Hacker News new | ask | show | jobs
by mdaniel 1275 days ago
> since the e2ee does not depend on a user chosen master password.

What's the story with "my phone went in the lake" using that setup?

3 comments

Since i use Google Authenticator for numerous services this is going to happen to me one day. So what I did was set it up on more than one phone.
I would legit pay money for Google to pull that piece of junk from the Play Store, because it's damn malpractice at this point, given there are so many other options that don't straight-up swallow the TOTP keys
Sorry what
You can back the secrets up to a text file, print them out, etc. too. They're short Base32 strings and TOTP is a standardized protocol with an RFC (6238) and everything.
Except it is cumbersome to doo on Google Authenticator. You must press export to get shown a giant QR code. You can't screenshot it. Must photo with different phone and print on a piece of paper for offline storage.
Yes i did this too
I also have two phones with Google Authenticator. Is that a bad idea?
Just wrote a longer answer to the question below, hope that covers your question as well.
fish it out of the lake and pay someone $1000 to extract the tpm and restore it for you