But be really sure you want to do this. The main reason I would not recommend ordinary consumers do this, is that if you lose your SIM (eg, stolen or lost phone), you can go to a mobile phone shop and get a new SIM card issued to you after verifying your identity. With other forms of 2FA, you do not have access to the same real-life-based identity verification service, and it is also essentially the source of SIM-swap risk.
To mitigate the risk of losing my 2FA credentials I use the FOSS app andOTP (Aegis is similar, but better UI, from what I hear). It can export your data as both cleartext and encrypted JSON so you can import into a new phone as desired.
[0] https://www.alphr.com/transfer-google-authenticator-codes-ne...
Per my understanding, if I have Authy on my Phone, the one on my PC/laptop is the backup, and vice versa - in the sense that if one dies I can use another.
Could you elaborate on the use case.
If you have ever set one of these up with a QR code, that QR scans to something like: otpauth://totp/ACME%20Co:john.doe@email.com?secret=HXDMVJECJJWSRB3HWIZR4IFUGFTMXBOZ&issuer=ACME%20Co&algorithm=SHA1&digits=6&period=30 (From: https://github.com/google/google-authenticator/wiki/Key-Uri-...). Notice all parameters I mentioned above are present, as well as a user friendly account name.
So to directly answer your question: a backup would in some way contain all the parameters above, possibly in that otpauth:// format, but could be json or something else.
I would not consider Authy to be a trustworthy backup. I assume they are storing these secrets for you and transferring them to other computers at your request. If you can't see the secret, you can't switch to a different app. (Take this last paragraph with a grain of salt, I don't know much about authy but it sounds like trouble. I use FreeOTP and other open source OTP apps).
Then you have a physical offline backup of the TOTP secret in a QR code with error correction.
Store those sheets of paper in a folder somewhere safe.
Also consider using a yubikey for TOTP -- but do a paper backup regardless.
Fortunately my wife is primary on the account and is very much on the ball. She got texts that the SIM card had been changed and within minutes had them recover it and lock it back down. Besides "ditch T-Mobile," this might be the best piece of advice: don't be your own primary, and be sure your primary has your SIM card on extra-paranoid notify-me-instantly-if-it-changes mode.
Fortunately the first thing they were after was my Coinbase account, which they two-factored only to discover was empty. If they'd hung around a while and poked around I would have been well and truly pwned. So, second piece of advice, already said upstream: do whatever you can to avoid giving online services your phone number.
When I finally got in front of a support rep they confirmed the whole thing and (just because I was there, and large, and extremely pissed off) let me take as many photos as I wanted of the entire incident report right there on their kiosk. This by itself did not fill me with a strong sense of confidence in their opsec; third piece of advice is: anybody but T-Mobile.
Many of them don't have a separate toggle for phone-based recovery so as soon as you provide the phone you are opting-in for phone-based recovery which makes you vulnerable.
I think all services should have a specific checkbox for this option, if they insist on SMS recovery stuff.
Long story, but some time ago I managed to convince my phone provider to require a "password" when I call them. They had added a saved note against my customer record advising any support agent to ask for the password. I rarely called them but I did see it actually working when I later interacted with them and they asked me the password. I don't recommend this approach at all as it's not reliable.
And yes, I have never been rejected from a service for using a google voice number as my 2fa source. Heck, even my google account uses 2fa through the google voice number - as one option :)
* Do you use the same Google Voice number as your actual Google account phone number, or just for other sites? If the former, how does it work with Google 2FA (ie if you are logged out of Google account I imagine you can't access you Voice number either?)
* Are you concerned with losing access to your Google Voice number if Google decides to ban your account one day? Regular phone numbers seem a bit less nebulous in that phone providers don't seem to just suddenly decide to ban you and your number as much as Google, Amazon, et al. Then again I have no data to back up this impression.
* What made you pick Google Voice over another VoIP option?
* Do you worry about Voice going away with Google Fi?
* I am using same google voice number as my actual google account. I live with constant fear that if I am locked out of google account then I cannot access my voice number. Only thing I do to avoid this scenario is to have back up code written somewhere. * Trust on Google * as of now no
a) Not using my personal number for online services
b) Using a virtual number instead of a phone provider SIM
...seems worth pursuing. I think a) above is more important for me than b), but my current phone provider does not yet support eSIM and my phone does not support dual sim, and I really don't want to carry two phones around...
Of course the best answer is to not rely on SMS or voice call 2FA, but as others point out, some services only support these insecure options.
The most secure way to protect against SIM swap attacks is not to use a SIM based number for 2fa. I’d suggest using a Twilio, Telnyx, or similar service where you have more control over the number and even the porting process.
Send test sms to yourself at least twice a day
>MILES: [MUSIC] They were able to get ahold of T-Mobile and manipulate their way in through either doing it in person or doing it over the phone, and convince somebody to change out the SIM for them.
Sometimes people just like to watch the world burn...
and besides even if they get something low value as far as money that doesn't mean it's not important to me or terribly stressful
one of the things I do think can be an improvement is using virtual sim, such as twilio, then it's more manageable, get notifications, probably more secure than employee being socially engineered to give your number away...