Remix.run Logo
beej71 2 days ago

It's a good reminder to everyone who uses 2FA. Be sure you have multiple ways in for when your phone becomes unusable.

teekert 2 days ago | parent | next [-]

Yeah I lost my phone some months ago. Quite the panick because I am also MS365 admin for 2 orgs... 3 hr later a trucker called my wife using the iPhone emergency contact feature (what a hero). Now I bought an iPad that stays at home and has all the apps. Honestly, I should also put a second phone somewhere else.

Also frees me up to experiment a bit more on the Phone side (just got a Pixel 10 with GrapheneOS), although, so far it all just works (with Google Services of course).

It's annoying that you really do need either Android or iOS nowadays. If only we could virtualize one of those platforms properly (and free as in freedomly).

bentcorner 16 hours ago | parent | prev [-]

At one time I heeded advice not to rely on 2FA SMS because you know it's not secure, so I kept everything in a 2FA app.

Well through an unfortunate sequence of button clicks I wiped my 2FA state and had a hell of a time getting into the apps that I removed my SMS from.

In theory yes SMS is an attack vector but personally the safety and convenience of SMS is more valuable than the odds that someone impersonates me at my mobile provider.

(Also I stopped using that 2FA app and just use a keepass db stored in onedrive).