Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For major sites, FAMG having access to email is not enough in my experience. I was recently locked out of my Instagram account and lost my 2FA. Instagram required me to contact support from a known previously associated email, but on top of that I had to upload a picture of myself holding a piece of paper with a handwritten nonce and they checked against my previously uploaded pictures. I also had to wait a period of time before they would telling me what nonce to use and starting the verification process.

I have heard stories of people not being let in and having to contact friends who work at Facebook and have access to the internal support queue. I know my friend had to do something similar at Google and have a friend make a internal support ticket when they were locked out of a gmail account. That experience with Instagram is the reason I moved away from using DUO for everything to Aegis where I can copy a password encrypted backup of my 2FA secret keys like I would any file. I am grateful I learned that lesson by losing 2FA to a single account.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: