Live data from Hacker News

Downsides of Google Authenticator

zdnet.com

31–40 of 139 posts

Re: Downsides of Google Authenticator

#31
Since we're apparently all sharing our 2fa methods I've really been liking the yubico authenticator. All the secrets are on the yubikey itself so if something dumb happens to my phone or computer I don't have to worry about them.

Plus, the same device does my FIDO2 / u2f / whatever it is this month for the services that support it.

Re: Downsides of Google Authenticator

#32
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

> You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface.

I find that a terrible design decision, because now every website has to implement their own backup code flow. PayPal, for example, is one of the most critical applications when talking about authentication, and while they support 2FA they don't give you any backup codes at all: https://www.paypal-community.com/t5/My-Account/Backup-codes/...

Now I cannot synchronize devices, I'm hosed if I ever lose my phone, and I'm still relying on PayPal customer support to do a proper out-of-band authentication. The worst of both worlds.

Re: Downsides of Google Authenticator

#33
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

>- Passcode or biometric locks on an app are a gimmick and offer negligible value.

Biometric locks are interfaces that the OS does not expose to users, and that are backed via an HSM. On the iPhone and modern Android, they allow you to envelope encrypt a message via biometrics in such a way that it can only be unlocked from within the app that locked it AND via enrolled biometric signatures. Passcodes are the same, but easier to phish.

It is incorrect to say that they "are a gimmick and offer negligible value".

In this document, they lay out these mechanisms in great detail. Anyone with an interest in security should read this, imo. It's a magnificent "blue team" effort https://www.apple.com/ca/business-docs/iOS_Security_Guide.pd...

Re: Downsides of Google Authenticator

#34
Last time I checked, by default, Authy codes were susceptible to SIM-swap attacks.[0] This is a bad article.

You should perhaps consider switching off of Authenticator to an Open Source manager like AndOTP; I think that's something reasonable to propose. But I don't understand the argument that I should be very concerned a lack of biometric locks, but not concerned about invalidating the "something you have" part of 2FA.

I don't think it's horrible if someone uses an app like Authy. It's better than nothing. But this article didn't need to exist -- if you use Authenticator, just keep using it, it's fine.

[0]: https://nitter.42l.fr/DanielShumway/status/10920819670074982...

Re: Downsides of Google Authenticator

#35
post #8

Earlier quoted context omitted.

Here’s the thing. I consider myself fairly responsible but I’ll bet I’m far more likely to lose my phone than it is that my Authy and Dashlane credentials are both compromised, which are my pw manager and Authenticator app. You have to choose your risks and for a lot of people an authy like feature is much safer overall than GA.

All my 2FA codes are backed up. On paper. I have a physically-secured cache of the QR codes which can be pretty quickly imported into a new app.

What happens when you're traveling? What if some combination of your wallet, laptop, paper files or phone are stolen or destroyed by fire or water?

Essentially, what's your backup plan so if the very worst happens when you're in the middle of nowhere you're not completely locked out?

Re: Downsides of Google Authenticator

#36
post #8

Earlier quoted context omitted.

Here’s the thing. I consider myself fairly responsible but I’ll bet I’m far more likely to lose my phone than it is that my Authy and Dashlane credentials are both compromised, which are my pw manager and Authenticator app. You have to choose your risks and for a lot of people an authy like feature is much safer overall than GA.

All my 2FA codes are backed up. On paper. I have a physically-secured cache of the QR codes which can be pretty quickly imported into a new app.

I see people say this a lot in the tech community, but it’s a preposterous expectation that regular users would be doing something like this. MFA needs to usable by everyone, not just the tech elite.

Re: Downsides of Google Authenticator

#37

Since we're apparently all sharing our 2fa methods I've really been liking the yubico authenticator. All the secrets are on the yubikey itself so if something dumb happens to my phone or computer I don't have to worry about them. Plus, the same device does my FIDO2 / u2f / whatever it is this month for the services that support it.

U2F + Googles Advanced Protection Program = secure AF

https://landing.google.com/advancedprotection/

Re: Downsides of Google Authenticator

#38
post #19
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

I agree with this comment completely. Adding a biometric lock would turn it into 3FA. Not sure if HN allows to plug your own apps, so please forgive: I made an app a while ago that aims to replace Google Authenticator for some of the reasons mentioned: it allows to back-up and transfer tokens without creating a large attack factor. Not having sync is a feature in this case as well. In fact, the app does not even have…

Biometric data should be considered identity and not authentication data. They can never be revoked or rotated for one. And who knows how many people have it on file. Not every auth server gets their own « key »

Re: Downsides of Google Authenticator

#39

I stopped using Google Authenticator in 2013 when my tokens disappeared after a software update [1]. They were restored in the next update, but I didn't like not having access to the raw TOTP data. I switched to Authy after the incident, and now use 1Password after I discovered their TOTP feature. [1] https://news.ycombinator.com/item?id=6325760

Isn’t that putting all eggs in the same basket?

Yes and no.

Yes, it puts 1Password as the only point of failure iff 1Password security is compromised. This would require knowing my Master Password, my Secret Key, and 2FA with either my OTP from Google Authenticator or a Yubikey to open the vault on a new device, or knowing my master password on a device that I already have 1Password set up on.

On the flip side however, for anyone who _doesn't_ know I use 1Password (oops), any credential stuffing attack or password leak is not likely to get anywhere, as they're not going to be attacking my 1Password vault.

Re: Downsides of Google Authenticator

#40
post #3

Bitwarden is a pretty good solution for this! It's not the smoothest since the browser extensions don't know how to fill in your codes like they do your password but it's leaps and bounds above the UX for Google Authenticator. Being able to access my codes from any device with a web browser is very nice. INB4: "But this reduces your security." * Yes, but I'm already using a password manager with 64 char generated pas…

Thanks for posting this. The threat modeling in this thread feels very much out of wack with my personal experience. The thing that has lead to the most compromised accounts for myself is old, short, unchanged passwords on accounts I had forgotten that probably have been leaked.
Post reply on HN