Downsides of Google Authenticator
zdnet.com
Downsides of Google Authenticator
1–10 of 139 posts
Re: Downsides of Google Authenticator
#2Using a cloud-based password manager is a huge risk though. And if you've put both your passwords and your 2FA generators in the cloud, you now have single-factor authentication.
Re: Downsides of Google Authenticator
#3Being able to access my codes from any device with a web browser is very nice.
INB4:
"But this reduces your security."
* Yes, but I'm already using a password manager with 64 char generated passwords on every site.
* If you're able to compromise my Bitwarden password you likely have enough to remove the 2FA on all of my accounts anyway.
"Why even have 2FA at that point then?"
* Because some things in my life require it.
Re: Downsides of Google Authenticator
#4- Passcode or biometric locks on an app are a gimmick and offer negligible value.
- The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface.
- In particular, Authy, LastPass and 1password have a giant attack surface compared to a simple app like Google Authenticator. They also rely on centralized services and if you also keep your passwords in there, you eliminate the whole point of two factor authentication.
- One important risk with authentication apps is compromised updates, and Google Authenticator has a very low risk of this since it's backed by Google's strict security processes.
What you should actually do is to move to U2F/WebAuthn and pester any of your service providers that do not offer it. Yes, if you need to replace a token, you'll have to go through all accounts and change it. There's is absolutely no way to prevent this without compromising on security.
Re: Downsides of Google Authenticator
#5> Is it risky "centralizing" this data? Sure, but I don't see it any more risky as using a cloud-based password manager. Using a cloud-based password manager is a huge risk though. And if you've put both your passwords and your 2FA generators in the cloud, you now have single-factor authentication.
In many cases that factor is now Google's security vs. the same reused password that is your hobby + the year you graduated high school. It this is what makes it convenient enough to always use, it's probably still a step up. It's at least a better, slightly more distributed factor. And even then they're distinct systems, possibly not even within the same cloud.
Re: Downsides of Google Authenticator
#6Re: Downsides of Google Authenticator
#71. Backup old phone using Titanium Backup.
2. Get new Android phone.
3. Root it.
4. Copy TB backup files from old phone to new.
5. Restore apps and data on new phone using Titanium Backup.
Obviously it's not a procedure a normal user is expected to do...
Re: Downsides of Google Authenticator
#8Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
Re: Downsides of Google Authenticator
#9Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
Re: Downsides of Google Authenticator
#10Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
Here’s the thing. I consider myself fairly responsible but I’ll bet I’m far more likely to lose my phone than it is that my Authy and Dashlane credentials are both compromised, which are my pw manager and Authenticator app. You have to choose your risks and for a lot of people an authy like feature is much safer overall than GA.