rightsblog.blogg.se

Vip access not working on new phone
Vip access not working on new phone










Symantec doesn't support any way to backup its secret - their documented work-around for a lost, broken, or replaced smartphone is to contact technical support at for each system with which I've registered my "credential ID". It is worth noting sites can optionally integrate push based notification (where the app asks Symantec to ask your phone to generate a token for it) or QR based authentication (where a QR code is presented which your phone uses when generating the token). I doubt Symantec would allow the same code to be used twice (the system requires the service to send the code to Symantec for validation) - but a malicious service could easy enough not validate you with Symantec themselves. 2FA does not necessarily fully negate the risks of password reuse. If I use Symantec VIP Access for both SiteA and SiteB, doesn't this effectively give SiteA TOTP tokens that it can use to impersonate me on SiteB?

vip access not working on new phone

Is this analysis of Symantec VIP Access correct? If so, do I have any better alternatives than (futilely) asking administrators of systems that use Symantec VIP Access to switch to something that doesn't suck? I'm not sure how the crypto works, but if I use Symantec VIP Access for both SiteA and SiteB, doesn't this effectively give SiteA TOTP tokens that it can use to impersonate me on SiteB? Also, Symantec doesn't support any way to backup its secret - their documented work-around for a lost, broken, or replaced smartphone is to contact technical support at for each system with which I've registered my "credential ID".

vip access not working on new phone

Vip access not working on new phone software#

This software seems to generate a single secret, then I register the "credential ID" with other systems to allow them to recognize my TOTP stream.

vip access not working on new phone

However, I've encountered a few systems that support only Symantec's "VIP Access" program. This system allows me to have separate TOTP streams for each site and allows me to backup my seeds (by printing the QR codes used to set them up). I'm most accustomed to using Google Authenticator / FreeOTP for my 2FA needs.










Vip access not working on new phone