Jump to content
NoahUK

Lost 2FA codes

Recommended Posts

My phone factory reset and so I've lost my Google authenticator codes. Any way of getting them back or turning off 2FA so I can get new ones? Unfortunately I deleted the original email with the code in it, which I now realise is the only backup. 

Share this post


Link to post
Share on other sites

Rofl. EVERY. FUCKIN'. TIME. "I don't pay attention to anything so instantly factory reset my phone without thinking and I delete important RECOVERY mails".

It's just not funny anymore how stupid people can be.

 

For anyone else reading this post for fun;

Print out/backup the emails that can make you recover 2FA. (FOR ANY account/game/whatever the fuck you use 2FA for).

Setup Google Backup on your phone, go grab an old phone and test out if you set it up correctly that it backs up your Authenticator (though should not be needed if you backup the recovery e-mails).

Have common sense.

Share this post


Link to post
Share on other sites

Ye it was my first time using 2FA. Installed it after being hounded ingame and guess I didn't quite know how it worked. As for my phone, it broke,  I didn't make a conscious decision to wipe it. 

Thanks for reacting so effusively though...

 

Share this post


Link to post
Share on other sites

Kind of defeats the entire purpose of 2FA doesnt it though. I'm not trying to be a dick, just stating facts.

Now, onto being a dick.

User: Pliz mr. admin-guy i lost my 2FA?! Please delete it so I can logon agin!

admin: Ok lol ¯\_(ツ)_/¯

Share this post


Link to post
Share on other sites
14 minutes ago, Storfan said:

Kind of defeats the entire purpose of 2FA doesnt it though. I'm not trying to be a dick, just stating facts.

In which way is the purpose defeated?

Share this post


Link to post
Share on other sites
3 minutes ago, Ambervale said:

In which way is the purpose defeated?

If you can just "lose" your 2FA and then ask admins to remove it, doesnt that open up as a security concern? I could be wrong ofcourse.

Share this post


Link to post
Share on other sites
9 minutes ago, Storfan said:

If you can just "lose" your 2FA and then ask admins to remove it, doesnt that open up as a security concern? I could be wrong ofcourse.

Exactly, you're completely right.

Maybe hackers already have my password but can't get in because of 2FA.

If they can simply claim 'lol i lost 2fa plz remove' they got access to your account.

Share this post


Link to post
Share on other sites
31 minutes ago, Storfan said:

If you can just "lose" your 2FA and then ask admins to remove it, doesnt that open up as a security concern? I could be wrong ofcourse.

 

20 minutes ago, smokeit said:

Exactly, you're completely right.

Maybe hackers already have my password but can't get in because of 2FA.

If they can simply claim 'lol i lost 2fa plz remove' they got access to your account.

Ah, did not understand what you meant. This is how it is. Noone will remove your 2FA. You as the user are responsible for your own account security. You should store the QR code safely somewhere, for example printed, or in a mailbox which itself is protected by 2FA.

Personally, I store my QR code in my Google Inbox where I also have 2FA. Google, however, has backup codes as a way of recovering your account if your authenticator is lost.

Share this post


Link to post
Share on other sites
5 hours ago, Storfan said:

Kind of defeats the entire purpose of 2FA doesnt it though. I'm not trying to be a dick, just stating facts.

Now, onto being a dick.

User: Pliz mr. admin-guy i lost my 2FA?! Please delete it so I can logon agin!

admin: Ok lol ¯\_(ツ)_/¯

Ye I completely agree. It does defeat the purpose, but I was hoping there was a way of proving its my account. 

As for trying to ask someone to disable it for me, that's why I'm here. Is there any other way of getting in touch with GMs as they haven't responded here or on discord? 

