Live data from Hacker News

Downsides of Google Authenticator

zdnet.com

11–20 of 139 posts

Re: Downsides of Google Authenticator

#11
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

I feel you're letting perfect be the enemy of the good. The baseline isn't centralized 2FA. The baseline is not using 2FA at all. While you may be willing to accept usability trade-offs associated with the lack of synchronization, a lot of people aren't. We shouldn't let better security be accessible only to tech-savvy people.

Re: Downsides of Google Authenticator

#12
post #3

Bitwarden is a pretty good solution for this! It's not the smoothest since the browser extensions don't know how to fill in your codes like they do your password but it's leaps and bounds above the UX for Google Authenticator. Being able to access my codes from any device with a web browser is very nice. INB4: "But this reduces your security." * Yes, but I'm already using a password manager with 64 char generated pas…

I just paid for my second year of Bitwarden. I love it.

Re: Downsides of Google Authenticator

#14
I stopped using Google Authenticator in 2013 when my tokens disappeared after a software update [1]. They were restored in the next update, but I didn't like not having access to the raw TOTP data.

I switched to Authy after the incident, and now use 1Password after I discovered their TOTP feature.

[1] https://news.ycombinator.com/item?id=6325760

Re: Downsides of Google Authenticator

#15
post #8

Earlier quoted context omitted.

Here’s the thing. I consider myself fairly responsible but I’ll bet I’m far more likely to lose my phone than it is that my Authy and Dashlane credentials are both compromised, which are my pw manager and Authenticator app. You have to choose your risks and for a lot of people an authy like feature is much safer overall than GA.

All my 2FA codes are backed up. On paper. I have a physically-secured cache of the QR codes which can be pretty quickly imported into a new app.

Do you trust the security of your printer when you print codes? They are historically one of the biggest attack surfaces.

Re: Downsides of Google Authenticator

#17
post #3

Bitwarden is a pretty good solution for this! It's not the smoothest since the browser extensions don't know how to fill in your codes like they do your password but it's leaps and bounds above the UX for Google Authenticator. Being able to access my codes from any device with a web browser is very nice. INB4: "But this reduces your security." * Yes, but I'm already using a password manager with 64 char generated pas…

Also if your local machine is compromised, which is much more common than people brute-forcing passwords, somebody can get your password and a 2FA code and access any account.

Re: Downsides of Google Authenticator

#18
post #15

Earlier quoted context omitted.

All my 2FA codes are backed up. On paper. I have a physically-secured cache of the QR codes which can be pretty quickly imported into a new app.

Do you trust the security of your printer when you print codes? They are historically one of the biggest attack surfaces.

Are you referring to network-enabled printers phoning home?

My 15 year old Brother doesn't have that capability... So on that front, a printout of QR codes is more likely to be compromised by the paper itself being left out somewhere.

Re: Downsides of Google Authenticator

#19
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

I agree with this comment completely. Adding a biometric lock would turn it into 3FA.

Not sure if HN allows to plug your own apps, so please forgive: I made an app a while ago that aims to replace Google Authenticator for some of the reasons mentioned: it allows to back-up and transfer tokens without creating a large attack factor. Not having sync is a feature in this case as well. In fact, the app does not even have the internet permission enabled, so it utterly unable to phone home. Transferring backups does require a biometric lock.

It is also entirely free, so I'm only posting this out of pride of my own work: https://play.google.com/store/apps/details?id=com.pixplicity...

Re: Downsides of Google Authenticator

#20
post #9
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

As long as you use encrypted backups with iPhone, your GA keys are backed up and you can restore a new phone with them also.

GA keys are not in icloud backups. You mean local “usb” backups?
Post reply on HN