Post
Topic
Board Securities
Re: Never trust BTCT.CO 's FAQ about GAuth!
by
Deprived
on 19/09/2013, 03:02:11 UTC
I followed btct.co's faq about gauth just now:


Quote
Codes from Google Authenticator not working after phone reset

If you recently reset or wiped your phone, the Google Authenticator app might not be able to generate valid codes. To get your Google Authenticator app working again, you will need to delete your account from the app, turn off 2-step verification, turn it back on, and add your account to the app again.

Open the Google Authenticator app on your phone.
Delete your account from the app.
Press and hold the account you want to delete, then tap Delete on the dialog box that pops up.
Go to your 2-step verification settings page and rescan your QR Code.


Yes I silly believed the offical FAQ should work ,and I deleted my btct.co account from google authenticator!
and ,where can I 'Go to your 2-step verification settings page and rescan your QR code?'

the 'change gauth settings' button in 'Account -> Google authenticator' menu seems broken, it just jump back to account homepage.

Now I cannot do any transactions in BTCT!
If I choose to reset my Gauth in btct, I'll be locked for 30 days!!!

Totally FAIL!






If your GA was working fine why would you conceivably believe deleting the code from GA before disabling authentication on the server was sensible?

I mean if you wanted to change your password on a site and the FAQ said "repeatedly hitting yourself in the head with a brick can help you forget the old password" I'd still have some doubts over whether forgetting the old password was actually a useful objective to aim for and would, at a minimum, ensure I changed the password to a new one (that I could remember) before smacking myself in the head with a lump of masonry.

Similarly, if a site told me how to delete my GA details I'd disable the need for those details before actually making any effort to delete them.