Google Authenticator now supports Google Account synchronization
security.googleblog.com
security.googleblog.com
And how are you supposed to handle the 2FA for your Google account? I mean I have U2F tokens which remove that concern, but that is far from the typical case. If you have the 2FA for your Google account in the Google Authenticator, which is probably a very common case, how does this entire thing work then when you need it, which is when you lose your phone?
You open your safe and you use one of the recovery codes that you wrote down when you setup 2FA.
Do you consider your safe to be... safe? I'd imagine it to be relatively easy to get into, by picking the lock or sawing through the safe.
A decent home safe can be reasonable protection against that loose scrap of paper with backup codes ending up in the trash can and may even keep it legible in the event of a house fire. But it is true, it won't be much help if you are targeted by safe crackers.
Security is relative to your threat model!
As for drilling or sawing through it, that's going to take hours to do.
This is true for expensive commercial safes, but not for home safes. You can drill/saw through them relatively quickly. What you can't do is drill/saw through them without making a whole lot of noise.
Yes. I'm not taking about a safe like you can see in the movies. Just a locked box.
> Where I'm from, we generally don't use safes.
That's on you.
> Do you consider your safe to be... safe? I'd imagine it to be relatively easy to get into, by picking the lock or sawing through the safe.
That's not the point. 2FA is about thwarting password leaks. If someone has physical access to my house and knows my passwords, I'm screwed, yes.
But since I don't live in a Jason Bourne movie, my threat model isn't a ninja who steals my passwords then comes into my house to hack my tiktok account. My threat model is breaking my phone and knowing that my backup passwords are in a minimally safe place where I expect them to be and weren't carelessly thrown away with old documents; and deter casual "attackers" like a niece who could be inclined to plunder my papers for coloring material.
And if I did live in a Jason Bourne movie, I'd expect the ninja to just beat me up when I get home and unlock my safe for him, assuming I had bought an unbreakable safe.
Here I was thinking you might blow him up with the toaster. Or crash him into a garbage truck after an extenuated car chase.
> That's on you.
Wait, are we expected to have to buy safes to use the internet now?
It just gives you a single location in your house which you know nobody could accidentally open up and misplace the contents. It's where our passports and other foundational government documents, ATM cards, and yes, 2FA materials go. When you keep that kind of stuff in say, a desk or nightstand drawer, it's vulnerable to the 'oh crap, we cleaned out that drawer' attack, where you or your family members toss that stuff inadvertently.
Try a safe, it's great.
I was just reacting to the somewhat bizarre idea that owning a safe is something we should be expecting people to do for their online stuff.
* Single location for things you've only got one of, or which are super valuable and small
* Not somewhere that a burglar would just immediately check (rules out places like "nightstand drawer")
It sounds like you're just bragging that you've saved $50 by not having a true lock on your thing. I'm guessing you're pretty sure you've hidden it so well that a lock isn't worth "bothering with." Good for you! Enjoy your safe regardless.
> That's on you.
In some places the general level of trust is so high that things like theft simply does not happen.
Yes there's a possibility one might lose valuable stuff not kept in safes. There's also the possibility of loosing the keys (or forgetting the combination) of the safe.
And lastly, wouldn't it be so badass ironic if the safe sent a code to your email for verification? :D
You can glue them in inconspicuous "boring" places in plain sight, like under a mousepad or behind a movie poster hung on the wall.
Great way to hide secrets in your home without owning a traditional safe (which just screams "steal me! I'm the valuable thing in the room!" anyway.)
My backup codes are filed in an expando-file. There are far too many to cram into a wallet. Also, if I'm carrying them around with me when I don't need them, my risk/threat model now includes loss and theft of wallet. That's ridiculous and unnecessary.
Or just ignore the backup codes altogether. We mostly have "fake 2fa" - where you can reset your 2fa auth if you lose your device because otherwise customer support would be impossible. Almost every service allows this.
If I don't label my backup codes with account information, how do I know which code to enter when recovering an account? Trial and error across 20-30 scraps of paper?
I remember as a child someone broke into our house while we were away to steal stuff. The safe wasn't bolted down, and they carried it from one end of the house to the other before giving up, either because they got spooked by something and bolted or because it was just too damn heavy.
Think about the logistics of it. If they're stealing a safe, that probably requires a vehicle. A vehicle is more identifiable and unless stolen makes it easier to track people if noticed or recorded. If stolen, there's a chance it will cause a problem immediately before, during or after the crime. If they don't use a vehicle, all the benefits of not using one, such as being able to take non-road paths and blend into crowds are negated. And if they choose to crack the safe on location, that adds time to the crime while doing so, and all time spent at the location of the crime increases the chance they'll be caught because someone notes something suspicious.
