Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Subjunctive
Sep 12, 2006

✨sparkle and shine✨

yeah, you might have to disable 2fa to remove your mobile, then re-enable it. I forget the flow, it was different when I did it

Adbot
ADBOT LOVES YOU

RFC2324
Jun 7, 2012

http 418

Subjunctive posted:

yeah, you might have to disable 2fa to remove your mobile, then re-enable it. I forget the flow, it was different when I did it

as ofright now, you can't do this. If you want to set up 2fa, it has to be SMS, and you can add something else, but SMS will always have to be active.

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Progressive JPEG posted:

I have facebook 2fa enabled with totp/gauth. They still send me sms codes and the sms codes still work. Afaict there's no way to just have totp 2fa.

top of the pops 2fa? so you have to mime playing an instrument? :P

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Chris Knight posted:

top of the pops 2fa? so you have to mime playing an instrument? :P
no they're saying that paypalxsms is the true otp (totp)

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
yeah fb can't do normal totp without a phone any more, i got caught out by this recently, it's lame

flakeloaf
Feb 26, 2003

Still better than android clock

not that 2fa over sms isn't still poo poo but maybe the telco oughta be picking up on the fact that someone's tried to reset your password 219 times in the last hour and a half

physically going to the rogers store to unlock my phone is simple because the drat things are everywhere, i wonder if i can just have them forbid anything over the phone other than "i lost my phone cause i'm a moron, brick it pls"

maskenfreiheit
Dec 30, 2004

flakeloaf posted:

not that 2fa over sms isn't still poo poo but maybe the telco oughta be picking up on the fact that someone's tried to reset your password 219 times in the last hour and a half

physically going to the rogers store to unlock my phone is simple because the drat things are everywhere, i wonder if i can just have them forbid anything over the phone other than "i lost my phone cause i'm a moron, brick it pls"

you can set a verbal password on most carriers so that if someone were to be like "lol cancel my service" then "lol i'm op and now i use this other service send me lovely 2f texts", they'd have to give the verbal password or show an id at the carrier's store.

Wild EEPROM
Jul 29, 2011


oh, my, god. Becky, look at her bitrate.
my voice is my passport

crazysim
May 23, 2004
I AM SOOOOO GAY

Rufus Ping posted:

yeah fb can't do normal totp without a phone any more, i got caught out by this recently, it's lame

Only registered members can see post attachments!

James Baud
May 24, 2015

by LITERALLY AN ADMIN

maskenfreiheit posted:

you can set a verbal password on most carriers so that if someone were to be like "lol cancel my service" then "lol i'm op and now i use this other service send me lovely 2f texts", they'd have to give the verbal password or show an id at the carrier's store.

Popup note on your customer file that a rep may or may not even read, easy to socially engineer your way past because people genuinely want to be helpful.

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

yeah it disables itself when you remove your phone number

crazysim
May 23, 2004
I AM SOOOOO GAY

Rufus Ping posted:

yeah it disables itself when you remove your phone number

ah! i did not see the nuance. sorry. i thought you meant the mobile app. that's bad. it'll be susceptible to the hoodwinked carrier csr thing then.

flakeloaf
Feb 26, 2003

Still better than android clock

James Baud posted:

Popup note on your customer file that a rep may or may not even read, easy to socially engineer your way past because people genuinely want to be helpful.

jennifer joy
secured her toy
and zachary zugg
helped breach it

wanna be helpful? don't let anyone who isn't me feel free to be me

James Baud
May 24, 2015

by LITERALLY AN ADMIN

flakeloaf posted:

jennifer joy
secured her toy
and zachary zugg
helped breach it

wanna be helpful? don't let anyone who isn't me feel free to be me

I'd say the real trick is to have "not your real name" on your phone account. Prepaid in a relative's or just totally fake name. I don't do it, but I've considered it.

communism bitch
Apr 24, 2009
Y'all sound so depressed and cynical about every method of protecting user data like login credentials. If 2fa using my phone isn't going to keep my neopets account safe what is?

spankmeister
Jun 15, 2008






I use antifa on all my accounts

Maximum Leader
Dec 5, 2014
using a 2fa code tattooed to your dick

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
get ready for drm on html5 video https://www.eff.org/deeplinks/2017/07/amid-unprecedented-controversy-w3c-greenlights-drm-web

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

I use antifa on all my accounts

preparing for imac pro eh?

