Google introduces mandatory 2-Step Verification for Google Accounts
trustcoyote.com
trustcoyote.com
The problem with 1Password 2FA is, I believe, that the 2FA itself is still gated behind your master password, in that if that gets compromised so does your supposed 2FA.
The central idea of 2FA is it's something you know and something you have. If that 1Password master password is the only thing needed to gain access then you don't really have 2FA.
Again, I don't use this feature of 1Paswword so this might not be exactly how it works.
But if so, I'm sympathetic to Google not treating it as 2FA because, well, it isn't.
As for "If that 1Password master password is the only thing needed to gain access then you don't really have 2FA." it's not, unless they get access to a device you have logged into 1Password on in the past (and thus entered your secret key [0]). For me this stays true enough to "something I have". If someone has my phone/computer AND can guess my 1Password master password then things are already pretty bleak and they already have access to whatever other 2FA app I was using (Authy/GA).
Lastly 2FA falls apart if you share an account with a significant other (or a team). In 1Password I can just move that login to a shared vault or share that login individually and everyone can log in and use 2FA. I'm not sure what the alternative would be. Sure, if a product supports multiple accounts or even multiple 2FA's (I don't think I've ever seen the latter, at least in non-enterprise settings) there is a way to do this but most apps/SaaS/etc there isn't an alternative (other than disabling 2FA).
On a flash drive/SD card, or even printed out, and then stashed somewhere safe/secure (i.e. not in an unlocked drawer next to your desk)
My threat model does not include "Nation state adversary breaks into my home and... reads the contents of the book". If I annoy the Russians enough, presumably they would just try to outright murder me.
In contrast, "Person I annoyed online plans elaborate Internet revenge" is definitely a potential threat I want to cope with, as are "Scam email claiming to be from company I have account with", "Facebook lose everybody's passwords", and so on.
Our choice is either:
* No 2FA
* Virtual, 1Password 2FA
It's better. But it's not great.
For example: if you have an application protected by password+yubikey with "remember device" enabled, after prompting for your password it may decide not to also prompt you for the yubikey, and that can be because a cookie (perhaps ANDed with some other heuristics) is taking its place. A cookie which can be trivially copied to another device, but can't be trivially memorized nor guessed, and is for that reason not a "knowable" thing. If it was considered a "know" factor, then the "remember device" feature would effectively be a "conditionally disable 2FA" feature (two "knows" are 1FA), but it's really not that, outside of describing the interim UX.
It's true, of course, that once you have created an authenticated session on a device, anyone who has compromised that device (with physical access or a software hack) can likely gain access to that session. But the authentication method still prevents unwanted initiation of sessions, which is the whole point.
Any service provider obviously needs to choose their session policies to match the sensitivity of their service, their own threat models, and the threat models of their clients. So e.g. an online bank probably shouldn't issue cookies that last for a year and are portable across IP addresses. For some services, it could be a good idea for the session to only grant less sensitive access (e.g. only read access), and still require fresh authentication for sensitive actions (e.g. transferring money).
But when I realised the 'something you have' is the password manager (actually, the data store) itself, and the 'thing I know' is my master password (and not the individual site's password) I've started using it for 2fa. I can still see how the subscription version of 1password stretches that definition though (because you don't actively have unique ownership of the data itself), which is why I use keepass now.
Just like a dongle, your pc is not immune to evil maid if left unattended. My threat model isn't inclusive of that (my threats come from the internet - I live rurally).
Requiring your phone for 2fa (google auth or sms 2fa or other) isn't a panacea either, especially if that's the device you're logging in with.
I wish Google would allow setting 2fa without a phone number...
The problem is, assuming your master password is unique (I hope so!), all of the likely vectors for exposing it also expose the database, even if it's only kept locally. Having the database only stored in one place is also quite inconvenient, of course, and any sync mechanism adds even more opportunities for it to be exposed.
My computer could very easily have a zero-day vulnerability get exploited. So could my phone. Either one would expose anything I do on it (for example: access my password database using my master password).
(My solution to this is to use a security key for as much as I can. If you're not concerned about this risk, great, but it definitely is a threat.)
Well, this is not exactly true. You need to know the master password, and you need to have the device that has the 1Password database on it. Even with the knowledge of the master password, you can't login into your $random_website account from my laptop. So even without the additional one-time 2FA codes, using a password manager that has a master password and doesn't synchronize its database, de-facto, _is_ a form of 2FA. Yes I understand that this view is controversial and that auditors will disagree.
2. You can add 2FA (well, technically 3FA if you need the secret key, master password, AND a rotating token) to your 1Password signin as well (I auth Authy for that purpose)
1Password also seems able to bypass the secret key ("If you still can’t find your Secret Key, contact 1Password Support.") which means social engineering, phishing, and/or credential stuffing attacks are viable.
If you care about this, consider security through compartmentalization provided by Qubes OS. I store my passwords in plain text in an offline VM (with hardware virtualization).
Granted that if you put your TOTP seed somewhere else outside the password manager, you technically achieved "3FA"(1Password master password + 1Password private key + TOTP token) and it is more secure. But I don't think putting TOTP seed and password together in the same password manager weakens 2FA?
To login to a website:
- Without a password manager, your 2 factors are account password + account TOTP.
- With 1Password, your 2 factors are 1Password master password + 1Password private key.
I personally have all my MFA codes in 1Password, but 1Password is protected with my Yubikey. In the unlikely event that a bad actor did acquire my master password, they wouldn't get far unless they also physically had my hardware security key.
Another benefit is that I'm much less likely to lose my U2F dongle as it's on my physical keychain (and has been, for years, without damage) than I am to need to replace or wipe my phone (although a password manager with 2FA codes in it also avoids this).
A FIDO authenticator is actually a USB HID class device, like a keyboard‡. So, if your $WORKPLACE doesn't allow you to plug in keyboards then, OK, I guess maybe a FIDO dongle isn't worth trying, but few people are in that situation.
If your employer has a policy of specifically issuing and authorising only particular devices (e.g. you can pick from a list of 3 Dell branded keyboards and 2 Logitech keyboards and anything else needs HR director override) then seems like it's time for them to authorise and issue a nice high quality FIDO authenticator. Yubico make some eye-wateringly expensive models, maybe they should pick those.
‡ "Like" a keyboard but it isn't a keyboard. The FIDO protocols don't involve keypresses, the device is just HID class because well, it's a Human Interface Device, seems legit. It sets protocol to 0xFF custom, and needs dedicated software to use that, which is fine.
I have not, and it's frustrating that Google offers no support beyond their help pages for their own branded hardware.
For our iPhones, the NFC has worked fine even without the Smart Lock app. I believe Google phased Smart Lock out some time ago but I've not tried using it in a while, I don't use an iPad very often.
At least one of each of our devices is always stored at home in a safe place, where we store other valuable documents. If either of us lose one device, we will buy a new U2F dongle, enroll the new dongle, and unenroll the old lost/missing/stolen dongle from each of the services we use.
You can't backup a U2F dongle but so far everywhere I've enrolled to use one it always recommends you enroll at least 2 and keep one in a safe place.
I haven't been able to get any Google Titan Key to work with any Apple device via NFC.
I use an iPhone 8.
The whole point of 2FA is to have "2" independent pieces of data to verify logins. Gating 2FA behind a single password defeats the point.
Chaining just increases vulnerability.
Indeed.
It's also why I think U2F should be mandatory in way more places/sites/companies (it is in some, thankfully): you then need to physically have a Yubikey or similar and it's not possible anymore to trade security for convenience. It doesn't solve all security issues, but it's already a great step forward.
When you let people the choice, they'll pick the lazy, insecure, way.
If you would like your parents to have better security for these accounts, I commend Security Keys. Unless your parents aren't together any more, or are just really fervently independent, it's probably fine to buy them one each, but with the suggestion that they both enroll both keys. This way when Parent #1 loses the Yubikey you bought them, Parent #2 can use their Yubikey to save the day until a new one is purchased.
Yubico's USB A format factor "Security Key 2" is robust, but relatively expensive for what you need.
Searches for "Security Key" on Amazon or your preferred site will give you a pile of products and review feedback across price brackets, the only thing your parents are likely to care about are the connector (USB A is no use for a USB C MacBook for example) and maybe other form factor concerns like can it hang from a keychain, or would it fit in a wallet? For their purpose these things don't fill up, and shouldn't (modulo physically smashing it) wear out.
You can always buy a USB-A-to-USB-C adapter/converter. They are available everywhere, inexpensive, and if you're afraid it will be misplaced, there's always the option to glue the USB A key to the adapter...
You can fill forms and feedback but I have never heard of free users ever getting as much as a reply back.
Google doing it properly should not upset you this much.
"Your Fi number is tied to your Google Account." -- I'm sure you've seen cases of people's google accounts being randomly locked for no reason. Now you lose access to make a call too!
The last thing I'd ever trust security to is SMS. Lots of good technical details here:
https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...
If a SIM swap scam is happening and your account is locked, it is incredibly unlikely they'll be able to swap it out.
[1] https://www.zdnet.com/article/nist-blog-clarifies-sms-deprec...
> We will soon start automatically enabling two-step verification for users if their accounts are configured correctly”
And then goes on to speculate about who exactly that group of users is.
Still, worth griping about 2FA while we're here.
In a way, it is.
A lot of people joined HN searching for a higher level of discussion and thought. And HN is powered by submissions from its users.
What would be nice is if we could get more high-quality submissions to drown out the bots and other low-grade content.
Perhaps if users could filter out submissions by domain. For example, I don't mind seeing nytimes.com submissions, but I don't want to see anything from youtube.com.
But then we're just back to building yet another social media echo chamber. Yuck. Life is hard.
The inherent tradeoff with information security is convenience. For a personal account, the user should decide where they want to exist on that curve. Google's assumptions that I have perpetual access to a cellular device, or a consistent ISP, are user hostile.
I've also had this situation when relocating countries. I had to abandon a 15 year old account (for which I also had a valid working recovery email) with a lot of issues recovering online banking etc. (Had to physically travel to another country to restore multiple services associated with the account).
I'm with fastmail now. I will never again depend on a mail service that I am not paying for.
Cellular providers have laughable security when it comes to account access and changes. The easiest way to get to someone's money and digital life is to figure out their cell phone company, and then convince them to send you a new SIM card for their account. Presto, instant to their bank account and now their google account.
This is about google wanting to tie more identifying information to a google account, and (by way of making all but "install our app" incredibly annoying) force iOS users to have a Google app on their phone so they know what IP address to associate with you at all times.
I was in the process of stripping Google out of my life and this looks like excellent motivation to speed that along.
I feel like my PC is should be the source of truth for my identity, not my phone. Phones get lost, stolen, and destroyed at times and there's no guarantee that I'll have access to my phone number for the rest of my life. I'm already completely screwed if my phone number changes, because not every service offers one-time-use codes to bypass 2FA.
It is absolutely baffling that there's no desktop 2FA program that's widely used. I guess tech savvy people are using android emulators on their PC to run google authenticator, but that's such a pain.
Has anyone had luck with yubikeys for personal accounts?
I simply use Authy instead of Google Authenticator. It has a desktop app that syncs to the Authy app on my phone.
With Windows 11, you'll soon be able to run Android apps without needing to install an Android emulator, but that's not here and now, though...
As for the part of my comment in parentheses; I'm graciously awaiting the facial equivalent of "passwords in plaintext on the server". It's rather uncommon these days but I can almost guarantee it'll happen at least once.
https://sixcolors.com/post/2021/06/wwdc-2021-apple-takes-the...
Frustratingly, there is no option to add a TOTP code (like most other services, including Google, offer) or to disable SMS 2FA as a backup (despite its known security issues).
I say this mostly because I assume Apple would use your Apple ID credentials as a way to log in to these services on a Windows or Linux machine, as they do currently with the "Sign in with Apple" flow.
Could even set up rules for like "only during business hours in my country"
For anyone attempting escape, rclone seems to be the only tool that supports exporting all Google Docs ever shared to the account. Google Takeout (or the equivalent GAFYD tool) worked for everything else
Your choices are:
- Run it yourself: And get eaten alive by third party anti-spam products. Maintaining a mail server is a full time job.
- Move to another large corporation (e.g. Apple, Microsoft, et al). What have you solved exactly?
- Move to a small mail provider and hope they don't go under (and you lose your x year old email address associated with tons of stuff) or have security issues because they didn't/couldn't afford the expertise.
The "least bad" option right now just seems to be to spread yourself around, so you're not too invested in any one vendor (in particular in case they ban you randomly for reasons they won't disclose or discuss).
1. Have your own domain name.
2. Use a small-ish mail provider that supports IMAP, etc.
3. Store all your emails/folders on a device (laptop, whatever). This way if the provider locks you out or goes under, it's easy to switch to another.
Has worked since what, the 80's? Personally been doing this since before Gmail existed. Ironically I chose this route precisely because the major providers (Yahoo, etc) were too unreliable for me - I had lost accounts multiple times because some of the (then) top mail providers decided to get out of the mail business and/or regressed their featureset so much that it hurt.
Of all the Internet services, this is the easiest one for someone to own.
On the other hand they are small enough to certainly be hurt by concentrated DDoS attacks as it’s been happening the last week.
Mail provider with any small provider.
Use Thunderbird, it's honestly better that it has been in maintenance-only mode for a decade and isn't being "innovated".
You can also just use an email client that downloads the emails you get, and then point your MX-records to another provider if and when your provider goes belly up.
Sounds about right. For e-mail I'm using SES for outbound on my domain, and.. of all things.. Yandex Mail for inbound. SES doesn't seem to have any problem with spam filters, Yandex OTOH, it's definitely a temporary solution, I'm only using it for POP3, but their webmail is also fairly cute. Yandex outbound is treated as spam by basically everything except Yandex
Yeah, sure, should be.
Meanwhile I've yet to actually see one in the wild, in a 20 year career, aside from one that's used on a server I know of.
Coworkers at small tech companies? Nope. Serious-business clients coming into the office? Don't see them busting out the USB stick and plugging it in to their laptops. Medium-sized tech companies? Nope.
Hell, I'd hate it even worse than phone 2fa. I lose my actual keys all the damn time. 80% of all remote controls in our house are, at any given time, vanished to some other dimension, because I have kids. The last thing I need is another tiny, super-important physical thing to lose. The only reason a cell phone is a useful object to me, and not another annoying thing I can never find, is because of "Find My".
Enabling SMS authentication for an account is a huge DOWNGRADE in security, not an increase. Cellular providers are infamously easy to socially engineer.
1)Password alone is weak. 2)Password and SMS 2fa better. 3)Password and real 2fa best. 4)Password, real 2fa, backup codes, basically just as good as best.
Google is only eliminating #1, and only requires 2fa when logging into a new device. I’m surprised HN folks are having a tough time grasping this one, in general it’s pushing people (I’d guess 90% of people would never opt into anything more than a regular password, including the parent) into #2 above.
Parent should do #4, but #2 is fine
For me, I have to consider 2FA, or in the case of my son, who doesn't want a phone, a Yubikey or similar. I don't want to live with the additional management and potential disaster of 2FA blocking his access to his email account, which is currently his gateway to university.
At work I have 2FA, but there's a whole IT/IS team to manage and unblock things (which happens, co-workers get blocked out of their email accounts regularly).
Personally, I'm hoping to convince my domain cohorts (family) to move to Protonmail or similar.
This is a good point: For many people, passwords are already too much of a hassle. 2FA is going to be just more hassle. I manage all the passwords for everyone in my family, because they just can't manage to remember theirs (even simple ones like hunter2), and they don't want to use a password manager themselves. I'm sure ours is not the only family in the world who does this. So, the burden falls on me to keep their passwords stored and secure, and tell it to them when they need it. Now add 2FA onto that pile and it's just going to be more of a hassle for me.
Now that I only have one phone, I've turned off 2FA as much as possible, because only one phone means when it breaks, I can't access my accounts, because I can't get to the 2FA tokens. No thanks.
I keep my backup codes in a plain text files in a folder on my home NAS which is encrypted on disk, and backs up through rclone (with encryption) to backblaze every night. I'm about to configure up a second NAS for redundancy because 3 2 1.
I read them, and said, no thanks; I'd rather be able to recover my accounts easily.
Yeah, but still pretty inconvenient. I migrated all my main stuff way from Google years ago, but I have a bunch of accounts I use as throwaways that will be a much bigger PITA to use.
My "2FA Mule" has no identifying information of any kind on it and doesn't follow my location(s).
It's a stock android phone with no google account and no apps installed except for "SMS Forwarder"[1].
It is configured to forward all SMS to an email address via encrypted SMTP. This means that I can receive these 2FA codes anywhere I have Internet access - such as an airplane or newly arrived in a foreign country where my SIM card does not work.
The "2FA Mule" itself is plugged in at my office in a corner.
I'm not employing this for anything sensitive but it's interesting to consider that I can use SMS based 2FA while divorcing it from my day to day SIM identity ...
[1] https://play.google.com/store/apps/details?id=com.frzinapps....
I don't think that's an issue at all ...
I don't care about the phone - all I care about is the SIM card. If the SIM card is destroyed, your provider can issue a new one.
I guess if the 2FA mule was destroyed while I was traveling that would be a real pain but ...
(yes even as relatively "cheap" phones are these days. there was a time that $20 was a no-go for me.)
I currently use "OTP Auth" for iOS, which supports backup and encrypted cloud sync, but I'm not sure if that supports something like "export to a text file".
It is open source, maintained, easy to use, can do backups and re-present the QR code so you can easily scan it with another device.
But I don't think Google mandates you to use a phone for 2FA? You can use any TOTP app or a U2F dongle like the Yubikey (or the Ledger Nano S, which has an U2F app).
I'm a Googler, but haven't really looked into this yet.
FTFY. Though, I'd argue privacy has been dead there for years already.
I recently went through this exact scenario: Old phone broke. Bought a new one, restored backup. Guess which app doesn't restore its data from the old phone? Google Authenticator. Lost access to all my TOTP logins.
Depending on the form of second factor you use, it can stop phishing attacks (and don't say you'll never fall for one, anyone can make a mistake). The "send a notification" option for 2FA gives you information about where the login request is coming from, which is a chance to check that someone isn't sitting in the middle of login process. And something like WebAuthn makes phishing impossible outside of a browser exploit since the domains won't match.
- Hardware key (fido u2f).
- TOTP or HOTP generator (on any platform, PC, Mac, iOS, Android, whatever).
- Trusted Device.
I'm not against RFC'd TOTP , but is it possible with google?
The second factor ties me to a specific device.
It probably wouldn't go down well if Google required an Android device to provide the second factor, but I could definitely see them requiring a device which does biometric verification of the user. That's a pretty good way of connecting online activity to a specific human (assuming the attacker can gain physical access to your authentication device, and has a model of your fingerprint/face, which governments increasingly do have).
[0] https://developers.yubico.com/WebAuthn/WebAuthn_Developer_Gu...
Google Accounts are the new printers, familial-y speaking.
Basically, people should be using password managers by this point. I recommend bitwarden because you can host it yourself, it's good for storing other secrets, and it has browser plugins/apps.
Follow-up question: I downloaded Authy on my phone and my desktop, and the first thing it wants is a phone number. I'm trying to solve for not having a phone -- can Bitwarden's TOTP be used without a phone number being provided?
Thanks in advance.
The post specifically states that there are other forms of 2FA, including token based.
How do you do this? I'm looking at my personal account settings and the 2-step options are "app on my iOS devices", "security key", or "text message/voice call".
I guess there's some needles here to be threaded, whether we stay or leave Google.
Most of those tools suck. For instance I got a yubikey which has numerous flaws (not quite a regulation USB device), but the one that "EOLed" it was that the hole to attach it to a keychain wore away. A 0.25-cent nylon washer would have fixed it. Fortunately I was able to recover the yubikey rather than lose it, but it isn't on my keychain anymore.
Banks and other high-margin organizations can afford heavy reset and recovery processes. Companies like Google where customer service is "talk to the hand" can't and won't.
That means it's not 100% guaranteed one will be locked out, _provided that_ one has the tech chops. Even with such condition, is enough to totally invalidate your statement of "100% guaranteed you'll be locked out".
You probably should change your statement to say "99% of people (i.e., those withiout tech chops) will very likely -- or almost certain -- to be locked out sometime in the future". Now that new statement will be true.
Nobody is obligated to help you learn.
"Nobody is obligated to teach you self-defense."
"I tried to stop while driving but my breaks failed and I crashed into a house!"
"Nobody is obligated to teach you proper car maintenance."
"My wife's surgeon lied about his qualifications and now she's dead!"
"Nobody is obligated to teach you how to spot a quack."
IT'S NOT OUR OBLIGATION EITHER. It's Google's, to make products that don't abuse and exploit their users. Stop this bizarre gaslighting tactic. 2FA is a shitty scam system that increases complexity and failure rates, radically decreases privacy, and DOESN'T increase security because the vast majority of users will just use SMS, which is easily hacked.
It makes me wonder how many people are going to be locked out of their accounts because of these changes. So many people looking for a human. Sadly Google support is famously terrible, and 99% of queries are just Google replying back saying: 'RTFM' or 'Please refer to the FAQ for support'.
As long as I have a nice strong password, why do I need 2FA?
Also, normal people share accounts. This is a known fact. By enforcing 2FA, the provider is preventing the other users of the account access if they don't have the registered phone or yubikey type device with them.
Of course this is what they WANT. They absolutely want to force a one person, one account system, so that the data collection for advertising isn't muddled by multiple people using the account.
What I would like to see is a separation between the 'logon' and the 'service'. This would be a system where there can be multiple users accessing, say, a shared mailbox. In this way 2FA would not create a barrier for access.
Another good example would be a shared Amazon account that is used by a couple. The account is set up to pull payments from a joint bank account, if 2FA was enforced (and I'm sure it's coming to Amazon), then only one of the couple would be able to use it.
Generationally, older people are used to joint finances, and they are not all dead yet, but are being forced into a usage model dreamt up by someone who has no appreciation that the one person, one account system is not something that fits everyone.
I know my view on this is not in line with the group think on Hacker News, but it's something I feel very strongly about. Providers need to fix the multiple account user problem first, before enforcing 2FA.
Before you just think "Disagree!" and vote me down, why not reply with your viewpoint?
(I work for Dashlane which supports this, but I'm sure some other PM can also do this)
Also a lot of 2FAs are based around authenticator apps which can only be installed onto one device at a time.
2FA is a strict improvement and everyone should be using it. I applaud Google for mandating a best practice.
It's far preferable to the alternative of having your account compromised because your password is guessed or stolen.
You consider something superior just because it works for you and therefore everyone should be forced to do as you, but you ignore what doesn't work for others (such as being tied to a phone).
And as others have said, you can use another product.
So while I support asking people to reconsider if they need a Google account, I would never recommend alternatives that lack 2FA and where possible, I refuse to use services that lack 2FA myself. Unfortunately there are still some categories like banking where TOTP, FIDO, etc is practically unheard of.