Like a lock on a house a safe within a house serves it's purpose not by making it impossible to gain access but by making it much more troublesome and likely to be noticed, changing the risk to reward ratio.
Luckily by sheer fluke my phone was saved which has my TOTP apps on it or I would never get into anything again.
Yes, it's on the user, who else would be responsible for that? A Google employee isn't gonna go to your house to install a safe for you so you can store it securely. You can argue all day that the average person often can't be trusted with these things but I fail to see how this is anyone's problem except their own, at some point we need to stop treating adults like babies that need their hands held through everything and let them learn that their decisions have consequences.
99% of people don't need that kind of security any way, just keep a piece of paper with the codes somewhere hidden that you can remember, you don't need to have access to them all the time unlike a normal password.
Never underestimate the massive market advantage gained from treating adults like babies and handling all manner of frustrations for them.
UX researchers would call that "A good user experience."
I continue to believe that security for nontechnical users is not a solved problem. WebAuthN or whatever may someday help solve this puzzle, but only if someone packages it in a way that is so frictionless that it's easier than just using your birthday and initials as your password for every account like my dad did. And if the recovery story for the "All my electronic devices fell into a lake" situation is something less exploitable than the pathetic SMS. I'm thinking notarized letter as someone else pointed out.
2FA is usually imposed onto people.
For example google just enabled it for me, and also imposed it to most active python developers who published on pypi.
When first set up, the Google account really isn't something to care about. It only over time, and you getting used to all the conveniences it offers, that it slowly but surely becomes important.
Even as a technician i stopped caring about all caps and the license agreement. It boils down to two choices "You want to use this? Click yes and agree on things you don't understand" or not use it at all.
HN rarely does humor, but when it does, it really cuts deep.
Can you really expect a typical person - including the tech-savvy ones - to keep a hastily written piece of paper for a decade or more, without losing it? My code card is clocking on a decade, I needed it only once (so far), and it's only pure luck that, in all those years, I haven't accidentally destroyed it or thrown it away.
Also: it only recently became apparent just how bad it is to lose access to your Google account. Most tech-savvy people I know don't even realize how many things in their lives are gated by that little login form. Non-tech-savvy folks? Maybe they'll figure it out in a decade, after enough people became thrust into poverty for the lack of Google 2FA recovery codes - enough many that it's as boring news story as car accidents.
The best solution (for me) would be to connect the Google Account to my government issued identity and utilize the strong authentication provided by government for account recovery.
I think it would be great if the recovery mechanism for "ordinary people" took about the same amount of time as a notarized letter. In that worst case where you are locked out of your account for a week or two it won't feel great, but it also helps you feel better that some jerk trying to steal your stuff can't do it any faster either.
There are all kinds of fun technical things that could be used to actually build interesting "notary factor" tools. I think tech companies mostly reject how cool it could be to build because they see "slow" as a "bug" rather than a "feature".
It could even be a means of fighting spam/bots while maintainh anominity.
I heard those words uttered at my bank one day, and I became furious. I'd been using, in good faith, a licensed notary at a shipping store, and it turns out he'd been notarizing any damn thing I wanted without regard for proper form.
I had been extremely naive about notary publics, and when I ran into one with ethics, it cast the sketchy dude into sharp contrast.
Thankfully I've had no legal repercussions due to the invalidity of illegally notarized documents in the past, and I haven't needed to notarize something in a while since then.
EU ID cards also come with biometrics and NFC included, so they can be used to prove your identity digitally (there was a concept in France for an app that reads the NFC, makes you take a video selfie to confirm it's the same person, and then uses that to securely verify your identity)
It could be suitable, within certain boundaries, but no, given that sim swapping just means bribing (or simply social engineering with a crude fake ID) a minimum wage worker at a mall store, anyone whose identity is worth more than $50 to steal should never even consider it.
For example, if it could only be initiated from a browser where you have successfully signed in on at least two different days, or from a residential IP where you were seen recently.
I would much rather see a mailed postcard, as the last-resort fallback to a TOTP. Better to be locked out of your account for 4 days waiting for the mail, than to be locked out of it indefinitely while the criminal has full access.
> my government issued identity and utilize the strong authentication provided by government for account recovery.
Yes, that seems so obvious and yet to my American ears it sounds almost like science fiction. People here unironically argue that a national ID card is the Mark of the Beast from the Bible.
What happens to the homeless or move?
Mail forwarding is a thing for those who move, although TBH it would be prudent to use the "Do not forward" option on this, as mail forwarding itself is prone to fraudulent usage.