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news

cinci zoo sniper posted:

if you ever say it "zero day" to a british person you'll be laughed out into the loving oblivion. do you also "zero" when dictating a phone number with 0 in it?

i am a british person who says "zero day"

cinci zoo sniper
Mar 15, 2013




Mr SuperAwesome posted:

i am a british person who says "zero day"

zero really? :downsrim: but yeah thread opinions and my limited experiences are different things. not that it matters much, im just more and more curious how oh-day hasn't seen broader, i guess, adoption due to being easier and shorter to say while retaining the clarity of meaning

Crime on a Dime
Nov 28, 2006

Mr SuperAwesome posted:

i am a british person who says "zero day"

GET HIM

geonetix
Mar 6, 2011


if you say anything else than "zero day" you should probably not be in this kind of business

cinci zoo sniper
Mar 15, 2013




geonetix posted:

if you say anything else than "zero day" you should probably not be in this kind of business

thankfully im a financial analyst :v: just interested in reading and talking about dangerous computers

Mr SuperAwesome
Apr 6, 2011

im from the bad post police, and i'm afraid i have bad news
obviously SMS 2FA is bad, but if you're using gauth/totp whatever and lose your phone, what then?

cinci zoo sniper
Mar 15, 2013




Mr SuperAwesome posted:

obviously SMS 2FA is bad, but if you're using gauth/totp whatever and lose your phone, what then?

i mean, how different is it from loosing phone with sms 2fa, or do your carriers restore stolen numbers?

geonetix
Mar 6, 2011


cinci zoo sniper posted:

i mean, how different is it from loosing phone with sms 2fa, or do your carriers restore stolen numbers?

they do, but the attack surface with sms 2fa is not stolen phones according to the defcon folk


on that note at work we had our first official mention of APT this week; achievement unlocked!

communism bitch
Apr 24, 2009

Maximum Leader posted:

using a 2fa code tattooed to your dick

Well that would guarantee security via obscurity, but I don't know if three characters would be secure enough....

susan b buffering
Nov 14, 2016

Mr SuperAwesome posted:

obviously SMS 2FA is bad, but if you're using gauth/totp whatever and lose your phone, what then?

pretty much every 2fa scheme ive seen has a set of recovery codes you can print off, so do that?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Mr SuperAwesome posted:

obviously SMS 2FA is bad, but if you're using gauth/totp whatever and lose your phone, what then?
just use the gauth recovery code when you set up gauth on your new phone

like how is this even a question

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

cinci zoo sniper posted:

i mean, how different is it from loosing phone with sms 2fa, or do your carriers restore stolen numbers?

where are you, if I might ask, that losing your phone means getting a new phone number?

cinci zoo sniper
Mar 15, 2013




Subjunctive posted:

where are you, if I might ask, that losing your phone means getting a new phone number?

latvia. a significant portion of population uses prepaid for which im far from certain about the possibility to restore number in the case of theft. with contract plans that should of course be possible

Chalks
Sep 30, 2009

Mr SuperAwesome posted:

obviously SMS 2FA is bad, but if you're using gauth/totp whatever and lose your phone, what then?

My phone broke so I emailed the company and asked them to turn off 2fa and they did it no questions asked. lol

Doom Mathematic
Sep 2, 2008
"Zero" is a number. "Oh" is just a digit. It isn't called "0-day" because you have oh days to patch it.

spankmeister
Jun 15, 2008






Beverly hills nine zero two one zero

spankmeister
Jun 15, 2008






By the way the plural is zeroes day

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

By the way the plural is zeroes day

argh

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
well SMS 2fa saved the day for me I guess. Thanks Microsoft.

flakeloaf
Feb 26, 2003

Still better than android clock

spankmeister posted:

By the way the plural is zeroes day

it's pronounced jeeroes day

Adbot
ADBOT LOVES YOU

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Google makes you add a phone number before turning on 2fa because extensive UX research has shown that users are too stupid not to gently caress it all up and lock themselves out of their account. You can remove the phone number later if you're a l33t power user, but that's probably the motivation for other sites requiring a phone number association when using 2fa.

  • Locked thread