Saturday 14 January 2012

Google 2-factor authentication and Android devices

A quick search showed that there are a lot of folks out there who have inadvertently blocked their android phones and been unable to log in with their Google credentials. This happened to me this morning and the advice generally seems to fall into two camps:
  • Exploiting a bug in the phone UI to allow access to menus during a phone call
  • Factory reset the device
There's another option which may help a growing number of users. If you have Google's 2-factor authentication switched on then username/password recovery of a locked device won't work. Switching off 2-step verification temporarily will allow you unlock you phone. Just don't forget to enable it again afterwards.

The real gripe in all of this is how poorly supported 2-step verification is particularly among third party software (and hardware) vendors. Plenty of things still break if you have 2-factor auth on and an application expects to log in with traditional credentials. Is this because it's too hard to integrate, adoption is still too low or some other reason?