• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

"2-Step Verification" - Okay Google, That's Great, But What If...

Oct 18, 2006
2,185
3,927
...I lose my phone?

What if, when my contract is up with this phone, and I go to get another (assuming I even do, because I have been toying with the idea of trying life without a mobile phone), I decide to go with a bare-bones "dumb" phone instead of a smartphone?

THis has to be one of the mst irritating things ever. And even though I have checked the "do not ask again on this device" box on the sign-in page, Google still texts me an often-slow-to-arrive notification where I have to tap "yes, it's me" to get into my damn account.

**** outta here Google...:meh:
 
Last edited by a moderator:
I’d rather have more two factor authentication than less. If you wanna live without a smart phone you can. Lots of people do that. It’ll mean some things like this will be more difficult. Although dumb phones get texts too.
 
All of my personal and business FaceBook and Instagram accounts were recently hacked and deleted because I didn't have two factor authentication turned on. My credit card was charged $280 a day and the only way for me to stop it was to cancel it and get a new one.

Use two factor authentication.
The extra seconds it costs are worth it.
 
I'm still completely baffled by those who still don't have a smart phone by choice. Yes, they can be a time suck, but if you don't use social media apps, the time suck decreases drastically. I can't imagine living without it for GPS, email, weather, music, etc. And I work for a tech company, where it's practically required.
 
I'm still completely baffled by those who still don't have a smart phone by choice. Yes, they can be a time suck, but if you don't use social media apps, the time suck decreases drastically. I can't imagine living without it for GPS, email, weather, music, etc. And I work for a tech company, where it's practically required.
I’ll be the first to admit I’m addicted to my phone. On the extraordinarily rare occasion I leave somewhere without it, I’ll go back there to get it. But that’s my problem. I can exercise self control and use it less if I want to. Plenty of people have them and aren’t glued to the screen. But I like mine. It’s my kindle. I play games I’ve invested years into. GPS, weather, email, music, texting, phone calls only when necessary. It’s my primary computing device. Talkbass is the only social media I use and it’s barely social media. I also like taking pictures of squirrels. Good times.
 
Last edited:
What part of this requires a smart phone? You just need to keep the same number and they text confirmation codes etc. If you had any computer with email access and any mobile phone you should be able to this. Perhaps there are other authentication factors I have not turned on that use a smart phone (biometrics is about all I can think of currently).
 
  • Like
Reactions: Gorn
What part of this requires a smart phone? You just need to keep the same number and they text confirmation codes etc. If you had any computer with email access and any mobile phone you should be able to this. Perhaps there are other authentication factors I have not turned on that use a smart phone (biometrics is about all I can think of currently).
Maybe some services only email and not text?
 
  • Like
Reactions: TOOL460002
I’ve got 2FA for my work O365 account. The ping goes to the Authenticator app on my personal iPhone. I upgraded that and do you think I can get it to go my new iPhone? Nope. Or my recently issued work iPhone? Nope again. So now I have three iPhones on my desk until I can figure this out. There’s not a help desk out there that has been able to unf%%% this for me.
 
Maybe some services only email and not text?
What part of this requires a smart phone? You just need to keep the same number and they text confirmation codes etc.

Also generally the best form of 2FA is some form of authenticator app that periodically generates codes. Phone numbers can be spoofed/intercepted and email well...

More and more frequently they are offering set recovery codes to hold onto in case you lose the device somehow but you can transfer accounts to a new app if you get a new device.
 
I’ve got 2FA for my work O365 account. The ping goes to the Authenticator app on my personal iPhone. I upgraded that and do you think I can get it to go my new iPhone? Nope. Or my recently issued work iPhone? Nope again. So now I have three iPhones on my desk until I can figure this out. There’s not a help desk out there that has been able to unf%%% this for me.
If you are using the Google authenticator (the one that looks like a grey dial) tap the ... next to 'Search for accounts' and select 'export accounts'.

Then, scan the QR code with the new app after tapping the plus in the bottom right corner and 'Scan a QR code'.

Unfortunately that's the only one I use that's not service-specific so I don't have any experience otherwise but if you have a specific one I might be able to figure it out.
 
I’ve got 2FA for my work O365 account. The ping goes to the Authenticator app on my personal iPhone. I upgraded that and do you think I can get it to go my new iPhone? Nope. Or my recently issued work iPhone? Nope again. So now I have three iPhones on my desk until I can figure this out. There’s not a help desk out there that has been able to unf%%% this for me.

Which authenticator app are you using?

-Mike
 
Also generally the best form of 2FA is some form of authenticator app that periodically generates codes. Phone numbers can be spoofed/intercepted and email well...

More and more frequently they are offering set recovery codes to hold onto in case you lose the device somehow but you can transfer accounts to a new app if you get a new device.
I remember my dad had a physical device that generated codes that allowed for remote access to company data. Weird dongle thingy. Could a text message be intercepted? It would either mean all your texts are compromised or there is a period of time in which they get diverted? Sorry in advance, a lot of my spoofing/interception knowledge comes from Oceans 11 and 13.
 
I remember my dad had a physical device that generated codes that allowed for remote access to company data. Weird dongle thingy. Could a text message be intercepted? It would either mean all your texts are compromised or there is a period of time in which they get diverted? Sorry in advance, a lot of my spoofing/interception knowledge comes from Oceans 11 and 13.
Yeah the physical devices are kind of like the super-secure version that nowadays we're essentially turning our phones into. Physical devices are still in use here and there.

It is technically possible for calls/texts to be intercepted and rerouted, though not super likely. It would only be a compromise of any new texts from the point of diversion, not a full history. (Think of when you get a new phone, even if you move the SIM card over, the texts don't come with it, only with an actual device backup/restore.)

I don't think currently many would have to be concerned with their texts being intercepted unless they're in a sensitive position or particularly rich and famous but methods are getting more advanced all the time.

Also no worries at all, it's a pretty interesting space right now as cyber security is getting more important at a pretty constant rate.
 
  • Like
Reactions: TOOL460002