Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Losing a second factor is an underappreciated threat. Adding 2fa can definitely increase the risk of losing an account, and a responsible person will weigh the costs and risks of doing so.

You can reduce that risk, e.g. by keeping a piece of paper safe somewhere, but it's never gone entirely. What if your house burns down? Oh, a fire safe. What if that gets stolen? A safety deposit box, etc. Those all have their own risks and costs as well.

It's completely reasonable to not add 2fa to your accounts, if you believe that your ability to keep safe a second factor is less than the chance of someone guessing your password.

I have lost (/stolen/destroyed) more physical possessions than I have had accounts hacked. By a lot.



Exactly: There are risks: flood, fire, stolen, lost, (I) broke (Smartphone, yubikey, usb, etc), broke (itself), kids, washing machines, etc.

I really like how our country TLD registrar handles 2nd factor recovery: nic.lv. As long as I'm alive and myself, I can disable 2FA without my second factor.

We have ubiquitous ID card which servers as passport. And it has smartcard there used to sign documents and communicate with gov/corp entities. If we lose 2nd factor, we can submit application, electronically signed, email it to request disabling 2FA. Or I can show up in person with my ID card/password and request disabling 2FA.

What I now noticed is I can pay for my domain and in payment notes request disabling 2FA. This looks like a weak point - I wonder if they correlate WHO paid for that domain name.

This obviously can't work for international services as they won't trust our ID card issuer.

Otherwise piece of paper with backup codes are: 1) impossible to retrieve remotely 2) easily replicated and distributed


> This obviously can't work for international services as they won't trust our ID card issuer.

Why not? They don't need to trust the issuer to say "this certificate is X person", they just need the issuer to say "this certificate is the same person as this previous certificate" (presumably via distinguished name matching).

As long as the issue vouches that it's the same person that initially registered the domain, it should be fine, regardless of whether the actual identity of the person is correct.


Sorry it can, but just not NOW :) Different countries would have to establish/trust various issuers and such and there would be "supported countries list" resulting in many countries left out etc.


There's actually an EU standard for using the smartcard functionalities of the ID cards to provide strong authentication/KYC-grade auth. EIDAS, iirc.


> We have ubiquitous ID card which servers as passport. And it has smartcard there used to sign documents and communicate with gov/corp entities.

Is this Estonia? A while back some friends of mine were applying for "e-residency" in Estonia partly for the ID card.


Latvia, neighboring country.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: