news.volyx.in

Tell HN: It is impossible to disable Google 2FA using backup codes

657 points by gravitronic · 1324 days ago · 337 comments on HN

Article summary

The author of the post lost access to their Google Authenticator settings after breaking their phone and is unable to disable 2FA or generate new backup codes using their existing backup codes. The 2FA settings page requires re-authentication, but only allows entry of a 2FA code, not a backup code. This situation highlights a potential recovery issue with Google's 2FA system. The author is seeking help or guidance on how to resolve this issue.

Main themes

  • 2FA recovery issues
  • Google Authenticator limitations
  • Security design flaws
  • Recovery mechanisms
  • Authenticator app alternatives
  • TOTP seed management

What commenters say

  • Google's 2FA system has a design flaw that prevents users from disabling or altering 2FA after using a backup code.
  • Using a third-party authenticator app or saving the TOTP seed can help avoid this issue.
  • Relying solely on backup codes for 2FA recovery is insufficient and can lead to account lockout.
  • The lack of a straightforward recovery process for 2FA is a significant security vulnerability.
  • Some users argue that this is not a security flaw, but rather a result of bad design or incompetent support.
  • Others suggest that keeping the TOTP seed or using a different authenticator app can mitigate this issue, but this may not be obvious to all users.
  • There is disagreement on whether saving the TOTP seed or QR code is a secure practice, with some arguing it defeats the purpose of 2FA and others seeing it as a necessary backup measure.