PSA : Check Your Mobile Numbers Used For 2FA Are Current

I had some fun this afternoon after deleting Google Authenticator from my phone due to chronic Fat Finger Syndrome only to find the 2FA number for recovering access to the application was my old U.K. mobile number.

Luckily, I had saved an account recovery code and got back in sharpish.

I strongly suggest everyone check there 2FA details for important things and generate recovery codes for these applications/accounts if possible.

4 Likes

Ooops ! At first glance I thought your post was about Prostate Specific Antigen. :slight_smile:

2 Likes

I will use “Alert” in future to avoid causing unnecessary alarm.

On a similar note, where possible I’ve moved away from SMS-based 2FA to using so-called TOTP (aka Time-based One Time Password if you’re geeky, or RFC 6238 if you’re the sort of person who should spend more time outdoors). Instead of receiving a text message, I have an app that generates a new 6 digit code every 30 seconds per site I use.

Don’t be like me and forget to backup the config in case you lose access to your phone or, in my case, the app crashes continuously :sob:

1 Like

Google Authenticator works well for that purpose, though I’ve never got the Chrome plug-in to work on my PC.

2 Likes

Yeah, I saw they can sync it to your Google Drive which is a nice idea.

I’ve been caught out by Google killing stuff in the past so am currently using this open source equivalent…

2 Likes

I use Microsoft authenticator. It’s robust and works well.

1 Like