Live data from Hacker News

Authy is joining Twilio

authy.com

71–73 of 73 posts

Re: Authy is joining Twilio

#71

Earlier quoted context omitted.

Why do you refuse to delete accounts? It is my data and I want it to be removed. How can I feel safe about my data if I cannot remove it if I choose not to continue using your service.

I would also really like to hear an answer to this question.

Sounds like it’s more like "Happy to answer _some_ questions”...

Re: Authy is joining Twilio

#72
post #37

Earlier quoted context omitted.

Ok, serious question: how do you manage your tokens? What happens if your device flies out of the window? A couple of months ago I managed to break the screen of my tablet with 20-30 services I use 2FA (Google Authenticator). I had to spend about 50 bucks just to get a new screen and repair it. For some of these services I had the token saved on my keepass, but I always felt a little dirty doing that. If there was a…

You print off a list of backup codes and stick them in a safe. Then log in with the backup code, and set up a new Authenticator token. You could also add a U2F token and store that away.

Not all of the services that implement Google's 2FA provide backup codes. Plus, the idea is that 2FA should be used anywhere, even for lesser-values web sites, so the idea of printing everything seems to be archaic.

Re: Authy is joining Twilio

#73
post #6

Founder of @Authy here. Happy to answer any questions.

Why does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. This is not in the spirit of 2FA.

An in my opinion crucial information is missing in the discussion that unfolded here 4 years ago; still this discussions comes up as a top result when searching for "authy telephone number required" and that is why I want to add something for current and future references: The phone number is only needed to recover access to your encrypted data that is stored on authys servers.

If you're questioning yourself whether authy is trustworthy because they require you to provide a phone number for a 2FA-TOTP-Method that does technically not require it at all(!) and thus could pose a potential security degredation, check the FAQ about account recovery/passwords here: https://support.authy.com/hc/en-us/articles/115001950787-Bac...

Quote: * The Backups password is never sent nor stored in our servers for your security * Like the Backups password, the App Protection PIN (and optional biometric data) is never stored in our servers * Like the Backups password and App Protection PIN, the Master Password is never stored in our servers

the question still is if you trust those promises - but as authy is backed by twilio (thus lots of 2FA-SMS are already processed by them) the chances are good those guys know what they do and do it responsibly

Post reply on HN