My largest worry is that coupled with Google's infamous lack of customer support, it might be very difficult to get into your account should something happen to your phone. I know it's something of a pain to have an authenticator removed in World of Warcraft if you lose it or it breaks, but at least there you have a phone number you can call that will let you eventually talk to a human being.
Does anyone know what Google's plan is for lost/broken authenticators?
Hey Matt, seeing your comments on this post reminded me I wanted to say thanks for making so many comments here on HN. It's awesome to hear from someone directly at Google in your role. Very cool. I'm sure a lot of us think very highly of the work you all do at Google. You and Apple, really, kick ass in this industry.
If you don't have the OTP codes and didn't set up a backup, and can't access any computer/device where you have access from logging in during the past 30 days:
3) You'll need to fill out an account recovery form to verify ownership of the account. Take time to answer each question to the best of your ability. The form was designed to ensure that no one can gain access to your account except you. Since Google doesn't collect a lot of information about you when you sign up for an account, we will ask you questions like when you created your account, what Google services you use, and who you email frequently (if you use Gmail) to make certain you are authorized to access your account.
I've been called on a few occasions to recover the gmail accounts of family and friends and it hasn't worked once, even when supplying reasonably accurate data.
Same here; that's why I forwarded the oldest email in my account to another address, took note of the date on it, and saved it to my hard drive; headers intact.
Keep in mind each fallback/recovery option like secret question, secondary email address, OTPs etc. is an extra attack vector too. So would be good idea to store that old email somewhere securely too...
> 1) When you activate the service, you get a list of ten OTP codes that you should print and store in a safe place.
The main problem with having a list of randomly generated OTP codes is, it very obviously looks like a list of randomly generated OTP codes!
A far better approach is to use the lines of a poem, prayer or even a list of motivational slogans or a grocery shopping list. You can even get more tricky with things like not using the first character or word of the lines. You always need to assume your list of OTP's will fall into the wrong hands, so your list should be protected by at least obfuscation and plausible deniability.
99.9% of the time you aren't worried about someone getting your wallet and taking your password - You are worried about people phishing you, snooping, or otherwise cracking your password.
You'll get a lot more bang for your buck defending against the high-probability attacks then being concerned about the theoretical, but highly unlikely vectors.
Does anyone know what Google's plan is for lost/broken authenticators?