I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.
I'd also suggest not to rely on a phone number as 2nd factor, it's not that super safe.
Well, I have my PayPal account set up with a strong unique password and 2FA via an authenticator app. Recently installed the PayPal app on my smartphone, and it asked for CAPTCHA, password, 2FA token, and then additionally SMS to an old phone number I still had on file. How does it make sense to ask for 3 factors? At any rate, I logged in on the computer and updated the phone number. Still wouldn't let me log in on the smartphone, needed to contact customer support.
Look, I understand that many people choose bad passwords and they get pawned and all, and I'm glad that the providers are a bit smarter and use other factors (cookies, IP, phone number...), but it really penalises security and privacy conscious users. If you use strong passwords and 2FA, but use VPNs, switch phone numbers, clear cookies, etc., you get flagged and locked out. Very annoying.
I just wanted to recommend Aegis as an alternative to Google Authenticator. It allows backing up codes to an encrypted (password protected) file. Plus it's FOSS.
A single password manager should only be used to store TOTP secrets alongside passwords if you're comfortable with both of them being accessed from the same devices. It's possible to store your TOTP secrets in a Bitwarden account or a KeePass file, and your passwords in another account or file, hosted/stored in different locations.
[1] https://bitwarden.com/pricing/business/
2. If you get a new device, you need to un-enrol and re-enrol in all 2fa providers with g authenticator - it's a nightmare. Very hard if the old device got fatally dropped in a pool! I know at least with Authy you can carry the tokens to a new device.
This is relatively new - a few years ago Authenticator did not support this.
Oh, and make sure before you use the emergency device, time is synced - codes won't work otherwise.
Thanks, this was around when my device went for a swim.
I use Authy these days.
https://android.stackexchange.com/questions/20899/why-does-t...
[1] https://github.com/andOTP/andOTP
I'm not impressed with Authy's privacy policy, especially this part which mirrors the Google issues:[3]
> We use the information we gather from you to monitor for unusual or suspicious activity in your account, to communicate with you about your account, and as additional information that can be used to validate who you are if you need to recover your account or your account has been or may be compromised.
Authy also collects and shares more of your private information than most OTP apps:[3]
> When you use our app we collect: Your phone number, device information, and email address.
> We also share your information with our third party service providers as necessary for them to provide their services to us. We may also have to share your information with third parties if required to do so by law.
> Your information will be transferred to the U.S.
my fall-back is Microsoft Authenticator.
HN outrage at Kafkaesque account lock-outs makes me imagine bureaucrats complaining about an approval requirement they themselves created. It is frustrating and I know data loss can be devastating. If people in the tech community individually follow basic security procedures, that helps us further discover pain points in the work toward better security. Who better to have to deal with these problems than people who focus on leveraging effort?