Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or just write down the TOTP seed on paper backups instead of backup codes.




Works for google (should!) but man there are some platforms that don’t expose the Totp code, or let you redisplay it! Sometimes they make you remove the old one before you can make a new one, too.

So don't put it off until it is too late -- if you haven't already, regenerate and copy TOTP seeds to paper now.

When you set up TOTP on a new account, copy the TOTP seed to paper then and there, resist the "I'll do this later".


If it isn't backed up it doesn't exist.

Corollary (likely unpopular I'd hazard) - hardware token implementations that I can't back up to paper don't exist as far as I'm concerned.


My policy is to enroll multiple WebAuthn keys and treat the second, third etc. key as the backup.

I stopped using webauthn for this reason, plus the fact requires a ton of intrusive browser features and access. This surely will enrage most readers, which itself reveals an interesting conditioning that has taken place.

Few, but screenshot the qr code and print it out.

Even Facebook supports totp it's just well hidden.


Print or print to pdf works but feel terrible leaving pdf and printed QR codes around when I have an actual handful of HSM/security dongles in that very same desk drawer :(

Instagram has them too.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: