Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
Downsides of Google Authenticator
11–20 of 139 posts
Re: Downsides of Google Authenticator
#12Bitwarden is a pretty good solution for this! It's not the smoothest since the browser extensions don't know how to fill in your codes like they do your password but it's leaps and bounds above the UX for Google Authenticator. Being able to access my codes from any device with a web browser is very nice. INB4: "But this reduces your security." * Yes, but I'm already using a password manager with 64 char generated pas…
Re: Downsides of Google Authenticator
#13https://docs.microsoft.com/el-gr/azure/active-directory/user...
Re: Downsides of Google Authenticator
#14I switched to Authy after the incident, and now use 1Password after I discovered their TOTP feature.
Re: Downsides of Google Authenticator
#15Earlier quoted context omitted.
Here’s the thing. I consider myself fairly responsible but I’ll bet I’m far more likely to lose my phone than it is that my Authy and Dashlane credentials are both compromised, which are my pw manager and Authenticator app. You have to choose your risks and for a lot of people an authy like feature is much safer overall than GA.
All my 2FA codes are backed up. On paper. I have a physically-secured cache of the QR codes which can be pretty quickly imported into a new app.
Re: Downsides of Google Authenticator
#16Re: Downsides of Google Authenticator
#17Bitwarden is a pretty good solution for this! It's not the smoothest since the browser extensions don't know how to fill in your codes like they do your password but it's leaps and bounds above the UX for Google Authenticator. Being able to access my codes from any device with a web browser is very nice. INB4: "But this reduces your security." * Yes, but I'm already using a password manager with 64 char generated pas…
Re: Downsides of Google Authenticator
#18Earlier quoted context omitted.
All my 2FA codes are backed up. On paper. I have a physically-secured cache of the QR codes which can be pretty quickly imported into a new app.
Do you trust the security of your printer when you print codes? They are historically one of the biggest attack surfaces.
My 15 year old Brother doesn't have that capability... So on that front, a printout of QR codes is more likely to be compromised by the paper itself being left out somewhere.
Re: Downsides of Google Authenticator
#19Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
Not sure if HN allows to plug your own apps, so please forgive: I made an app a while ago that aims to replace Google Authenticator for some of the reasons mentioned: it allows to back-up and transfer tokens without creating a large attack factor. Not having sync is a feature in this case as well. In fact, the app does not even have the internet permission enabled, so it utterly unable to phone home. Transferring backups does require a biometric lock.
It is also entirely free, so I'm only posting this out of pride of my own work: https://play.google.com/store/apps/details?id=com.pixplicity...
Re: Downsides of Google Authenticator
#20Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
As long as you use encrypted backups with iPhone, your GA keys are backed up and you can restore a new phone with them also.