5 ms·
Something similar happened to me about a year ago when the Google Authenticator app automatically updated to a new version. I lost all my accounts in the update
by napsterbr 2y ago
Something similar happened to me about a year ago when the Google Authenticator app automatically updated to a new version. I lost all my accounts in the update process. Definitely learned a few lessons there.
- xandrius 2y agoThis nightmare is why I always backup MFA QR codes and use those to add them to an open source app which let's me backup the data elsewhere too. Sorry to hear that!
- SoftTalker 2y agoYep, any time I use an authenticator with an account I generate "backup codes" and keep them in my password manager. This saved me when I got a new phone and for some reason my Google Authenticator did not transfer to the new phone properly.
- lostlogin 2y ago> Google Authenticator did not transfer to the new phone properly. This seems to be my normal experience with a new phone for MFA apps. I’m doing something wrong. That and setting up email are so dreaded that I hold off updating.
- knallfrosch 2y agoSwitching from Android to iOS for a phone, I found that Microsoft Authenticator officially doesn't support this. You can't backup, you can't transfer. Everything is lost, please start anew.
- mook 2y agoI think they finally managed that last year, but only by syncing to your Google account: https://security.googleblog.com/2023/04/google-authenticator-now-supports.html https://security.googleblog.com/2023/04/google-authenticator... … Yeah I'm not sure that's very good for a 2FA app either. Offline backups feel better for me. I use something else for 2FA.
- alchemist1e9 2y agoI’d be interested to hear details on that. I’ve been thinking of printing QR codes as backups.
- xandrius 2y agoFor crucial stuff, I take photos first and store them on my own nextcloud (with its own replication) and also copy them on a physical device. And my Android authenticator (andOTP) allows me to export encrypted backups (with password saved on password manager, ofc), which I then save on Dropbox. If it's a MFA I actually don't care much about (security-wise), I simply save the token on bitwarden so it autocompletes for me (it defeats most of the main point of "multi" FA but I don't care about it to begin with). Printing is not a bad idea, especially for backup, if you put them in a fire-proof safe or something. Make sure to give each a name to know which service they are for.
- qingcharles 2y agoI put my TOTPs in Google and Microsoft authenticators for double-redundancy. On two separate handsets. Then I have someone else I trust implicitly scan the QRs too and have them on their phone. I've been burned too many times.