Suggestions

2FA Recovery Code/Phrase

Submitted by MarcFrid, , Thread ID: 52040

Thread Closed
19-10-2017, 09:34 PM
#1
[Image: LwqjyWu.gif]

Recently I have came across issue. I bricked my phone and lost access to it. Means all my 2FA aswell. Luckily I upgraded my account and I was able to prove my ownership of the account, but what if you are not upgraded? And have no proof. That is issue because who is going to beleive you that you are true account holder. The internet is vulnerable these days so email verification is not going to be enough.

How is it going to work?

Quite simple. On enabling 2FA you will receive a recovery code/phrase that you will write down. It will be most important in 2FA if you loose access and have no recovery code then you are not going to get your account back unless you got some REAL PROOF, but I would not count on it.

Code?

Code, for example a 1234567890 (but randomized) and unique for each user. Codes can be easily written down.

Phrases?

Phrases, are little bit more harder to remember or write down but are alot more secure this is example how a phrase recovery would look like:
Code:
tawny purged fabrics stellar auburn safety hull ajar noodles island jobs opened ajar
Basically 14 random words used as your recovery.






Conclusion: Alot of services use recovery codes and Nulled should too. Its a really bad situation to get in this problem, I experienced it. However I was just lucky. Even through my phone is not working anymore I still was able to recover most of my accounts (that I had 2FA on) through these recovery codes. Nulled was a little bit tricky but thanks to Aoki I got my 2FA removed.

Please vote on poll if you agree with this
(I made LL in the link big because there is site with big i that is scary face so to prove that I am not a fucking jerk....)

RE: 2FA Recovery Code/Phrase

#2
In reality who really needs this? If you have the email to your account, you're safe to assume, it's your account.

Nulled is pretty good at sorting issues out, so I don't see this necessary.
[Image: xvv2qQA.png]

RE: 2FA Recovery Code/Phrase

OP
#3
19-10-2017, 09:36 PM
Widget Wrote:
In reality who really needs this? If you have the email to your account, you're safe to assume, it's your account.

Nulled is pretty good at sorting issues out, so I don't see this necessary.

When I was talking about Kekko before my account was unblocked shesaid:
[Image: lfxZUD2xR7mTgI5BK3Vx0w.png]

I mean I made it more advanced that it should be but they still say:
[Image: 04Si4XXuRtGe1iJXN5bGYg.png]

Luckily enough this did not apply for me. You sure have more experience than me on Nulled.

RE: 2FA Recovery Code/Phrase

#4
19-10-2017, 09:43 PM
Gr00vy Wrote:
When I was talking about Kekko before my account was unblocked shesaid:
[Image: lfxZUD2xR7mTgI5BK3Vx0w.png]

I mean I made it more advanced that it should be but they still say:
[Image: 04Si4XXuRtGe1iJXN5bGYg.png]

Luckily enough this did not apply for me. You sure have more experience than me on Nulled.

Well, here's the solution- Allow 2FA on your email (Since they're pretty lenient on disabling it, if you haven't got access to it) and disable it on Nulled. Problem solved.

Hackzors can't get your email, and you need not worry about 2FA.
[Image: xvv2qQA.png]

RE: 2FA Recovery Code/Phrase

#5
and that would defeat the purpose of 2FA. Why not just have your password then?
[Image: InZ3hGx.png]

RE: 2FA Recovery Code/Phrase

#6
19-10-2017, 09:34 PM
Gr00vy Wrote:
Phrases?

Phrases, are little bit more harder to remember or write down but are alot more secure this is example how a phrase recovery would look like:
Code:
tawny purged fabrics stellar auburn safety hull ajar noodles island jobs opened ajar
Basically 14 random words used as your recovery.
Too compicated

19-10-2017, 09:34 PM
Gr00vy Wrote:
Code?

Code, for example a 1234567890 (but randomized) and unique for each user. Codes can be easily written down.
Well, I planned something. If you are using the steam authenticator you'll probably know how they did it.
Once you initialize your 2FA you'll get a so called "Recovery Code" which can be used to deactivate your 2FA, if you've lost or deleted the authenticator. I plan the exact same system.

Right now we're handling it like Steam Support. If you've lost access to it, you'll have to contact them using your steam E-Mail.
Aisaka Squad
Clxud | @231 | Kyoko |@1126 |@1256 | @5056 | @25108| @3747

[Image: yrNnxfb.gif]

RE: 2FA Recovery Code/Phrase

#7
The security of 2FA through SMS is inherently flawed, I would advise HIGHLY AGAINST using anything remotely like that.

RE: 2FA Recovery Code/Phrase

#8
It is like a password? I often see that on nulled but I have no clue for why that thing

RE: 2FA Recovery Code/Phrase

#9
03-12-2017, 02:28 AM
JarJarKay Wrote:
The security of 2FA through SMS is inherently flawed, I would advise HIGHLY AGAINST using anything remotely like that.

It's not SMS based and how is it flawed anyway?
[Image: InZ3hGx.png]
1

RE: 2FA Recovery Code/Phrase

#10
03-12-2017, 02:46 AM
Engineer Wrote:
It is like a password? I often see that on nulled but I have no clue for why that thing

https://en.wikipedia.org/wiki/Google_Authenticator

I mean you could have just Googled.
[Image: InZ3hGx.png]
1

Users browsing this thread: 2 Guest(s)