|
|
|
|
|
by em-bee
2809 days ago
|
|
how did you loose your 2FA device? this is what scares me the most about using 2FA. github for example says if 2FA is lost there is not way to recover. i have lost a phone number before... and although github also supports other 2FA devices, such as a rotating key app which can be on multiple devices, you have to set up all devices at once. so i can put it on my laptop and my phone, but not my home and my work computer unless i carry one to the other place. phone and laptop is not enough. if i use my bag, both are gone. and i'd have to reset all devices if i ever want to add a new one.
at that point i am more afraid to loose access through stupidity than through theft. no thanks. greetings, eMBee. |
|
My solution for TOTP/HOTP 2FA (aka "Google Authenticator"-2FA) is quite simple:
I print out the QR codes used to activate the 2FA, and keep them in a safe. That way I can always re-activate the 2FA on a new device, and it's still just as secure (because, if an attacker can break into my home and break open the safe, they could just as well take my phone with them)