I guess if you've moved, you would need to mail them proof that you lived at the old address and that you live at the new address. I had to do that to claim unclaimed property with the state -- I had to send them some old bills or legal documents showing the old and new addresses.
No, it's not reasonable to expect everyone to be well organized. Life can be chaotic. People lose stuff. We know this. Some people are so unfortunate as to lose all their stuff. Repeatedly. The level of organization people have varies extremely.
But I do expect there are hundreds of millions of typical people with houses and sufficient organization to hang onto to their important papers, and it's a good idea to add your backup codes to your other important papers. It's good advice, though not always applicable.
Honestly, losing my passport probably wouldn't be as big a deal as losing access to my Google account.
> The processing time for routine applications is taking from 10 to 13 weeks up from six to nine weeks for those who applied before Feb. 6, the State Department said.
> Expedited processing, which costs $60 more, is taking seven to nine weeks, an increase from three to five weeks.
https://www.axios.com/2023/04/24/passport-delays-2023-proces...
Obviously you wouldn't be able to get in to your account to use google's built in tools because you wouldn't have access, but if you sent a letter to their legal team with proof of your identity then they would be obliged to process the request by law (as I understand it).
Passport is different from pass-code. Passport has no password.
Nearby, 'cause I travel semi-frequently. Otherwise, in one of few designated drawers. I only kind of care, because replacing it isn't hard, just annoying - and I don't need my passport to get a replacement one.
> Your birth certificate?
Wherever. I don't care. If I need it, I can file a form, pay a small amount, and get arbitrary number of copies from the local government branch.
> Any other important papers you have?
The only important paper I store safely is the booklet the military gave me when I turned 18, related to then obligatory military service (which I didn't go to because of minor health issues). I only worry about tracking it because I don't know the process to replace it, and the military is Serious Business - but then, I'm sure the process exists. Also, I don't worry much, because chances I'll actually need it for something are nil (if shit hits the fan so much that I'll get called into service, nobody will care about that booklet - they'll hear me speak fluent Polish, they'll give me a gun and send to the meat grinder).
Also, relevant: most of the important documents - like my national ID (replaced twice over the past few years), passport, contracts, etc. - have an expiry date on the order of 10 years or less. My Google 2FA codes already existed for more, and I expect them to be valid for the next 10 years too.
Personally, I keep these in my password manager. My password manager is offline-only, and the database is regularly backed up, so this makes sense for me.
Try as I might, my mother doesn't understand the difference between an iPad device PIN, an Apple ID (rarely needed), her email password on this same device (Google-based in this case) and add a few dozen more.
All she knows is the device in her hand. The abstract model we have where we separate device, service, app, web page, different companies...simply does not exist for her, it does not compute. So even if she'd have the discipline to write down things, it would still not work. She doesn't even grasp what part is asking for what.
There's a reason big consumer services like Google and Facebook have not enforced 2FA: a vast population will severely struggle understanding what the hell it is and what to do.
Even when you do enable 2FA on Google yourself, it runs in "soft mode". It doesn't ask for 2FA for previously trusted devices/locations. Surely for good reasons.
So passkeys would be very practical for her if I'm understanding you correctly.
As for the OP, it sounds really convenient but convenience is what led to Code Red Worm in 2001.
Also: where do you keep the encryption key for that thumb drive?
From the support page:
> If you’re signed in to their Google Account within Google Authenticator, your codes will automatically be backed up and restored on any new device you use.
Still doesn't explain how it works. On the same page they're talking about synchronization:
> Google Authenticator 6.0 on Android and 4.0 on iOS introduces the option to keep all your verification codes synchronized across all your devices, simply by signing into your Google Account.
I don't understand why "people" think it's a good idea to hide any form of mental model or technicalities.
Provide people with a mental model. It will make it easier to understand all the Ws. People are not stupid. They will understand, as long as you can describe it properly.
Neither was approved nor denied, just in limbo. But nice to see that both features have finally shipped. Sadly I have switched away to 1P, too much effort to move it all back.
It seems like a very, very bad thing to store both your passwords, and TOTP codes in the same tool...
I use Authy instead, which also backs up TOTPs.
I'm also having the same thoughts about Google Auth: my email (Gmail) is a big target for gaining access to the rest of my digital life, and putting 2FA in the same hands seems risky. I'd need to do more evaluation to consider leaving Authy.
If you are using a strong random password generated from 1PW you've already mitigated against that threat. TOTP isn't buying you much additional security. So for most folks it is just fine to store you TOTP seed in 1PW.
Unlike TOTP, passkeys _do_ buy you additional security in their phishing resistance. So you should always prefer passkeys/fido2 keys to TOTP if that is an option. Its still fine for most users to use 1PW as your passkey storage.
The only argument I can imagine is that if someone gets ahold of your phone it's either locked and they can unlock it or it's unlocked, in which case either your 1pw account and/or other TOTP apps are either locked or unlocked. In the worst case scenario where everything is unlocked, having a separate app is negligible.
Besides, AFAIK Google Authenticator doesn't require additional unlock steps, unlike authy or 1password.
You're better off worrying about how to avoid TOTP and securing 1password than about having TOTP codes stored alongside your passwords.
Why isn't TOTP buying much additional security?
It seems to me that apart from password reuse it's mitigating many other potential problems: keyloggers leaking passwords from your device, passwords leaking from the authenticating server, etc.
The only good solution is WebAuthn and related technologies (phone passkeys for disaster recovery), so that server side needs nothing more than a public key.
But lets say you are in fact a user that gets targeted by an adversary capable of deploying a key logger against you. Does TOTP protect you? No! If you are compromised to that point, the attacker is also in a position to just hijack your sessions.
There isn't a threat model out there that is trying to solve the problem of "my end user device has been compromised but I still want to be able to use it to access sensitive systems without those systems being compromised."
Storing both on 1Pass is not as secure, but the option is that once in a while you misstep and spend a week restoring TOTP setup (or lose entire accounts because your service provider has no functional customer support) then I'm amenable to stable but less secure options.
There are many non important accounts where I have 2FA, and both the password and the TOTP is in 1p. This should suffice for any brute force password attacks. However there are some accounts (like google) which one can consider more important for which I keep the TOTP on a separate app like Authy.
More recently I've been switching to yubikeys where possible.
I keep my 2fa backup codes in my Keepass safe. Where else will I keep them?
Yes. It defeats the purpose. But whenever you mention it, you will get lots of replies with plenty of hand-waving why this is still better and why it doesn't matter "much".
If you go to the effort of doing 2FA, do it right. Two Yubikeys, and a reasonably decent TOTP app (Authy qualifies as "reasonable") for those sites that do TOTP.
I’m glad there’s finally real support for backing up codes.
I'm in the process of moving to Aegis. It's FOSS, encrypts the file on the device, and supports the biometric lock. It can do a daily backup to a few sources, including the Google backup (I think) and personally I dump it to a folder that my Nexcloud will automatically upload to my personal server.
You'd need to involve the provider for changing token seeds.
At a client level, all you have is one seed.
If you save a seed, it can be used on any number of devices.
Twice I've had to spend hours manually resetting/renabling my 2FA after a phone was damaged, and sans buying a new screen just to get a backup of the phone, there aren't many other options.
(Similarly, this was the time I learnt that the UK gov does not issue backup codes for their 2FA and you just have to spend 45 mins on hold to have them reset it for you.)
Unfortunately Google has the last laugh here, because since Android 12 even scrcpy can no longer bypass FLAG_SECURE. Currently you'd have to start messing about with root and using some sort of Xposed and/or Magisk (?) module to disable FLAG_SECURE in order to be able to mirror that kind of apps with scrcpy again.
For me, I'd usually be on the desktop when setting up 2FA anyway, so I'd just save the QR code from the desktop browser ("Save image as ..."). When I needed to set up a new phone, I'd open the saved image on the desktop and point my phone at the screen.
Screenshot -> Print is one backup method.
Screenshot -> Encrypt -> Save to secure location is another method.
Also, as of last week, there existed an issue with special characters when trying to import and the app would just freeze or not recognize the QR code pattern at all, so you better had backups of all your secret keys.
Both issues made me switch to Aegis and appreciate my past self backing up the secrets with KeePassXC.
They actively added code to prevent you taking screenshots, which is insane but true.
In any case, if you're trying to create a backup there are other avenues of capturing the QR code - offline digital camera is probably the most secure way of doing so.
Now it's tied to the Google Account which means it'll be tied to either their personal or work account and now we have to worry about personal account bans removing their 2FA or when they leave the company, our suspension process killing personal 2FA that were synced via the wrong account.
Not saying it's a particularly good way, but it's a way.
Do not use google-anything, for anything in production, ever. They make shiny products that depending on your point of view may be nice or just shiny. But their total solution is not a serious competitor to any of the major players. Any time anything depends on google, you risk it destroying a part of your business - yes, under a paid support contract.
I was doing a dc migration at a hospital once, and they used google authenticator. I'm waiting for the day some sysadmin who knows some dev who worked with some dev on an app that was banned from some phone that got resold, will cause all the storage, network, and sysadmins to lose remote login access to all their devices during a sev1 at 2am.
