Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wanted to point out a very serious problem related to this post: Google will no longer simply accept totp as a verification but insists on sending you a notification to one of your devices.

Now I can't just use KeepassXC to get into Google anymore, I have to use my phone. The problem that the OP points out provides very real and poignant evidence that this is not only annoying but dangerous.

What is it that companies have against totp? It's starting to get obnoxious. I want to use it everywhere but some companies have stopped honoring it.



Yes!!! This has happened to me before. I entered my TOTP and then Google forced me to open YouTube on my phone. I didn't have YouTube (I deleted it), so I had to re-installed the YouTube app and sign in through that before I could login to whatever I was initially trying to do.


This makes absolutely beyond zero sense given how Google accounts work on Android, or just in general.


I have an iPhone, but it still makes no sense. I wish I could opt-out of authenticating through Google's apps and just use my TOTP. It's annoying.


Unless something changed, you can enable SMS MFA, add TOTP as a secondary MFA option, then remove SMS to only have TOTP. I did this a couple years ago after someone explained it to me. It is stupid, tedious, and still requires giving up your phone number to Google, but it may help you as it did me.

I also use KeePassXC and have had phone issues in the past, so I hate relying on my phone for anything important (it's also just not as convenient as copy/pasting from KeePassXC).


That's just my point: it has changed.


This came up two months ago and I posted screenshots of a new 2FA setup and it very clearly allowed registering a TOTP or Yubikey without SMS. You just had to actually spend 10 seconds looking at the page and seeing there was a link for it.


> What is it that companies have against totp?

It isn't useful for tracking since it is private.


I get an annoying message to use my phone, but then there is an option to authenticate using TOTP instead. Do you not see the same thing?


You need to remove your device as a 2FA device. then you can TOTP code as only entry point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: