Esta página ainda não está no seu idioma. Está a ler o texto em inglês.
Blog
Two-factor codes next to the profile: what that changes
A equipa ARMANOS8 min
Why your assistant waits every time
A platform asks for six digits at a login from an unfamiliar device, and an ad account often asks at every login at all. The digits live thirty seconds and appear wherever the app holding the key is installed, which is in your pocket.
The hands are your assistant's, and the permission to work comes from you, by hand. On three accounts that is nothing, on thirty it is your whole working day.
- 1
The password went through
The platform asks for the second step and waits for six digits.
- 2
The digits live half a minute
The window is short, and they have to go across at once.
- 3
The app sits with you
The key is on your phone, and your assistant does the work.
A key and a code differ
A code is six digits for thirty seconds. A key is the short string you took off a QR picture once, back when you turned the protection on at the platform.
A code comes out of the key and the current time, and there is no road back: a dozen codes read over your shoulder will not give up the key. So a code you hand over costs you a minute, and a key you hand over costs the account until you bind the second step again.
The app on your phone does exactly the same: it holds the key and shows digits by the clock. The only difference is where the key sits and whose hand reaches it.
| What you hand over | What it costs |
|---|---|
| One code | One minute of work and one message |
| The whole key | Entry to the account until the second step is bound again |
| Password and key together | An account that works without you |
Three ways and the price of each
There are three ways in all, and you have probably walked two of them already. Forward every code by hand, give your assistant the key itself in a chat, or put the key where the profile opens.
The first runs into your time, the second into a chat you cannot recall. The third leaves the key on a machine rather than in somebody else's chat, and that alone is what separates it from the second.
| The way | What you pay with |
|---|---|
| Forward every code | Your attention across the whole working day |
| Give the key in a chat | A copy of the key nobody can recall |
| Put the key by the profile | Access for whoever opens that profile |
What changes with the key there
The key already sits next to the account anyway: in a spreadsheet, in a note, in a shared password vault. Next to the profile it moves one step closer to the window where that account is actually used.
Then the digits appear in that same window, and the phone drops out of the work entirely. The app produces the code on this computer, and nothing goes out to the network for it.
The window does not show the key back: the One-time code window in the profile menu shows the digits, the seconds left and the account name, and the card carries only a 2FA mark. You paste it once, and after that you work with digits alone.
- 1
No second device
The digits appear in the same window the profile lives in.
- 2
Nothing to look up
The key belongs to the profile, so there is nothing to match by name.
- 3
Nothing to retype
You copy the code with a button, and a flow types it into the form.
- 4
Nothing goes outward
The key and the clock are on this computer, and a code needs no network.
Who you open the account to
A key by the profile means exactly one thing: whoever opens that profile gets into the account without you. That is the price, and it is worth saying out loud before you hand over the first profile.
On macOS and Linux only the owner of the computer account can read your keys in that file, and on Windows only the user folder closes them off. Against someone sharing the machine and against another program those are different barriers, and the second one is weaker.
A key cannot be revoked the way a password can: a password you change in a minute, while the second step has to be bound at the platform again. So handing the key over is a decision for the whole time you work with that person.
What never leaves your machine
The key does not travel to the server: there is no such field there at all. Sign in on another machine and you will see the profile, but no key beside it, and a sync back does not wipe it either.
Cookies and a profile login are not accepted either: a body carrying such a field is refused whole. ARMANOS keeps the key, the cookies and the profile login on the machine where you put them, and sends them nowhere by itself. A shared folder for sessions is something you point at yourself, and then cookies and logins travel into it.
- 1
A server without that field
The key is not there, and there is nowhere to take it from.
- 2
A login on a second machine
The profile arrives, and the key stays on the first one.
- 3
A transfer under a password
Only a profile archive carries the key, and your password opens it.
How the key reaches your assistant
Shared access to a profile does not bring the key along: your assistant opens the profile from their own machine and finds no digits there. The key travels by two roads: a profile transfer with its session, whose file opens with a password you set, and a profile export with the Export button if you pressed «Include secrets» yourself. That second file has no password.
A copy of a profile does not take the key either: a copy is a new account, and somebody else's second step is no use to it. Another person's password does not open a transfer file at all, and an honest refusal comes back instead of the contents.
The session travels into the archive along with the profile: cookies, logins and the state of the sites. Your assistant sits down in a warmed profile instead of signing into thirty accounts again from scratch.
Why a right key gives wrong codes
Most of the time the trouble is not the key but its settings. A bare key carries only the secret itself, while a whole otpauth:// string also carries the number of digits, the step and the algorithm, and an unusual platform sets those its own way.
The same key with eight digits, a sixty second step and SHA256 gives one code with those settings and a different one without them. An account looks lost after that, although what got lost was three fields.
The app turns down a string that counts logins rather than seconds the moment you paste it: time based digits will never come out of it. Spaces, dashes, lower case and equals signs in a key are no obstacle at all.
| What you pasted | What you get |
|---|---|
| A whole otpauth:// string | The digits, step and algorithm of the platform that issued it |
| A bare key | Six digits, a thirty second step, SHA1 |
| A string that counts logins | The key does not land, so no wrong digits |
| A string with a typo | A refusal on saving, and nothing written to disk |
Will the digits match another app
Your assistant types the digits into the same platform that expects them from a phone, and a disagreement has nowhere to come from: the step and the method are set by RFC 6238, one for everybody. Six reference samples of that standard, the farthest of them at a time of 20000000000 seconds, give exactly what the app on your phone gives.
The clock is a separate trouble: the digits follow this computer's clock, and a clock that has drifted gives what the platform does not expect. A few wrong tries in a row read as guessing, and the platform closes the entry itself after that.
You can leave the app on your phone switched on: two places holding one key do not get in each other's way and give the same digits. That is also how you check yourself on the first day.
Your own login is another door
The second step on a platform account and the second step on your own account are two different doors. The first you hand to your assistant along with the profile, the second you hand to nobody.
On your own login the same number does not work twice, ten misses shut the door for a while, and turning it on gives you ten recovery codes, each good once. Lose the phone and a recovery code lets you in, while your assistant gets in with neither.
Which order to choose for yourself
With one assistant and three accounts, leaving it as it is comes out cheaper: your time on ten codes a day costs less than untangling things when you part. With thirty accounts, forwarding codes is the very work you hired a person for.
If you hand the account over for good, the key travels with the profile, and after you part the second step has to be bound again. If the account stays yours, hand over access to the profile and not the key.
There is a middle arrangement too: you hand over access to the profile and keep the key. Your assistant works in the profile, still writes to you at the second step, and every login stays your decision.
| Your case | What to do |
|---|---|
| Three accounts and one assistant | Keep the codes yourself and forward them |
| Thirty accounts and shifts | Put the key by the profile on your assistant's machine |
| Handing the account over for good | Transfer the profile under a password and change the account password |
| The account stays yours | Give profile access without the key and keep the digits |
What this does not claim
- It does not claim that a key by the profile is safer than a phone. It is more convenient, and access to the account goes to everyone who opens that profile.
- On disk the key is not encrypted. On macOS and Linux the file permissions close it off, on Windows only the user folder does, and there is nothing more to promise there.
- A lost key is lost. It never goes to the server, and it cannot be put back together out of the digits it produced, so keep the platform's own backup codes away from the profile.
- The app does not read a QR picture. You paste the text of the key or an otpauth:// string, and a screenshot of a phone is not something it will take apart.
- This is not about the login to your own account. That second step lives on the server, with recovery codes, and no arrangement hands it to an assistant.
Where you can see this yourself
Every number above comes out of code you can open and run.
- The codes match all six reference vectors of the standard, the farthest one included
- apps/desktop/src/lib/totp.js · apps/desktop/test/totp.js
- A string that counts logins instead of seconds is not taken for a time based one
- apps/desktop/test/totp.js
- The number of digits, the step and the algorithm survive a profile restore
- apps/desktop/src/main/main.js · apps/desktop/test/config-import-2fa.js
- The file holding the keys is written owner only
- apps/desktop/src/lib/secureFile.js · apps/desktop/test/secrets-on-disk.js
- The key survives a login on another machine and a sync does not wipe it
- apps/desktop/test/sync-preserves-local.js
- A copy of a profile takes neither the key nor the login pair
- apps/desktop/src/lib/перенос-профиля.js · apps/desktop/test/profile-clone.js
- A profile archive carries the key, and another password does not open it
- apps/desktop/src/lib/bundle.js · apps/desktop/test/profile-bundle.js
- The code route answers only with the token and never a web page
- apps/desktop/src/lib/local-api.js · apps/desktop/test/local-api-gate.js
- Cookies and a profile login are refused by the server whole
- apps/server/test/куки-и-входы-сервер-не-примет.js
- On your own login a number never works twice and a recovery code works once
- apps/server/test/two-factor.js
Questions
- Will my assistant see the key or only the digits?
- The One-time code window gives back the digits, the seconds left and the account name, and it does not show the key again. But the machine holding the profile holds the key too, so count it as handed over together with the machine.
- I shared the profile through the team. Did the key travel?
- No. There is no such field on the server, and a shared profile does not carry the key: from their own machine your assistant sees the profile and no digits.
- How do I take the access back?
- Changing the password is not enough: the key keeps working afterwards. Take back access to the profile and bind the second step at the platform again, and the old key stops giving right digits.
- What if the account uses eight digits or a one minute step?
- Paste the whole otpauth:// string: it carries those settings itself. A bare key does not carry them, so the app falls back to six digits, thirty seconds and SHA1.
- Can a page from the web pull out my code?
- No. A call that looks like it came from a page is turned down whatever token it carries, and the digits never reach the page.
- Do I paste fifty keys one at a time?
- The key arrives as a spreadsheet column together with the profiles, and the column heading needs no adjusting. A key that cannot work simply does not land in the profile: there will be no wrong digits, but the window shows no separate line with the reason, and the profile arrives without a key.
Next to this
One time codes in a profile
Where the key goes and what shows on the card afterwards.
Two-factor authentication
What that second step is and which kinds exist.
Profile transfer
What travels with a profile and under which password.
Free fingerprint check
12 values read in your browser, with nothing sent anywhere.
See what your own browser answers
The check reads 12 values and sends nothing anywhere.