Apparently the authors of Signal consider backup to be less important than all the idiotic "story time" features and similar doodads.
This basically means you can never factory reset your phone without someone else using their phone to help you, which means you're forced to share your entire account and all your codes with a third party who might keep them forever.
You also can't preemptively back it up in case your phone is stolen or lost.
But nope, Google thinks they know best and in 2023 they still actively block you from keeping your accounts safe. It's mad.
I just tested this using the copy function of my Brother printer/scanner, and my phone was able to successfully import from the printed export code.
I've only got 4 accounts in Google Authenticator (because I only have it because I wanted to help someone else once who was using it figure out something). The more accounts you have the denser the QR code will be, so it is possible that you might have to split the export into multiple passes with this method if you have a lot of accounts.
Whilst clever for the people who don't have Google Authenticator installed, it's just bizarre to ignore it when it's there.
TOTP are still phishable, the push notification includes information on where you're logging in from, so you at least have a chance to notice that the login is coming from Croatia and not your house.
FIDO is still vastly better though.
I always thought Okta was kind of weird, because it's just a notification that says "allow/deny" and it's easy to click the wrong one.
First, Google Authenticator, which is in fact just totp which can be used for both Google 1p and any 3p TOTP thing. And second Google's push-notification based auth checks which are used for only certain 1P Google apps (like logging into your gmail or youtube).
(And no, enabling "advanced protection" doesn't count. It's well-meaning but it's too restrictive.)
Plus (unlike TOTP and FIDO), it's proprietary, making it harder to fit in my workflow. For instance, I can generate TOTP codes from my computer in order to seamlessly sign-in to services.
The old one has its name changed to "(old)": https://play.google.com/store/apps/details?id=com.google.and...
2FA setup in general is a PITA to support with users in the real world. I speak from experience. It's too complicated. Too many different steps involved. People get stuck doing it. People get locked out of their accounts. Etc.
Most people with a clue would not use Authenticator but one of the many alternatives that do the same job but with a bit more convenience (like syncing secrets between devices).
I tend to use Authy. And of course Okta actually acquired Auth0, which created Authy. But you could also use many common password managers for this (except of course the Google or Apple ones people actually default to on their phones).
Meanwhile, Google, MS, Apple, and others are also pushing hard for passkeys. That seems more promising. But what worries me is that they regard this as a browser thing. So that still leaves a lot of mess outside of browsers. As well as their legacy of other supposedly user friendly ways of signing in. At this point most of them de-emphasize 2FA actually. Because it is such a support nightmare.
https://support.apple.com/en-gb/guide/iphone/ipha6173c19f/io...
That seems nice
Honestly I think apple could do a better job at camera -> qr ux flow
Cable Sasser wrote a blog post that was making the rounds a few weeks ago, advocating for a dedicated app. He's right, the existing Apple implementation works great but it's still a lot for normies.
https://cabel.com/2023/03/27/apple-passwords-deserve-an-app/
You mean the idiotic little tiny yellow popup which only stays on the screen while the QR in view and must be tapped to activate... WTF were they thinking right? (You can add a "QR reader" button to your control center though which functions in a more sane way.)
Anyway yes you can do that, but I wouldn't use iCloud keychain at all because your Apple account, including ICKC, can be fully hijacked using one factor only - the passcode of the device an attacker has. People watch you unlocking in a bar, then grab your phone and run. Google "joanna stern iphone passcode" before moving any precious data into Apple's control.
But if an attacker has your iPhone with passcode they surely get access to your Google Authenticator or Auth app. How "not storing TOTP keys in iCloud" way is better in this case?
I'm afraid you're right. I previously thought that my authenticator, Microsoft Authenticator (MSA), was taking advantage of the feature that banking apps use where it could detect that a biometric was updated (Finger added / Face added) and clear stored credentials in that case, meaning that it could only unlock credentials with the actual face that saved them.
Well, I was wrong. Holding my thumb over the face sensors twice yields an "Enter passcode" prompt which unlocks MSA. I assume Google Authenticator does the same. Just reinforces how thoroughly compromised you are if that single 6-digit code gets shoulder-surfed. facepalm
Note: I'm assuming the reason MS and Google made this choice is that since sync was added later (a few years ago for MS and this week for Google), if they did the secure thing which is technically to self-destruct all your keys if you've altered your biometrics, this would mean that a simple redo of your face scan or adding a finger would lose all your TOTPs, because there was not a fall-back password or something that secured those apps.
So I guess perhaps a more secure solution in this situation is 1Password? Because with that, if you can't pass Face ID, you'd have to enter your master 1pw key which hopefully nobody knows or can guess.
https://www.wsj.com/articles/apple-iphone-security-theft-pas...
