54

My phone with 2FA codes has died... again... for the 3rd time in something over 2 years (average Poco X3 Pro experience).

I've used the Cisco Duo app, mainly for the convenience of automatic backups. After all, this has saved me the last time my main phone died. Connect GDrive, download DB, enter passphrase to decrypt, there you go.

I've turned on my still barely functioning 2017 Moto G5s Plus. There I had the Duo app. Upon opening it says something along the lines of "Device offline, showing on-device accounts only."
How does that read to you? Auto-sync, I thought.
I connected to the internet, refreshed the app, nothing. I go to settings, check the backup... horror!
"Last backup: October 6th 12:06"
I opened the app at 12:06.

Why would you update the backup if it has more recent timestamp than current version?
"Hmm... this phone last backed up in 2023, most recent backup on cloud is 2024, yep, OVERWRITE IT WITH 2023 VERSION!!"

Hmm... this also means I've lost access to my Cisco NetAcad school account...

Welp, lesson learned, switching to Aegis.

Since disabling TOTP requires TOTP token, I have no way to disable it. I hope the instance admin can, but SDF has far more important shit to care about.


I am thinking on getting something crazy like Ulefone Armor 24 brick. Though it lacks things like 5G, stereo speakers, and 4K video recording, but I can afford it and have it shipped tomorrow morning.

top 25 comments
sorted by: hot top controversial new old
[-] julianh@lemm.ee 22 points 1 month ago

Pro tip: if you have nextcloud you can set aegis to backup to a folder synced to the cloud, giving you automatic cloud backups. It can keep multiple copies too to prevent a situation like that happening.

But yeah, sorry that happened, hope you find another way to access those accounts.

[-] infinull@lemmy.dbzer0.com 2 points 1 month ago

I do this, but with keepass (keepass on all devices and then sync with nextcloud). Saved my butt a few times, I can go into the file history and pull an old version of the keepass db out of it, and then keepass has a merge feature, so I can pull the old file out, and merge with current to find missing records.

Anyway... backups good.

[-] folekaule@lemmy.world 16 points 1 month ago

This is why more sites need to support multiple 2FA devices. Most of them support a fallback like SMS, but they restrict you to one key. I can't think of any reason to restrict this other than trying to "keep it simple" for users, which is just silly.

[-] user224@lemmy.sdf.org 14 points 1 month ago

Or implement backup codes. I have backup codes for sites like Google. They are some longer single-use codes that can be used to login and reset 2FA. A lot of sites have that.

But yeah, I never thought of multiple keys. I could simply enroll and un-enroll each device. Safer and more convenient.

[-] folekaule@lemmy.world 1 points 1 month ago

I think everywhere I use 2FA they also have downloadable backup codes, but you have to store those securely somewhere also.

[-] TheSaus@lemmy.dbzer0.com 3 points 1 month ago

This is why i like physical hardware keys

[-] zea_64@lemmy.blahaj.zone 1 points 1 month ago

I yearn for a day user agents can not suck. Backups and syncing should not be this hard!

[-] anas@lemmy.world 12 points 1 month ago* (last edited 1 month ago)

Sorry about that, but thank you for this post, I had no idea Lemmy finally implemented 2FA.

EDIT: On second thought, there actually is no way to generate a recovery code, so I think I’ll wait a little longer.

[-] 3dogsinatrenchcoat@slrpnk.net 5 points 1 month ago

recovery code tip: just save the secret it gives you and then you can put it in another app

[-] anas@lemmy.world 2 points 1 month ago

That’s actually not a bad idea, thank you!

[-] user224@lemmy.sdf.org 2 points 1 month ago* (last edited 1 month ago)

OK, I recovered it. It seems Lemmy (at least 0.19.3) has no rate limiting for trying 2FA codes.

Edit: Fixed typo (seem -> seems)

[-] anas@lemmy.world 3 points 1 month ago

Oh, this doesn’t sound very secure

[-] AI_toothbrush@lemmy.zip 6 points 1 month ago

Ahh i had this with a hungry shark world account. I was huge on the game, grinded insane from the start of the game so i had a ton of shit that was only available in older versions and when i moved to a new phone and wanted to restore the backup it overwrote it losing me years of data. Snorted copium for a few weeks but gave up after. Never played it since then.

[-] notthebees@reddthat.com 4 points 1 month ago* (last edited 1 month ago)

If you used GDrive, it might have kept the old backup but version controlled it instead of deleting it.

[-] user224@lemmy.sdf.org 3 points 1 month ago

Perhaps, but it seems this is a hidden portion of Drive that only the app itself can access.

[-] notthebees@reddthat.com 2 points 1 month ago

Check to see if it's an orphaned file. https://support.google.com/drive/thread/236647252/what-is-an-orphaned-file?hl=en What is an orphaned file? - Google Drive Community

[-] user224@lemmy.sdf.org 2 points 1 month ago

Nope, but thanks.

It uses the hidden appDataFolder and it seems the files in it can only be accessed via those apps.
I found some more (but old) info here: https://stackoverflow.com/questions/22832104/how-can-i-see-hidden-app-data-in-google-drive

Maybe I could figure out something from those examples, but based on Google there's just mere 4KB of data. That doesn't sound promising.

[-] notthebees@reddthat.com 1 points 1 month ago

I had realized after I posted that. Didn't actually edit the comment.

[-] scroll_responsibly@lemmy.sdf.org 4 points 1 month ago* (last edited 1 month ago)

@user224@lemmy.sdf.org Try either emailing the sdf membership email address or sshing onto one of their hosts and posting on BBOARD.

Edit: …if you haven’t already

[-] user224@lemmy.sdf.org 4 points 1 month ago

Already did, but thanks.

I remembered them resetting 2FA (per-request) when Lemmy used I think SHA256 instead of SHA1 and a lot of people got locked out.

[-] nifty@lemmy.world 3 points 1 month ago

Well, there’s no karma so if you’ve saved threads or comments, I’d quickly archive those somewhere. Then just link to this account in your new account bio

[-] renzev@lemmy.world 5 points 1 month ago* (last edited 1 month ago)

Fun fact, lemmy does have a karma system, it's just hidden from the interface! There's even a public API method that you can use to check your karma.

[-] RicoBerto@lemmy.blahaj.zone 7 points 1 month ago

Wow, mines much higher than I thought!

[-] nifty@lemmy.world 4 points 1 month ago* (last edited 1 month ago)

Thanks, good to know! I like how easy it is to check

[-] rain_worl@lemmy.world -1 points 1 month ago

spoileri did the same thing but in reverse, the link text was the rickroll url, but it went to the api page instead

this post was submitted on 06 Oct 2024
54 points (90.9% liked)

196

16501 readers
2168 users here now

Be sure to follow the rule before you head out.

Rule: You must post before you leave.

^other^ ^rules^

founded 1 year ago
MODERATORS