I'm able to live without electricity but I'm not about to call the power company and have them cut my feed. There are folks who consider it some kind of incarceration to be beholden to the electricity provided by a power company; I respect them but I don't share their philosophy.
Unless the situation is "There is another power company right next door," I'll have to disagree.
If the claim is one can self-generate power, the analogy holds but not in the way, I think, the author means. Self-generation off-grid is a pain... Buy or build and maintain your own generators, your own storage, deal with impedance, deal with the risks of operating on high voltage, equipment breakdowns are yours and yours alone to repair, etc.
Similarly, I can self-host my own email, video, web servers, and possibly even build my own voice-activated assistants tuned perfectly to my specifications, sharing my data with nobody... But that's a lot of work when Google has provided all of that for me.
Your example is a great reason for 2FA to exist.
1. Google does not require 2FA.
2. Google DOES require 2FA on an account, but only requires the second auth if "suspicious activity" crops up.
3. Google requires 2 auths on each and every login.
On 1, if a bad actor picks up your phone and tries to log in, they will fail if you haven't saved your login, or succeed if you've been lazy and saved it. In the latter case, that's really on you (and you might still be able to get your account back even then, if they didn't fully and quickly reset password and other details!)
On 2 however, they will try to log in, fail, and trigger a lock-down that can only be lifted with both auths. One of which you don't have anymore. Congrads, you've just lost your account!
3 is the same as 2, just for different reasons. As soon as that phone disappears, you don't have the second auth, and you're screwed.
And don't even bother with anything that isn't a phone. We both know nobody in the general public is using anything other than text for this. And some older folks don't even have that! Add on to this that SMS can be easily hacked, and it's pretty clear this whole system is a joke.
In the past, wouldn't all your data still be behind a password? Am I missing something?
The irony of the matter is that I keep my OTP key in the same password manager as my google password, in order to not require a phone to access it, and this "App Password" is significantly weaker than my generated passwords...
Google's Authenticator app's data is not restored. I have no way of logging into half a dozen apps that require 2FA now. Good going, Google. I'll never use your shitty 2FA again.
Don't just blame Google. The same thing happened to me with an iPhone using Duo. Now I'm locked out of Facebook because Duo wants me to re-link my Facebook account, and I can't log in to Facebook to do the link because I can't use Duo.
To make things worse, Facebook's customer service has lived up to its reputation. Meaning my requests for access, including sending in copy of my government ID, have gone ignored.
I appreciate that 2FA is better, but this is the reason I don't use 2FA anymore.
i've been able to do this because i replicated otp set up in a second source (1password).
in 1password, edit the record then inspect the otp field string. it will look like this:
otpauth://totp/Discord:you@email.com?secret=blahblahblah&issuer=Discord
save the "blahblahblah" and you can manually recreate a token at any time.
The most ideal set up would be to have a universally Yubikey or something equivalent. Preferrably with a backup pre-configured second Yukibey possible in a disaster recovery bugout kit. Then have all the initial QR codes, otp secret manual otp key strings like i demonstrated above your post, account recovery keys, backup break-in codes, or whatever other flavor of two-factor recovery a service uses, all this notated in a secured password manager. The real problem i see with two factor is that the offered recovery method is so variable from service to service. it makes knowing which information you need to have on hand when you've gotten locked out is problematic.
the other thing i do is that for core cloud service providers, i print out the password manager details for the accounts. this is apple, cloud backup service, google, microsoft and a couple of hardware device passwords. it's a risk to have this printed, but the print out is in a fireproof safe with a trusted party.
i basically assume my disaster recovery plan is that i have my wallet and the clothes on my back and nothing else. everything else gone including my computers and phones and i have to get back all services and data without having any devices.
the higher the level of security, the higher level of disaster preparedness the end user needs to practice.
I've emailed my elderly parents to make sure they understand that this mandatory 2fa roll out is happening, and I've explained how they could fuck up their accounts by not notating the recovery method. offered to review their details to make sure it passes a sniff test.
This is the weakness of the scheme. It relies on people doing something that most people are not good at doing.
Thus there will probably be a way for the user to recover without the codes (sending in photo ID or whatever) and that will be the point of attack for anyone trying to maliciously take over the account.
Super easy to move between phones and to recover in case of disaster.
As far as I can tell, for cases where you're just using Authy in the same way as Google Authenticator (a big standard TOTP app), the only value proposition is that Authy allows separate programs with your TOTP keys in them to communicate together so that they all have copies of the same keys. It seems in those cases that Authy is storing very little and is instead acting like a dumb "connecting layer" for installations of the Authy app to talk to each other. This is nice for security, but the consequence is that if you lose access to all your Authy installations at the same time then you're SOL.
I'm inferring this merely from using Authy for years, if someone knows more about how they work, please chime in to correct me.
...
We put 2FA keys in different password manager it works great.
2. How should the tech world communicate that better so that it's more user-friendly?
The main issue is Google Authenticator and how popular it is. As GP noticed, it doesn't flag the files as being allowed for backup which is kind of ridiculous. Almost anything is better, https://getaegis.app/ is my recommendation.
You can also manually backup your seed (screenshot / save the QR code during enrollment).
That's not user friendly though. I don't see how to make a user friendly, reliable, and safe 2FA system. Not having 2FA isn't safe either!
Where Google Authenticator just doesn’t backup half your codes, leaving you in for a surprise if you lose your phone.
https://i.imgur.com/4YrElkJ.png
Keep that in mind when you e.g. go traveling.
Rather than giving users options, Big Tech has decided to paternalistically kill passwords in favor of less convenient and less secure methods (my email is much less secure than my password store). Even from residential IPs, it's become the norm for banking websites to harass you with snake oil "2FA" every time you login. The only solution is to split up your online activities so you can conform to their demands with one VM/browser config, account for the extra annoyances as the price of using their services, and move as much activity as possible to freedom-respecting technologies.
I log in all the time, this morning included, and do it every time with a simple password. I have never been prompted for 2FA and there is no identifying info in my account or in the emails that it catches. The account names are even fake.
If I do end up prompted to set up 2FA I will simply delete the whole shitteroo and start over somewhere else with another fake name.
"The company plans to automatically enable two-step verification for accounts that have been configured correctly."
But also, frankly, I just don't trust Google to implement this correctly, given their track record. Google sure employs a lot of smart people, but the quality of their products and services is generally crap.
Really? There are scratch codes for that. Or you can use an app that backs up your TOTP key for you, like Authy. Or you can store your TOTP key manually. Or you can have multiple devices. Or...
> having to run extra software
Oh, come on. Are you really complaining about having to compute an HMAC?
> I just don't trust Google to implement this correctly, given their track record.
Huh? You do know "The day Google forgot to check passwords" was fictional?
https://www.google.com/intl/en/landing/2step/#tab=how-it-wor...
I'm not sure why TOTP isn't an option. Google Authenticator still seems to be a supported app.
> The Google Authenticator app for Android, iPhone, or BlackBerry can generate verification codes. It even works when your device has no phone or data connectivity.
You can also use third party apps, I use Authy
https://webapps.stackexchange.com/questions/127464/enabling-...
Perhaps this changed now, but I had to set up a different 2FA method first (I used a U2F security key), then add OTP, and then it was possible to remove the U2F method.
After logging in with OTP once (I just keep the private key on my laptop in pass) you never seem to get asked to provide it again, but 2FA is nominally enabled.
Fortunately I do not use anything from google over 2 years, so it is not problem for me, but I cannot imagine frustrations for everyone, that needs their data from google and they are systematically forced to share more and more personal data with them.
You can also use any of the many other 2FA methods they support, like standard TOTP, a security key, or even by simply rotating a sheet of scratch codes.