Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

People need to stop calling this "google authenticator".

It's called TOTP:

https://en.m.wikipedia.org/wiki/Time-based_One-time_Password...

It's an open standard, RFC 6238:

  https://tools.ietf.org/html/rfc6238
Calling it "google authenticator" is like saying "I'm going to GMail that document to you".


TOTP being an open standard doesn't really help, though, if the only place you have the key for a given site is Google's authenticator.

You need to actively take advantage of it being an open standard.

There are a few ways you can do this.

1. When you set up TOTP for a site, scan that QR code or enter the text version of the code in two different TOTP authenticator apps.

You might even consider scanning the code on different devices, too.

2. You can save the QR code or text version of the code, so that you can set up another authenticator app later if you lose access to the one(s) you scanned the code in originally.

Only consider this approach if you are confident you can protect the saves code, such as with strong encryption.

3. Many sites will give you one or more one-time codes that can be used to bypass TOTP. These are meant to allow you to get in so you can set up a new TOTP authenticator if you lose access to your current authenticator.

As with #2, you need to be confident that you can securely store these codes if you want to safely use this approach.

For #2, I recommend both saving both the QR code and the text version of the code. You can get command line tools that do TOTP, such as oathtool [1]. Having the text version of the code will make it easier to use such tools, which might come in handy if your phone gets lost or destroyed and you need to generate TOTP codes before you can get a new phone.

[1] https://www.nongnu.org/oath-toolkit/


Sorry, I can't hear you over the noise of my Dyson hoover.


well, duh, we're in a thread about dependency to google services, no need to be pedantic, the message is abundantly clear.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: