I keep my keys in analog form - I print QR code for every service. We know how to handle valuables stored on paper.
I keep my keys in analog form - I print QR code for every service. We know how to handle valuables stored on paper.
You can store the TOTP seeds in more compact form by converting QR code screenshots to alphanumeric using zbar barcode tools.
In my experience it has difficulty parsing some QR codes created using CSS due to tiny borders between blocks. Those can be fixed by applying a small gaussian blur followed by sharpening (use imagemagick for maximum automation) to fill out the borders.
Edit: packages available in Ubuntu (zbar-tools) & Fedora (zbar), source code at https://github.com/mchehab/zbar
The app puts a no screenshot request, so you have to scan the qr code from another phone.
Without it, he has 30 seconds to login and put the code by just opening the app and looking at the code.
Not much of a feature, but might help some users
* when setting up 2FA, a website shows a QR code
* I screenshot the QR code, and print it out on an A4 sheet, with an annotation of what service it is for
* I scan the QR code from the A4 sheet on two different phones.
* Back on the website, I continue 2FA setup process only after the A4 sheet is printed, and both phones show the same codes
* The A4 sheet goes in a folder for safe keeping
* One phone goes in my desk drawer for daily use
* The other phone goes in my "go" bag that I take with me on short trips etc.
Both phones are used exclusively for Google Authenticator:
* they have no extra apps
* they have a screen lock
* they are always in flight mode
Started doing this when I got burned by having to extract GA's sqlite file from mostly-dead Nexus One over adb.