Sort:  

I am looking forward to FIDO being more popular since 2FA has the flaw that both sides need to keep the seed code encrypted and secure. There has been cases where the website did a poor job with this security.

FIDO uses a different process that supposedly eliminates this problem. Alas i do not know the tech behind it.

FIDO doesn't work on mobile, so you wouldn't be able to login to any sites using it while on your phone.

Well that sucks. Thanks for the info.

the more the improvement of the system more the security and more headache

2FA is really quite the revelation in privacy settings, but it seems like it's still early days for it. Most people still don't use it, and I started using it no longer than a year ago or so. When it works, it works, but when unusual things happen it can get messy. I don't think Google will let itself become obsolete in anything, but I wouldn't be surprised if they made big changes to their authenticator to keep up with better ideas.

Got rid of using Google authenticator when i lost access to a crypto exchange account because i didn't save the seed key. Switched to Authy 2fa Authenticator ever since then and can't even dream of going back to google Aunthenticator because of the backup and sync feature it lacks.

Will give this 1password a trial. I just hope it has enough features to make me switch from Authy. 😁

and no recovery option if you lose your phone

the recovery option is sms text message to new phone with same number, get a new sim from phone provider and works fine

As a result, starting next week, SMS two-step verification users on Google will see an invitation to try out the new system, although anyone with a security key will not. On Android the system is built-in, but iOS device users will need to have the Google Search app installed.

i guess it is not available to all users idk

Nice contribution. I haven't tried the 2FA function in 1Pass yet.

I don't quite understand your statement at the end where you say that cell phones are bad 2FA devices.

In the case of 1Pass, if I understand correctly, both factors are secured in one place.

I use Authy myself and I am very satisfied with it.
In any case better than Google Authenticator :)

If sms is used as second factor, someone can call your mobile company and pretend to need a copy of the sim and they will sometimes get it. At that point they can get all your sms messages.

Yes that is right. Social Engeneering is an often used attack vector.
But I don’t think Authy can be restored only with sms. If this is so there is no need for Authy at all.

As you might know, some providers send the auth code via SMS instead of using a 2FA application. In theory, if you're planning to attack a single person, it's shockingly easy to call the provider and gain access to the SIM card. This technique is called "Social Engineering" and is actually pretty effective.

Google Authenticator and competitors use an encryption key which is shared with the device via the QR code you're scanning at initial setup. Therefore, the code is unique and device-bound, so there is no way for an attacker to gain access to it (unless he gets access to your device).

acá toca guardar la clave secreta de cada sitio para la configuración de 2FA.

I have had my phone fry and lost this before. Crypto sites are a bitch to get access back to. The only thing that saved me was being fully verified on certain sites. Still haven't gotten back into Kraken so that has just become a savings account for now. I do have the QR printed off somewhere, just haven't looked for it.

Thank you for info. When I activated 2FA on Bittrex I forgot to back up the key. Now I depend on Google Authenticator which is bad in so many ways.

Just disable it arausa, and then add it back on Bittrex...you will get the new code friend...make sure to delete the old data on your phone in the GA interface...then when you scan the new QR code the new password will be saved

Thank you very much for your advice. Well, not sure what do you mean by deleting old data in the GA interface I'm using iPhone 5, but I'll give it a try to find out.

Sorry for the late response arausa....what i meant was go to the GA app and delete the exchange you added before by holding your finger on it..it will show you a trash delete button....then press the + to add a new exchange and then scan the new QR code for the 2fa you re established...let me know if that makes sense friend...cheers

Thank you very much for explanation, yes, it worked! Cheers!

Oh my! Thanks for the heads up. I just didn't think. Glad to read this before I lose my phone. Personally, I'm going to switch to Authy, but thank you. I didn't realise how much it would affect me if I lost my phone!

There is a wayto extract seed in text form if the phone is rooted. I got mine extracted and stored somewhere else. But the combination you suggested is much more straight forward indeed.

yeah, I have looked into that, but it is much harder on iPhone and a lot of work just to move it.

In case of iphone it would be harder. Anyway this is the design flaw of the app in the first place.