Google's Authenticator app's data is not restored. I have no way of logging into half a dozen apps that require 2FA now. Good going, Google. I'll never use your shitty 2FA again.
Google's Authenticator app's data is not restored. I have no way of logging into half a dozen apps that require 2FA now. Good going, Google. I'll never use your shitty 2FA again.
Don't just blame Google. The same thing happened to me with an iPhone using Duo. Now I'm locked out of Facebook because Duo wants me to re-link my Facebook account, and I can't log in to Facebook to do the link because I can't use Duo.
To make things worse, Facebook's customer service has lived up to its reputation. Meaning my requests for access, including sending in copy of my government ID, have gone ignored.
I appreciate that 2FA is better, but this is the reason I don't use 2FA anymore.
i've been able to do this because i replicated otp set up in a second source (1password).
in 1password, edit the record then inspect the otp field string. it will look like this:
otpauth://totp/Discord:you@email.com?secret=blahblahblah&issuer=Discord
save the "blahblahblah" and you can manually recreate a token at any time.
The most ideal set up would be to have a universally Yubikey or something equivalent. Preferrably with a backup pre-configured second Yukibey possible in a disaster recovery bugout kit. Then have all the initial QR codes, otp secret manual otp key strings like i demonstrated above your post, account recovery keys, backup break-in codes, or whatever other flavor of two-factor recovery a service uses, all this notated in a secured password manager. The real problem i see with two factor is that the offered recovery method is so variable from service to service. it makes knowing which information you need to have on hand when you've gotten locked out is problematic.
the other thing i do is that for core cloud service providers, i print out the password manager details for the accounts. this is apple, cloud backup service, google, microsoft and a couple of hardware device passwords. it's a risk to have this printed, but the print out is in a fireproof safe with a trusted party.
i basically assume my disaster recovery plan is that i have my wallet and the clothes on my back and nothing else. everything else gone including my computers and phones and i have to get back all services and data without having any devices.
the higher the level of security, the higher level of disaster preparedness the end user needs to practice.
I've emailed my elderly parents to make sure they understand that this mandatory 2fa roll out is happening, and I've explained how they could fuck up their accounts by not notating the recovery method. offered to review their details to make sure it passes a sniff test.
This is the weakness of the scheme. It relies on people doing something that most people are not good at doing.
Thus there will probably be a way for the user to recover without the codes (sending in photo ID or whatever) and that will be the point of attack for anyone trying to maliciously take over the account.
Super easy to move between phones and to recover in case of disaster.
...
We put 2FA keys in different password manager it works great.
As far as I can tell, for cases where you're just using Authy in the same way as Google Authenticator (a big standard TOTP app), the only value proposition is that Authy allows separate programs with your TOTP keys in them to communicate together so that they all have copies of the same keys. It seems in those cases that Authy is storing very little and is instead acting like a dumb "connecting layer" for installations of the Authy app to talk to each other. This is nice for security, but the consequence is that if you lose access to all your Authy installations at the same time then you're SOL.
I'm inferring this merely from using Authy for years, if someone knows more about how they work, please chime in to correct me.
2. How should the tech world communicate that better so that it's more user-friendly?
The main issue is Google Authenticator and how popular it is. As GP noticed, it doesn't flag the files as being allowed for backup which is kind of ridiculous. Almost anything is better, https://getaegis.app/ is my recommendation.
You can also manually backup your seed (screenshot / save the QR code during enrollment).
That's not user friendly though. I don't see how to make a user friendly, reliable, and safe 2FA system. Not having 2FA isn't safe either!
Where Google Authenticator just doesn’t backup half your codes, leaving you in for a surprise if you lose your phone.