Hacker News new | past | comments | ask | show | jobs | submit login

Sorry, I should be clearer: to login to Google on a new device, you typically need to accept a prompt on an old device. But if your old device is dead, that's not possible. Authenticator does TOTP and things, which is typically not adequate for logging in (even though it _should_ be).



I'm not using Google Authenticator or anything like that but when my old phone dropped somewhere at the bottom of a river all my banking apps, which do 2FA, had a way to let me start again on my new phone. Services that don't assist their users in a disaster recover scenario are severely lacking.


Yes they are, and yet they exist.


The prompt on an old device is just one of the MFA options you can use. You can also use a security key (e.g. Yubikey, Solokey, etc.).




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: