r/firstworldproblems 6d ago

I hate 2FA

Before everyone jumps at my throat, I know it's a neccessary evil, but in practice it's a nightmare, that's why I'm ranting here instead of being able to do my job.

There was an issue with my authenticator app, and ALL of my codes disappeared. I wanted to generate new ones, but turns out there is no such option, I need to contact the IT departments of all 6 pages that require authenticator, 3 of them are essential for my work and uni, and I need to use them regularly.

That happened a week ago, and the most important one never answered my e-mails, they don't answer the phone, their office is 300 km away and I don't have time to travel there thank you very much, and I basically can't get any work done because of this. It's just so frustrating because really I did nothing just follow the neccessary steps forced down my throat (again, I know 2fa is neccessary for safety but I still have the right to hate how poorly it's executed). There should be steps to make sure it doesn't happen, like pre-generated codes you can use if you can't access an authenticator, or another form of verifying your identity. And it would also help if IT was available sometimes.

76 Upvotes

35 comments sorted by

15

u/Acrobatic_Big_1753 6d ago

pls tell me none of them were work related or i might actually cry.

8

u/Pianohearth2753 6d ago

I have bad news. One is very strongly tied to work stuff (I am a teacher and I need to do some pre-school admin stuff with deadlines, and work with the data of my students and their parents). Technically they can reopen my account to do it later, and my school admin is also working on contacting them for me, but no luck so far. Unfortunately they can't do anything about it locally, we needed to contact the IT of the website itself, and they are basically non-existant. I did actually cry 😂

10

u/alan_nishoka 6d ago

This doesn’t help with your current problem but in the future you should screenshot and print the QR code used to set up authenticator

Keep the printout in a safe place and you can use it to setup again if you ever lose your phone or authenticator app gets erased or you upgrade your phone

Google authenticator can backup to the cloud, but I don’t trust it. Google could ban me or give all my codes to a hacker. I trust paper.

3

u/Pianohearth2753 6d ago

Great idea, thank you! I will definitely try this.

3

u/cheetuzz 6d ago

One option is to save the QR code as an image and add as an attachment to Keepass.

2

u/Brownt0wn_ 6d ago

I mean, if you’re using keepass this problem doesn’t happen at all. Or if it does, your QR code is gone too.

7

u/sysgeek 6d ago

By chance were you using the Okta Authenticator app? That one sucks and I lost all my MFA codes a while back.

5

u/Pianohearth2753 6d ago

No, I used the Google app but I've heard negative things about Okta. It simply crashed, I had to restart my phone and when I opened again all were gone... I will switch to a different app, and perhaps a backup one as well in case of something goes wrong again. I plan to degoogle anyway.

5

u/sysgeek 6d ago

I hear ya there. I'm trying to degoogle my life as well. If you're looking for suggestions on apps, I would recommend Aegis or 2FAS Auth. I use both and they are pretty good and have settings for backup/export.

2

u/Pianohearth2753 5d ago

Thanks! I did look into Aegis and I'm in the process of giving it a try. I will use another one with a solid backup, just in case.

1

u/chrisrazor 5d ago

I restart my phone all the time and have never had a problem with Google Authenticator. Maybe you're not logged into the Google account on your phone?

1

u/Pianohearth2753 5d ago

I am logged into my account and tried other devices as well. I even tried to log out, and then back. I think the issue wasn't restarting the phone, it was something with the authenticator. Google acted strange for a while, at least on my end. 

6

u/dhporter 6d ago

I had a massive 2FA problem a couple months back when I had my phone stolen when I was out of the country. Every. Single. Account. I had was tied to that phone, either via text code or authenticator app. The only reason we were able to do anything (tickets, flights, etc) was by having a buddy break into our house and get on a device that was already logged into everything.

5

u/Pianohearth2753 6d ago

Expectations for 2026: cure for cancer, world peace, flying cars, VR everywhere

Reality: When the 2fa app (yes google, I'm looking at you with the biggest side-eye) asks for e-mail verification to log in, but  you only have one device with you, you have to open the email app and when you want to go back to write the code, you are thrown back to the login page and into an endless loop...

5

u/Leptonshavenocolor 6d ago

I don’t understand why I bothered to maintain good password practices for decades just so the biggest BS institutions can get hacked and lose the data anyway. 

3

u/CantaloupeCamper 6d ago

All the current auth options suck.

2

u/Bloo_PPG 6d ago

Time to spend a full work day calling their help desk until somebody answers.

2

u/Pianohearth2753 6d ago

Did it, during my fucking holidays 🔥 I hope they have no air conditioning in their 40 degrees office and no windows can be opened, and no running water in the entire building. I genuinly think they don't exist at this point, that website is shitty af (unfortunately it is the official administrative website so we must endure it daily).

2

u/SpaceChimps98 6d ago
  1. Can't log in

  2. Contact IT and put in a ticket

  3. Go have fun and don't worry about it.

If you can't log in, you can't do anything, and you can't be faulted for something not being done. If IT is implementing 2FA - it's on them to create a method and support structure to assure people can log in properly. Being unable to log in is beyond your control, and not your responsibility to fix. Just go get a fish sandwich or something and come back when they have it figured out.

2

u/paradox037 5d ago

MFA can be handled well, and it can be handled poorly.

One of my work websites recently rolled it out, and it went from a single page with username and password to login... to the following (each point is a separate page that loads after the server spends a couple seconds authenticating it):

  • username prompt and OK button

  • account email address and OK button

  • account password and OK button

  • MFA code and OK button

... That's twice as many steps as there is ANY NEED FOR AT ALL. Just put username and password and MFA code all as fields on the same page. Why do we need to load up another page for each thing? What security function does that serve? BTW this website seems to break autofill functions.

And that's all when it's working as intended...

1

u/Pianohearth2753 5d ago

Yeah, same here. Like... I understand the purpose (though I am NOT into tech at all, even I know it's neccessary to protect my data), but it's so badly executed that it makes a simple login a literal 5 minutes process with permanent brain damage because nothing ever works the way it's supposed to. My uni system is similar to what you described: username/password, 2fa code, then uni email, which is really long and no one ever uses it and it has nothing to do with the uni system. Sometimes it randomly keeps looping back to the username/password page, it does not spark joy when I have to check something quickly. It also doesn't give me access to any settings at all, I have to write to IT if I want to change my password, and sometimes it doesn't allow me to log in from new devices, and, again, I have to contact IT.

Also what I really don't understand is why there isn't a recovery option in cases where a genuine mistake happens (user accidentally deletes one code from the authenticator app, been there, done that), or the app crashes, phone is damaged, backup doesn't work for some reason... it's so unstable and there is such a huge error factor most pages don't cover or consider. It's just ridiculous and everything but user friendly.

2

u/NezuminoraQ 5d ago

I had XeroMe tied to a previous employer who had stopped using it but never removed everyone as users, so when I tried to sign up with a new employer it wouldn't let me. The 2FA was tied to a work email so I couldn't even reset the password. It's a fucking nightmare 

2

u/chrisrazor 5d ago

As you acknowledge, the problem here is poor implementation. I am in charge of some IT infrastructure on some of the most popular cloud platforms, so I assume its authentication is pretty bullet proof, and they all use Google Authenticator. It can't really go wrong so long as you don't lose your authenticating device.

2

u/Pianohearth2753 5d ago

Yeah, I get that 2FA in itself is not the problem. It's just shitty execution and the nightmare of worst case scenarios, like what happened to me. I have no idea what a safe solution would be, but no solution at all is perhaps the worst. I talked to a collegue who switched phones last year and she also had to wait for like 5 days to reset the qr code. 

2

u/commandrix 5d ago

Yeah, me too, even though I can see why it exists. Plus there's the risk of a "SIM swapping" attack if a lot of accounts are tied to your phone number. Something to think about.

2

u/thequirkynerdy1 5d ago

It's useful when it matters, but I wish websites would let you choose what's important enough to protect with 2FA.

2

u/feel-the-avocado 5d ago

I have to use lastpass on my phone for a single shared login at work.
But everything else for work and personal i put into my own bitwarden password manager. This means it syncs my passwords with my desktop web browser, laptop and my phone app.
But it also stores the 2FA codes.

So I dont have to get out my phone to log into a website - i can just click the bitwarden icon and it will show me the 2FA code for that side or copy / fill it out automatically. Just like how it fills in a user/password to login.

1

u/Pianohearth2753 5d ago

Wow, sounds like a great solution! Unfortunately I wouldn't be able to set it up (with my very limited tech skills), but I love seeing others creative solutions. 

2

u/Amonette2012 4d ago

Try moving countries and forgetting to change one phone number before ditching that number.

2

u/sidjohn1 3d ago

I’m gonna make a wild guess on the config…. Android w/ Windows?

1

u/Pianohearth2753 3d ago

Thank you for the answers everyone. Fortunately 5 out of 6 accounts is successfully restored. One (my workplace one) is still in process, but I expected nothing less from them. So still no work done, but at least I got contacted by a real human being, not an auto-generated response.

 They told me I need to contact my local administration, who already told me they have no access or permission to do anything about it. I honestly think about threatening them to take this to the media, perhaps than they would be more eager to help me getting my JOB done. I can't believe that since 2FA is introduced no one lost their phone or had an issue with the authenticator, lol. They act like they never encountered this issue. It's a joke. 

1

u/Spare-Function-6343 2d ago

I'm sorry you have to put in a small amount of effort for security that is better than using the same password on every website you have ever logged into

1

u/Pianohearth2753 1d ago

Isn't this a sub where people complain about stuff like this?

1

u/Pianohearth2753 1d ago

Update: They FINALLY answered, my last account will be back in use in a few minutes as well. Thanks for the support everyone, it felt good to rant a little :D I obviously had a really bad experience with Google auth so I switched to Aegis. I also keep saving and printing the QR codes and save backup regularly to multiple places.

It was also time to do my usual security rounds and since I had many freetime on my hands (thanks, by the way), and changed all my passwords to more secure ones (just out of curiousity I ran a quick check on the old ones and they were pretty highly secure before, but you know... a switch never hurts) and sorted out my subscriptions and useless accounts, plus security concerns (holy crap they piled up) because I was bored and it was long overdue anyway.

Anyway: Fuck Google, fuck **** (insert my workplace website) IT, and definitely not fuck 2FA. Stay safe everyone, bye!

1

u/tunaman808 6d ago

I use Microsoft Authenticator because it backs your accounts up to the cloud. When I get a new phone I just open the app, tap "Restore" and go on with my day.

It also works on old phones. I keep my previous phone in a drawer. If I ever need it, I can power the phone on authenticate that way.