TL;DR: if someone spies out your iPhone's passcode, they may be able to hijack other accounts synchronized with it.
In such situations, this simple passcode is like a master password, with with critical things such as PayPal and Apple Pay payments can be initiated to drain bank accounts.
Two-factor authentication also doesn't help, as their challenges can be approved easily once the iPhone is unlocked with the passcode.
And so I looked it up. Became pretty popular on hn.
My advice would be to not have everything in one place, no matter which ecosystem you are on. Going all in is never a good idea whether its Google or Apple. Its great that Google has done this, but just use another app to manage that.
Personally I would be a little weirded out if a customer service rep could access my account over the phone, especially in an account recovery situation where "I lost credentials oops".
1) Attack vector reduced to one account which you maintain with healthy hygiene, and hopefully don't use with public systems, etc.
2) You can keep backup 2FA for single account instead of keeping for N accounts.
For years I've been telling anyone who'd listen to use Authy instead.
Google Authenticator already has a QR-Code based very easy export procedure, I just backup my GAuth to my spare phone and tablet. It feels safer because it's physical.
Of course, not everyone has several devices, and physical security is not granted to everyone. I guess cloud-backedup 2FA is better than no 2FA, or than 2FA with no backup at all. But... Cloud ? for security stuff ?
Though, I often find myself wondering if this represents going in circles with security. If the security surface of all of your 2FA keys now reduce to one measly password, well, wait a second, does protecting everything with two passwords count as 2FA?
Employees down to subcontractor's trainees can modify the code or pwd store... FYI, the industry standard for "risk of corruption" is: 3 months of wages. In low-pay countries, this means, literally, pocket change. How sure are you that whatever Google does is impervious to such insider bad actors, even if at a specific time their setup was indeed secure ?
Everyone with a Yubikey knows that the secrets aren't coming out and they will need a backup. It would be foolhardy to rely on a Yubikey alone, when the risk model obviously entails loss or theft of the device itself. That's what paper codes are for.
It would seem that the QR export, and now this account sync, is Google weakening security as a concession to intense end-user pressure.
Yeah, it sucks to lose all your TOTP secrets at once; that's why you form a contingency plan and stow your paper backup or maintain a spare device.
Google Authenticator is a victim of its own popularity. Fortunately, the field moved on, and we now have WebAuthn and Passkeys for non-exportable private authentication keys.
The expectation is that WebAuthn private keys are stored in the secure enclave, which would be a comparable security guarantee to YubiKeys and other hardware devices.
"Passkeys" are now forcibly synced via iCloud, you can't use WebAuthn on iOS without enabling iCloud Keychain.
FreeOTP Plus forked the same functionality of FreeOTP provided by RedHat with the following enhancement:
* Export settings to Google Drive or other document providers
* Import settings from Google Drive or other document providers
* Enhanced UI with material design with dark theme support
* Search bar to search token
* Provide more token details for better interoperatibility with other apps
* Utilize modern camera hardware to scan QR code faster
* Option to require Biometric / PIN authentication to launch the app
* Heuristic based offline icon for tokens of 250+ websites.
* More settings to customize the app functionality
[1] https://f-droid.org/en/packages/org.liberty.android.freeotpp...
1. Backups that are specific to the app that made them. They can be used to restore the secrets to that same app on a new or replacement device, but might not help if you want to migrate to a different app.
2. Backups that can be restored to other apps.
If you aren't sure you are going to stick with the same TOTP app long term this could be important.
Sometimes there are third party tools that can take #1 type backups and give you back the secrets in a form suitable for other apps.
For example, Google Authenticator can export the secrets in the form of a QR code that contains the secrets for multiple account. Another instance of Google Authenticator can read that, but other TOTP apps might not be able to. But this tool [1] knows how to take the information in that QR code and decode it and split it into the individual secrets for each site. It can even generate QR codes of those for scanning into another TOTP app.
If you want #2 type backups that just work with most TOTP apps, there is a fairly easy way to get them. Whenever you set up a new account and a site gives you a QR code, simply take a screenshot before using that QR code to finish setting up the new account.
Store your collection of QR code screenshots somewhere safe.
If you ever want to migrate to a new TOTP app or to the same app on a new device open those saved screenshots and scan the codes.
If you've got an image display program that will let you open many at once restoring can be pretty fast. On my Mac for example I just do "open *.png" in the place I have the screenshots. That opens them all in Preview, with each one being a separate page. Then I tell preview to show one page at a time.
Then it is a matter of scanning one, hitting "page down" on the keyboard, and repeating until they are done. After two or three I'm in the groove and it goes pretty fast.
I never thought about that. I always backup the key before I first use it, when it's shown for the very first time. Heck, I've written a CLI / text TOTP app (using some Java TOTP library) for my own use (fully offline / airgapped / paasword protected / showing six codes at once for the same code [+1 hour / now / -1 hour and previous code / current code / next code] and which also shows a public/commonly used example code, which is convenient to diagnose sync/clock issues).
> But this tool [1] knows how to take the information in that QR code and decode it and split it into the individual secrets for each site.
Like JBSW Y3DP EHPK 3PXP ?
In my experience every site that shows the QR code offers the possibility to see that secret (and those that don't are misleading users into thinking it's more complicated than it is).
A TOTP secret is just that: 16 or 24 or whatever characters. The QR is just an encoding of these characters. The "issuer" serves no role other than autofill the name of the service for you (and you're not forced to use the issued nameL you can use any name you want).
I never ever scanned a QR code to configure 2FA / TOTP for any site. I write the 2FA code down, then encode what I've written down (in at least two devices).
I'll never understand why they didn't do this many years ago.
What happens to your data when google decides to lock your google account? Does your device keep a local copy or will it just shut down?
The issue described here started happening to me recently: https://www.googlenestcommunity.com/t5/Apps-Account/Why-is-G...
Summary- Google has added a “match the numbers in the app” style 2FA to YouTube. Makes sense- their video monopoly means that for many iOS users like myself it’s the only Google app they’ve got. Except…
1) It’s the default, and there’s no apparent way to change it, or even turn it off. This is annoying- I prefer TOTP since it’s more secure. There’s a Google Prompts section in the 2FA settings, but it says that I don’t have any supported devices. This actually makes sense, because
2) It doesn’t f*king work! Ever since they changed it from “press yes” to “match number”, the screen opens in the YouTube app and then loads forever. Which means I’ve got a spurious notification on my phone, a screen to dismiss next time I open the YouTube app (or several, because for some reason they can stack), and two extra clicks every time I log into Google on a new device.
Actually, I lied earlier- there is one way to disable it, and it’s to DISABLE ALL 2FA, as you can see people doing in that support thread. I honestly don’t blame them, but clearly less 2FA was not the plan of whoever’s idea this was. Speaking of support forums- I don’t think anyone at Google reads them, but they do read HN :))))
It’s not ideal since you need to deal with two accounts but that’s what password managers are for.
"This channel is for troubleshooting Google devices. It is best to report this with YouTube support for better assistance. [...] I'll be locking this thread after 24 hours."
...just because the initial report contained the keyword 'YouTube', presumably. The reporter clarified the situation, and a different "support" team member comes in and regurgitates the same canned response! On Google's side, why even bother replying at all if that's all you're going to do?
Oh, it's just so they can claim to their advertisers that they do support.
Remember: if you're not paying for the product, you are the product! (https://en.wikipedia.org/wiki/Television_Delivers_People)
This cliche isn't true: if you pay, you're a more valuable mark. You're always a product.
For actual support you need a paid account to reach out to.
You could argue that it's badly named and should just be called Google's community forum instead, which is what it really is.
Some examples of the subjects of these threads:
- SD Card readers in original M1 Macbook Pro not working
- Bluetooth headphones balance getting messed up randomly (so old someone created an application to automatically center balance)
- Specific Intel Macbooks crashing after using a Thunderbolt dock exactly twice.
All of them with no response from Apple at all and no fixes in sight.
Out of all of them I guess I'm more disappointed in Apple because they have cultivated this aura of superior UX (so that emphasis on UX should extend to when people have problems).. but then again it's largely just an aura.
Oh it's still waiting for its Google Authentication Numbers.
> I'm chiming in to ensure you've got the answer you're looking for. Feel free to let us know if you have more questions about this.
Totally void of any helpful information or even remotely understanding of the issue. Of course at the time the comment was posted, no useful answer had been given by any support team member.
But to be fair though, the support team did follow up a few month later:
> Thanks all for your patience on this post, and sorry for the confusion. I originally pinned a response by @knewland397 as a helpful workaround for some folks on the thread, but I understand that it didn’t answer the whole question. Happy to shed some light on the situation here!
> Prompts like this are intended to be easier than entering a verification code to log in, and you can receive them from not only the Youtube app, but the Gmail app, Google Photos app, and more. To learn more about prompts and how they help keep your account safe, stop by our Help Center [1].
> To answer your question of why your Nest Community account is impacted, our community uses the same Google Account authentication as the rest of Google services.
> For future reference, our friends over at the Google Account Help Community are best equipped to help you with these types of questions. This forum is meant to host discussion about apps and accounts as they relate to Google Home and Nest.
