Post
Topic
Board Beginners & Help
Re: Authentication: Types, Risks/ Attacks, Advice
by
Charles-Tim
on 27/06/2020, 13:06:28 UTC
It is true. I never ever use qr code when storing 2FA secret codes. I'd rather use the code itself and write on a paper for example or store it on a flash drives then you can keep it safe from leaking. It seems you are using google authenticator. Is it because where you can sync your account from the current device to other device which in my opinion is good but it also have disadvantage where the company that create that platform may have access to your credentials which is bad. I have been using google auth and Authy for 2 years.
You still do not give valid reason why QR code is not good for 2FA backup.

or store it on a flash drives then you can keep it safe from leaking
This method is not good enough, you can  write it down on a papar like you have ones said, you can laminate it for more safety.

When the map is broken, you have nothing to recover your 2FA but with secret key, if one of characters is blurred or broken, you still can guess it from the leftover of broken character.
When backing up QR code, the secret key is included.