 

 

Share this post


Link to post
Share on other sites

Administration can help, cause on all project, who use this security-system, exist another way to aut.: link (send code via mail). (the same with blizzard or steam).
Lost QR != lost account. It's issue. Two factor != one and only one way to enter.
But no one want to help.
If they want - they can propose some donate for this issue (help with $ for project, and we deactivate u'r 2fa).
But they can help! Just ignored.
sorry for english.

Edited by manetheren

Share this post


Link to post
Share on other sites
15 hours ago, manetheren said:

Administration can help, cause on all project, who use this security-system, exist another way to aut.: link (send code via mail). (the same with blizzard or steam).
Lost QR != lost account. It's issue. Two factor != one and only one way to enter.
But no one want to help.
If they want - they can propose some donate for this issue (help with $ for project, and we deactivate u'r 2fa).
But they can help! Just ignored.
sorry for english.

If such an option is implemented, then yes, you can use it to get back into your account. Google for example has SMS verification (if you previously added your phone number) or backup codes. Unfortunately, currently we do not have any such option.

Share this post


Link to post
Share on other sites
3 hours ago, Ambervale said:

If such an option is implemented, then yes, you can use it to get back into your account. Google for example has SMS verification (if you previously added your phone number) or backup codes. Unfortunately, currently we do not have any such option.

But issue exist.
How can help people, who lost app with qr-code? Or people lost access for they account's pemanent?
I think - can help with disable 2FA for people with this issue, with e-mail confirm (maybe, with donate too).

Share this post


Link to post
Share on other sites
30 minutes ago, manetheren said:

But issue exist.
How can help people, who lost app with qr-code? Or people lost access for they account's pemanent?
I think - can help with disable 2FA for people with this issue, with e-mail confirm (maybe, with donate too).

So let's say that I hack your account, and find your password! But crap, you have 2FA so I still can't steal your stuff. But oh hey, perhaps you use the same password (or a very similar one) for your email! Just to use your so-called "e-mail confirm" and I can disable your 2FA.

There are reasons why administrators should NOT remove it without a pre-arranged method (like backup-codes that you need to download and store, or SMS to a phone where you have provided a safe phone number, etc).

Share this post


Link to post
Share on other sites
18 hours ago, manetheren said:

But issue exist.
How can help people, who lost app with qr-code? Or people lost access for they account's pemanent?
I think - can help with disable 2FA for people with this issue, with e-mail confirm (maybe, with donate too).

I repeat my previous fictional exchange:

Spoiler

 

User: Pliz mr. admin-guy i lost my 2FA?! Please delete it so I can logon agin!

admin: Ok lol ¯\_(ツ)_/¯

 

 

Share this post


Link to post
Share on other sites

Lets try to resolve this though through a possible means that is hopefully on his side...

 

Could you answer the following question for me @NoahUK

1. What email provider do you currently use?

Share this post


Link to post
Share on other sites

e-mail - it's more powerfull sign of my persone
if i lost e-mail  - i lost all 
2fa != only need qr

If i lost service for second (!) secure - i dont lost main auth. access = my e-mail.
one of them - it's a reason for sucessfull enter
cause its two factor auth. TWO )) not only-one , by qr-code (app -code)

Edited by manetheren

Share this post


Link to post
Share on other sites
12 hours ago, manetheren said:

e-mail - it's more powerfull sign of my persone
if i lost e-mail  - i lost all 
2fa != only need qr

If i lost service for second (!) secure - i dont lost main auth. access = my e-mail.
one of them - it's a reason for sucessfull enter
cause its two factor auth. TWO )) not only-one , by qr-code (app -code)

I'm having troubles understanding your English... :(

Share this post


Link to post
Share on other sites
12 hours ago, manetheren said:

e-mail - it's more powerfull sign of my persone
if i lost e-mail  - i lost all 
2fa != only need qr

If i lost service for second (!) secure - i dont lost main auth. access = my e-mail.
one of them - it's a reason for sucessfull enter
cause its two factor auth. TWO )) not only-one , by qr-code (app -code)

You = Making < ZERO (0) Sense.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×