google email addresses as the primary address, such as the one in that link. I'm logged in to such an account right now and there's no way to do this. The account primary email is also set as the recovery email address and there's no way to add another. It's actually deceptive to the user to even call it a recovery email address in this case, since Google will never offer to alternatively send a verification code there if the 2FA device is unavailable.