O
2

PSA: I was using two-factor authentication wrong the whole time

Last week I got locked out of my email because I had SMS 2FA set up and my phone died during a 12 hour shift at the station. Turns out I never saved the backup codes, and the recovery process took me 3 days of calling support. The moment I realized my mistake was when the rep asked if I had written down those codes and I just sat there silent. Has anyone else been burned by relying on SMS codes instead of an authenticator app?
2 comments

Log in to join the discussion

Log In
2 Comments
shane244
shane24418d ago
You say you were "using two-factor authentication wrong" but honestly I think SMS codes get way too much hate. Not everyone wants to install another app on their phone, you know? And let's be real, backup codes are easy to lose too (I've taped mine to my monitor at work before and that's a security risk in itself). The real problem here isn't SMS, it's that you didn't have a backup plan for your phone dying. A simple prepaid flip phone with a spare SIM in your car would've saved you that headache, and it's cheaper than a whole new phone. Plus, authenticator apps can fail too if your phone brickes or you forget to back up the seeds before a factory reset. SMS is universal, it works on any phone, and if you keep a backup number on a cheap device somewhere, you're golden.
7
lane.angela
Yeah I actually read somewhere that SIM swapping attacks have been on the rise lately, so relying on SMS for 2FA isn't as safe as people think even with a backup phone. That backup code taped to your monitor thing made me laugh though, I've done similar stuff lol.
4