I've encountered a similar but less problematic version of this simply by being abroad somewhere my provider didn't cover.
I've encountered a similar but less problematic version of this simply by being abroad somewhere my provider didn't cover.
In practice, a lot of the non-sms factors end up requiring reset every couple of years on average. It means our support orgs end up treating MFA resets as routine and that in itself can lead to situations where you open your customers up to social engineering attacks on support and support tooling.
There's really no easy answer here, my only hope is that eventually we move to government issued, strong, digital identities as second factors.
What if an iPhone user uses Apple Notes to store their TOTP keys (probably one of the most reasonable ways accessible to a non-technical user), but then 5 years down the line switches to Android, 5 more years pass and they've entirely forgotten that they even used to put TOTP codes in Apple Notes 10 years ago, and then they need their TOTP codes?
Securely archiving things which are rarely if ever needed across many decades is an incredibly hard problem, and I would trust approximately 0% of users to do it correctly.
I lost my yubikey I used for my AWS account (I know, I should have two but I really did not have anything worthwhile on this account). I also changed phone numbers in the meantime as well as email. And then proceeded to forget my root password. I have not used the account for a number of years and it really did not sink in until I needed it.
See? You would think I was totally and utterly fucked.
Well, not. I called them and with a procedure that took some 3 days and numerous phone calls, id photos, etc. But I finally got the access to my account back.
We're disagreeing over semantics then. I'd call this "being locked out of my account semi-permanently".
I have to say I don't fully understand your perspective. In a sibling comment you admit that free customers ought to be subject to this misery because they are using the service for free, and here you suggest that requiring numerous phone calls and numerous days of non-access to services is not an inconvenience. I suspect we simply have different life priorities. For me, those three days could be critical in my relationships with customers, clients, employers, etc.
Would you like your bank to make it convenient for you to get your money if you forgot your ID? It is double edged sword -- convenient for you is also convenient for somebody who might want to steal your money.
So no, I do not object to AWS doing due diligence when I recover my password because I know this hopefully makes me a bit more secure from somebody else doing the same.
You just make cloned yubikeys. You can't read data from the key, but you can initialise it with your own data and you can initialise more than one with the same payload.
I'm so over the phone system and the credit card system. We have superiors but we are stuck in the past culturally.
If the process takes couple of days and they do a lot of communication, there is a good chance the real owner of the account will get notified and have time to react before the attacker gets access to the account.
Also, the commenters are completely wrong on that it is enough to have the email or ID to get through the process. The AWS people who contacted me required a lot more information that only the owner of the account would know.
And the point of 2FA in the first place is thought by many to prevent social engineering.
All you needed was an id photo and be able to talk on the phone?
That and account history etc. will probably be in many peoples email. Thus access to the email only would allow you to get access to 2FA services too.
Just feels safer to me to have a printed backup of both stored away in case the tech breaks or gets lost.
One could argue that your accounts were never secured to begin with.
If this doesn't make any sense, it probably is because I have the details quite right, but the end result is I was unable to help him make any more sense of this, and there appears to be literally no way to regain access to his facebook account.
a blessing in disguise perhaps?
Maybe 2FA should be considered a red flag at this point.
Security is important. Security that is implemented badly costs you business.
I've been a part of designing these types of processes and this is all argued about forever. The alternative is the e*trade approach where I can call in, give my DOB, Address and last 4 digits of my social social and I get a new MFA token immediately. No PIN, no signature nothing.
What company did you say you were designing security policies/processes for...?
The process we use now is automated but customers don't like having to find recovery pins, billing information so a lot of them still call if they get a new phone and their TOTP isn't there. It will also fail for various other reasons related to browser fingerprinting and reputation that I won't go into details about.
MFA recovery is very tricky, most websites don't even let you do it in an automated way for security reasons. If it goes wrong, you've basically broken MFA for your whole site. Banks are the types of places that are going to err way on the side of caution.
Only culprit that's really enforced it is the Canada Revenue Agency
My bank recently made a 'security' updates and now my Google Voice number no longer works with their text or call 2FA. They provide no other alternatives and I must have it. I have to now call their customer service, wait a half hour to speak to someone, verify my identity, and have them reset in order for me to login.
Thankfully I rarely login to that bank as it's not used for much, but if it goes on for more than 2 months or so - I'll probably switch.
As an aside, open banking is also a joke as it doesn't allow the end user access to their own account, only 3rd parties - simple API access would make this problem moot, as where I hold my funds grants me API access and I can do things like trigger transfers on webhooks etc, very simple and infinitely useful.
A few months later they added TOTP support. Not sure if I influenced that at all, but it's just another reason why I will only ever use a credit union as my main bank.
When you are paying customer you are also getting the privilege of contacting the support.
I think it is fair that Google does not want to directly talk to billions of people using their services and not paying a cent for it. You get it for free? It is up to you to make sure you don't loose access.
The problem in my case was that Google changed the rules halfway through. I kept my username and password perfectly secure in my password manager. But one day they suddenly decided that I can't log in until I respond to an SMS code they sent to a phone number they somehow got from me 12 years ago that I no longer have access to. It would be fair for them to not suddenly force SMS MFA without the user's consent.
The cheapest paid workspace account is cheap enough that it probably costs less than processing a single support ticket. Remember, when you loose access you are probably looking at multiple touch points and multiple people on their side to get you back. You wouldn't want any single person to be able to just change whatever they want?
So if they allowed it, people would just pay for the privilege once to get the problem resolved and then downgrade themselves back after one month.
The issue here is that the ratio of free accounts to paid accounts is so high that if any support was allowed for unpaid accounts it would absolutely deluge the system and paid accounts would have to pay a lot more to cover the cost of support for unpaid accounts.
But I do think they could provide a paid support ticket where you can pay an amount that would cover their costs (and of course then some) for a single support request.
The issue with this is that somebody could do this to "recover" account that does not belong to them. Paradoxically, there is some extra security in not allowing any social hacking by just not allowing any manual work on the account.
That's the problem. The more flexible you are with helping a customer, especially just over a phone or computer, the more open you are to social engineering attacks. At least in the US, there are various processes involving notarized/Medallion signatures and the like. But at that point some not insignificant number of people will complain the processes are too onerous, they don't have a local bank, etc.