Pages:
Author

Topic: 2FA Google authentication - page 2. (Read 452 times)

newbie
Activity: 1
Merit: 0
November 09, 2020, 10:41:14 PM
#10
Hi tech guys,
Please help me with my question concerning 2FA. Do you think it's essential security measure, does it work very well? Then Google will have my security code, right?
I'm just afraid to do smth wrong like lose password or QR-code or smth and lose my crypto.

Yes, it's essential. 2FA will help you secure your account including your crypto on hackers. I'm Actually using it and my account is secured.
HCP
legendary
Activity: 2086
Merit: 4318
November 09, 2020, 10:34:23 PM
#9
Yes I know it now, you can ceck my last comments. Here, my misunderstanding is because the service just mentioned G2FA only, so i think if it only works for google 2FA only.
Yeah, it's a common misconception that "Google Authenticator" is a "Google Only" service... you're not the first (and won't be the last) person to get confused by that. I certainly was when I first started using Google Authenticator several years ago. The sites that have implemented the 2FA service are partly to blame by calling it "Google 2FA" etc...

And Google really should implement a "proper" (encrypted) backup solution for Google Authenticator. Relying on users to safely store the individual "secrets" themselves is messy and prone to error. Authy, Aegis and Authenticator (Plus) (and others) have all been able to come up with solutions, I'm not sure why Google can't? Huh
legendary
Activity: 2324
Merit: 1603
hmph..
November 09, 2020, 06:08:11 PM
#8
You can get secret code and import it into any 2FA app. It works universally.

Yes I know it now, you can ceck my last comments. Here, my misunderstanding is because the service just mentioned G2FA only, so i think if it only works for google 2FA only.
legendary
Activity: 1512
Merit: 4795
Leading Crypto Sports Betting & Casino Platform
November 09, 2020, 02:45:00 PM
#7
About 2FA google authenticator, i didn't face problems using it but i remember hearing that it has been somehow compromised and some hackers succeeded to login users accounts using it. Not sure about this info so maybe someone could correct it .
I still remember of a news I read on cointelegraph this year about google 2fa being compromised. It is not the fault of the app itself, the hackers used tricks to make victims download a trojan horse that was installed on the devices. If someone can not handle anything about malware, how can he use bitcoin wallet successfully or using 2fa app successfully.

Although, I am not a fan to any google products, because google are privacy invaders. Also I can not use Authy, although it is much simple to use by synchronizing the backup on cloud, of which I do not believe in such. I prefer to keep my backups offline which is the safest.

I Don't recommend to use 2FA google authenticator as its's almost impossible to recover your account once you lost your codes. I've lost my device in which my codes were saved and i then i realized that i am unable to access my google account even my phone number was registered in gmail . I've lost all my data and trust me It sucks.
If because you lose your code is the reason you do not recommend any 2fa, you are then wrong. The best you can do is to make a backup of the 2fa backup code and safely store it somewhere safe from attackers and damages and yet also still accessible to you.  Authy can the best for you then, but I can not recommend it due to what I mentioned above about synchronizing with online cloud which makes backup recovery easier. 

The best 2fa I have known and that I can recommend are Aegis, authenticator and andOTP.
hero member
Activity: 2338
Merit: 757
November 09, 2020, 02:21:20 PM
#6
I Don't recommend to use 2FA google authenticator as its's almost impossible to recover your account once you lost your codes. I've lost my device in which my codes were saved and i then i realized that i am unable to access my google account even my phone number was registered in gmail . I've lost all my data and trust me It sucks.
All of your logins protected by 2FA google authenticator have each a backup code that can be used in another device. And if you are looking for a more secure option, try Authy ; it's a nice alternative for google authenticator and can be secured by a single code backup which can be used to recover the app with all the accounts within if your device gets compromised or you accidentally erase the app.
About 2FA google authenticator, i didn't face problems using it but i remember hearing that it has been somehow compromised and some hackers succeeded to login users accounts using it. Not sure about this info so maybe someone could correct it .
newbie
Activity: 14
Merit: 1
November 09, 2020, 01:39:35 PM
#5
I Don't recommend to use 2FA google authenticator as its's almost impossible to recover your account once you lost your codes. I've lost my device in which my codes were saved and i then i realized that i am unable to access my google account even my phone number was registered in gmail . I've lost all my data and trust me It sucks.
legendary
Activity: 3640
Merit: 1571
November 09, 2020, 01:36:03 PM
#4
the shared secret is also not the same as your bitcoin private keys or seed. it is only used to generate one time passwords for authentication purposes.
legendary
Activity: 2114
Merit: 1293
There is trouble abrewing
November 09, 2020, 11:35:26 AM
#3
it depends on the reason why you are using 2FA (through Google Authenticator). for example for an account that you must have and there is no other ways around it (like your exchange account) it is an excellent additional security and you must have it. but for your wallet account (of custodial type), you should rethink using that wallet because your money is already not-safe since you don't control it, adding the 2FA will secure your account not your money.

Then Google will have my security code, right?
as far as i know the software does not broadcast anything unless you explicitly create a backup of your keys. so Google won't know your codes.
hero member
Activity: 1722
Merit: 801
November 09, 2020, 08:59:17 AM
#2
You can get secret code and import it into any 2FA app. It works universally.

Authentication: Types, Risks/ Attacks, Advice. The clarification from o_e_l_e_o  is perfect.
if most of service currently just have Google 2FA on their services?. So far, I'm just seeing it on service i use no other 2FA options except SMS/email  verification.
I'm not entirely sure what you mean here, perhaps because I do not use any Google products so I'm not aware of what their 2FA options are. If a site such as a crypto exchange says "Scan this code with your Google Authenticator App", then you should be able to use any 2FA app. I have certainly done this in the past and it works fine.

If the service only offers SMS or email verification for 2FA, then you obviously can't use an app - you can only use what the site offers. Both of these are not great choices, but you can make it slightly better by using a different email address with a different password to the one you use to log in to the account, or by using a burner phone with a number you do not use for anything else and which you never use to access the services in question.

You can choose open source 2FA apps to use.
Most of these are not open source and do not allow proper encrypted back ups. Google Authenticator in particular is awful from the regard. FreeOTP is no longer in development. Here are the apps you should be using:
Android - Aegis or AndOTP
iOS - Tofu or Authenticator
jr. member
Activity: 42
Merit: 2
November 09, 2020, 08:20:24 AM
#1
Hi tech guys,
Please help me with my question concerning 2FA. Do you think it's essential security measure, does it work very well? Then Google will have my security code, right?
I'm just afraid to do smth wrong like lose password or QR-code or smth and lose my crypto.
Pages:
Jump to: