Live data from Hacker News

Downsides of Google Authenticator

zdnet.com

91–100 of 139 posts

Re: Downsides of Google Authenticator

#91
post #77

Earlier quoted context omitted.

As a LastPass user, my main defense against the possibility of someone accessing my LastPass account is the fact that all of my important accounts have 2FA completely separate from LastPass. So if someone got a hold of my LastPass master password, they can't access my google account, banking, etc.

I'm curious about LastPass - it's what I use and work in politics.. Their security page says encrypted on device [1] before sending to them? is that not trustworthy or I'm not understanding? or maybe worried about compromised devices (where it's over anyways)? 1: https://www.lastpass.com/enterprise/security

I trust LastPass's security as much as I trust any company's security. I'm not worried about MITM attacks, but there are many other ways that someone could get access to an account.

The biggest security issue is that they hold the keys to my entire kingdom. So if someone somehow gains access to that account, I need another layer of protection, no matter how small the chances are.

Re: Downsides of Google Authenticator

#92
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

> In particular, Authy, LastPass and 1password have a giant attack surface compared to a simple app like Google Authenticator. They also rely on centralized services and if you also keep your passwords in there, you eliminate the whole point of two factor authentication. 1pass user, while I know that it's not as secure as keeping them separated I view it as if someone has access to my 1password vault unencrypted I'm…

DashLane in the streets, 1pass in the sheets.

My 1pass vault is decentralized, and also includes a robust password generator for making stuff on the fly -- something Dashlane lacks. I'm not sure I'm using either service fully, but one of them is a work freebie and the other is from back before 1pass went to a subscription model.

... the idea isn't that either are perfect, but since password sharing and phishing are a bigger attack vector than whether my phone falls into the wrong hands, using 2FA as anti-phishing insurance is still better than not.

Re: Downsides of Google Authenticator

#93
post #76

Earlier quoted context omitted.

Authy Desktop Memory / Real / Shared 71.3 MB 116.8 MB 96.3 MB

> du -sh Authy\ Desktop.app/ 142M Authy Desktop.app/ > du -sh Clozure\ CL.app/ 35M Clozure CL.app/

disk space is cheap, ram is expensive.

Re: Downsides of Google Authenticator

#94
post #32
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

> You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. I find that a terrible design decision, because now every website has to implement their own backup code flow. PayPal, for example, is one of the most critical applications when talking about authentication, and while they support 2FA they don't give you any backup codes at all: https://www.paypal-communit…

The best available solution is to implement WebAuthn support and allow users to add multiple devices. No backup code, no phishing.

Re: Downsides of Google Authenticator

#95
post #89
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS). Without backups, having a phone die or get lost is a very frustrating experie…

Totally agree, I had my phone stolen a few years back. Had to buy a new one. What a surprise when I restored Google Authenticator and all my sites were gone.

However I do have an issue with 1password's feature of auto-filling those codes, seems like it's just invalidated the whole "something you have" party of MFA.

For me Authy is a happy medium

Re: Downsides of Google Authenticator

#96
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

I agree with you on the advantages of U2F/WebAuthn, but the rest of your comment seems pretty oblivious to the usability challenges of TOTP MFA. The security risks that you cite are remote and orthogonal to the security risks of not having MFA in the first place. Trying to shame users into obeying the finer details of the TOTP RFC won't work. Let's just nudge people over to U2F instead.

Re: Downsides of Google Authenticator

#97

Earlier quoted context omitted.

Authy only has SIM issues if you give it your phone number. Don't do that.

The linked article is recommending Authy over Authenticator because backing up codes on multiple devices is too hard. If you're going to disable remote backup on Authy, then there's almost no advantage to switching away from Authenticator in the first place. Authy also doesn't allow local export of tokens, so there's no advantage there. I guess with Authenticator you lose the ability to lock your local tokens with a…

You're right... I take back my comment. For some reason I thought that I had removed the number from Authy. I definitely have multiple devices turned off, which is definitely a confusing bit of UX.

I had a long thread with @philnash (Twillio which owns Authy) not too long ago... this is his reasoning...

https://news.ycombinator.com/item?id=22022814

While I do not agree with him about having SMS enabled at all, I can listen to his reasoning.

I also agree with you... Authy has been treated a bit like a bastard child once it went to Twillio... the updates are few and far between. The UX isn't great and hasn't improved.

Seems like a good opportunity to build something better.

Re: Downsides of Google Authenticator

#98

Earlier quoted context omitted.

Authy only has SIM issues if you give it your phone number. Don't do that.

You can have a mobile number based backup and restore on SAASPASS Authenticator without SIM swap issues by adding a custom password as well. Alternatively you can have it on multiple devices without a mobile number by cloning it.

Interesting. Never heard of that company before. What a horrid name. But their app looks interesting and is free for personal tier. I'll check it out. Thanks!

Re: Downsides of Google Authenticator

#99
post #76

Earlier quoted context omitted.

> du -sh Authy\ Desktop.app/ 142M Authy Desktop.app/ > du -sh Clozure\ CL.app/ 35M Clozure CL.app/

disk space is cheap, ram is expensive.

  > ps ax -o %mem,comm | grep dx86cl64
   0.4 /Users/ron/devel/ccl/v1.11/Clozure CL64.app/Contents/MacOS/dx86cl64
  
  > ps ax -o %mem,comm | grep Authy
   0.7 /Applications/Authy Desktop.app/Contents/MacOS/Authy Desktop
   0.2 /Applications/Authy Desktop.app/Contents/Frameworks/Authy Desktop Helper.app/Contents/MacOS/Authy Desktop Helper
   1.1 /Applications/Authy Desktop.app/Contents/Frameworks/Authy Desktop Helper.app/Contents/MacOS/Authy Desktop Helper
No matter how you slice it, Authy is just an outrageous resource hog.

Re: Downsides of Google Authenticator

#100

Last time I checked, by default, Authy codes were susceptible to SIM-swap attacks.[0] This is a bad article. You should perhaps consider switching off of Authenticator to an Open Source manager like AndOTP; I think that's something reasonable to propose. But I don't understand the argument that I should be very concerned a lack of biometric locks, but not concerned about invalidating the "something you have " part of…

Last few times I've set up new devices, I've had to 2FA using an existing device on my account, not just the phone number. You can also disable the multi-device switch in settings which will not allow adding any new devices to your account until disabled.
Post reply on HN