The help center [1] indeed documents the apps (under the "iPhone and iPad" tab):
> Gmail App, YouTube App YouTube, Google App, Fotos App Fotos, AdWords App or Smart Lock App.
https://apps.apple.com/us/app/vinegar-tube-cleaner/id1591303...
I refuse to use the YouTube app because they disabled playing in the background or with the screen locked . They Want your eyeballs on the screen for the ads. It so blatant.
They allow background play and screen-off play. You just need to subscribe to Premium.
I don’t know if it’s just me, but it seems like for the last couple years the products from the FAANG companies have been rotting on the vine. It seems like all the people that made these have moved on and have a b-team barely making them work.
If such insecure factor can’t be disabled, what’s the point in setting up TOTP and / or hardware keys?
I use all 2FAs allowed.
Tangent on passwords. What the world needs is a path to automated, interoperable secret management in 3-4 RFCs:
User-operable, standardized password change REST API that:
0. Sends a session token/nonce
1. Describe the password policy declaratively and precisely, to be validated client-side with boilerplate client code
2. Offer a list of supported PBKDFs and their required and allowed parameter values
3. Includes both client- and server-side PBKDF hashing with minimum values for a given risk type AND adjusted with the "inflationary" Moore's Law costs of tech resources (CPU, GPU, RAM, ASIC, FPGA, QC) over time
---> This would then permit a password manager app to automatically change every password perhaps every day. I'm thinking the future should be like this but use user certificates as a primary AA mechanism and passwords as a break-glass-backup.
If someone uses Chrome's password manager and Authenticator's TOTP, this seems to make account takeovers an exceptionally juicy prize. Capture a Google account and you've captured credentials and all necessary factors in one fell swoop. Well done, bravo.
I mean, account takeover already means game over because you can read/send email, but the whole idea of device-based TOTP is to isolate it from anything with an attack surface.
It's not been a problem for me though as I've just always saved the otpauth code from the start.
for i in *.png; do uri=`zbarimg -q --raw "$i"` && ykman oath accounts uri --touch --password "MYYUBIPASS" "$uri"; doneYou can still export TOTPs to other phone directly. You can still make sure you store TOTP secrets on multiple devices/password manager.
edit: I want to reiterate that these are still TOTP codes and not WebAuth/FIDO2.
They can also do more sophisticated things, but that's not what I was referring to here. Those sophisticated and more secure things are supported by Google, Facebook, Dropbox, Github, etc, but not by most banks. Banks are so slow with this stuff and still do SMS-based 2FA which is absurd to me.
And another thing: https://www.paypal-community.com/t5/Managing-Account/Why-am-...
I would absolutely love if more services supported WebAuthn/FIDO2, of course, but Yubikey TOTP is supported everywhere Google Authenticator is.
I would still prefer independent app for password manager and another for TOTP with backup enabled for all.
I use Keepass/Keepass2Android for 2FA wherever possible.
Not seeing anything new on Android and it's fully updated.
[1] yes I know there are github projects that make this doable but it's super involved whereas it doesn't need to be.
How nice it is for all 3 letters agencies and google employees that they have your passwords and your otp all in their cloud. In clear. All that is needed for having the keys to all your other kingdoms.
Did the holdouts on the relevant team not make it through the layoff rounds or something?
Article: "Google Authenticator cloud sync: Google can see the secrets, even while stored" - https://defcon.social/@mysk/110262313275622023
If I remove an account from an app / device, I expect it to be gone. But they clearly shadow it.
I have three google accounts (work, work and personal). And when I log into my personal account, which I have removed from the gmail app. It still uses that app as it’s “2FA”, and then reactivates the account.
1) if I remove the account, actually do it!!!
2) if I’m not logged into any apps, then use a 2FA method I DO have active (google auth app)
I wonder how I’m gonna access that account now? Every time I’ve tried to change the email, I’ve been unsuccessful.
I've moved to using the pass otp extension[0] which gives me secure storage of the totp seeds without being tied to a single device.
if you think this is a good idea, i highly recommend you add a second 2FA device to the account you're worried about instead of... centralizing your "have" factor into a "know" factor.
I will say that the previous migration path was super simple as well. The old device generates a number of QR codes that the new device scans, in sequence.
Google is pretty on top of things in terms of service updates on products that have core adoption / pmf.
most of these security protocols fail to scale . what happens when you have 30 tokens and you get a new device ?
many vendors are still requiring a phone call.
security without usability is just cosplay
Glad Google finally has this.
https://defcon.social/@mysk/110262313275622023
TL;DR don't use it as there is no encryption.
mmmmh....