How to Enable Two-Factor Authentication on Amazon
eff.org
eff.org
So in the end, after thinking I was all secure with this special hardware one time token generating device, it falls back to email + phone, both of which can get taken over easily.
How easy is it really for someone to intercept a phone call Amazon makes to your number?
(edit: I'm not arguing, I really don't know)
Basically the MFA in the end is a gimmick since phone and email is all you need. Carriers often can be socially engineered to forward numbers or change sims, and email obviously can be hacked. Might as well just text + email instead -- didn't need to buy this $40 device.
Which seems really odd to me. Because I know I had two separate 2FA TOTP seeds, one for AWS, one for retail.
Anyone else notice anything like this?
So something shady is going on.
https://www.amazon.com/gp/help/customer/display.html?nodeId=...
Anyone know if you can use the authenticator
app on more than one device?
Not only can you do that, you can scan the QR code in the image in the article and get the author's TOTP credentials in 'Google Authenticator'.The normal way to do phone-based 2FA is a QR code with data of the format "otpauth://totp/yourusername?secret=1F56D7AFLONGBASE64&issuer=Amazon" where the secret is the secret needed for TOTP [2] one-time code generation.
As such, you can write down the secret (or print out the QR code) and scan it into other phones (or use it with tools like oathtool on linux) and they'll then generate identical codes to your main phone.
Obviously, if you store your TOTP secret alongside your password or keep a copy somewhere that isn't safe, there's no point in using 2FA. And if people fuck this up too often 2FA users will start insisting we install twenty shit proprietary apps (one for steam, one for salesforce, one for symantec vip access....) and nobody wants that. So use your new powers with care!
[1] https://www.eff.org/files/styles/large/public/2016/12/19/ama... [2] https://en.wikipedia.org/wiki/Time-based_One-time_Password_A...
Then again, it sounds like it's really easy to disable 2FA with just a simple phone call, so...
oathtool --totp -b "key value"
where your "key value" is your secret (same thing you would get if you scan QR code). And then you just need to keep the secret safe, and you can run it on as many devices you need.
EDIT: just realized that michaelt had much more substantial comment.
* Google 2-Step Verification || https://www.google.com/landing/2step/
And for everything else...
* Turn On 2FA | Turn It On || https://www.turnon2fa.com/