Hacker News new | past | comments | ask | show | jobs | submit login

Yeah, same with my company. "DO NOT USE GOOGLE AUTHENTICATOR" is littered throughout our Intranet and onboarding docs in bold letters with recommendations for different options. And people still use it and lose their codes all the time.

Now it's tied to the Google Account which means it'll be tied to either their personal or work account and now we have to worry about personal account bans removing their 2FA or when they leave the company, our suspension process killing personal 2FA that were synced via the wrong account.




The best and safe way is to save qr codes and or strings to a seperate password database (I use keepass).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: