Live data from Hacker News

Downsides of Google Authenticator

zdnet.com

111–120 of 139 posts

Re: Downsides of Google Authenticator

#111
post #9

Earlier quoted context omitted.

As long as you use encrypted backups with iPhone, your GA keys are backed up and you can restore a new phone with them also.

GA keys are not in icloud backups. You mean local “usb” backups?

They are definitely in local backups (note that I didn't say iCloud), but I believe they're in encrypted iCloud backups as well, as I've done recovered phones with GA tokens from an iCloud backup before.

Re: Downsides of Google Authenticator

#112

Since we're apparently all sharing our 2fa methods I've really been liking the yubico authenticator. All the secrets are on the yubikey itself so if something dumb happens to my phone or computer I don't have to worry about them. Plus, the same device does my FIDO2 / u2f / whatever it is this month for the services that support it.

Yes, and OpenSSH just added FIDO/U2F support!

https://www.openssh.com/txt/release-8.2

https://www.phoronix.com/scan.php?page=news_item&px=OpenSSH-...

Re: Downsides of Google Authenticator

#113
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

This sort of user-hostile approach is not a net positive for security, because most people don't want to have a bunch of offline backup codes for each one of the hundreds of websites they have signed up with.

Re: Downsides of Google Authenticator

#114
post #89
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS). Without backups, having a phone die or get lost is a very frustrating experie…

Google Authenticator is backed up on iOS if you use an encrypted local backup via iTunes (or macOS Catalina) or iMazing.

Re: Downsides of Google Authenticator

#115
post #95
post #89

Earlier quoted context omitted.

I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS). Without backups, having a phone die or get lost is a very frustrating experie…

Totally agree, I had my phone stolen a few years back. Had to buy a new one. What a surprise when I restored Google Authenticator and all my sites were gone. However I do have an issue with 1password's feature of auto-filling those codes, seems like it's just invalidated the whole "something you have" party of MFA. For me Authy is a happy medium

Google Authenticator is backed up on iOS if you use an encrypted local backup via iTunes (or macOS Catalina) or iMazing.

Re: Downsides of Google Authenticator

#116
"Still using Google Authenticator? Let me recommend a replacement with a significantly larger attack surface."

I don't know what the current situation is for iOS, but on Android I've been using andOTP and it addresses pretty much all of the author's pain points (except for automated syncing between devices and the need to install it per-device, but you really should keep the number of TOTP-generating devices to a minimum; more devices = more opportunities for someone to steal that second factor of authentication).

Re: Downsides of Google Authenticator

#117

Last time I checked, by default, Authy codes were susceptible to SIM-swap attacks.[0] This is a bad article. You should perhaps consider switching off of Authenticator to an Open Source manager like AndOTP; I think that's something reasonable to propose. But I don't understand the argument that I should be very concerned a lack of biometric locks, but not concerned about invalidating the "something you have " part of…

Authy keys are encrypted with your passphrase before they are synced. You can't reset this password even after SIM-swap.

Re: Downsides of Google Authenticator

#118
post #106
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

> - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. And it's easy enough to synchronize multiple devices to the same qrcode when setting up 2FA so that you can generate codes from a backup device if one goes missing.

If your account get hacked, then the one includes hacker's phone. The whole point of totp is gone. Hackers no longer need to stole your phone physically. Hack your account is enough.

Re: Downsides of Google Authenticator

#119

Earlier quoted context omitted.

They are a weak mechanism against individual targeted attacks, but a great mechanism for herd immunity. It's not perfect, for sure, but it helps raise the posture for the general user in a way that's easy and accessible. That's a win, imo.

> They are a [...] great mechanism for herd immunity. I don't see how, could you elaborate what you mean? Imagine a leak from a database storing biometric keys, is this a disaster on par with a normal leak? In my opinion it's even worse! You might say we only use biometrics for a local authentication, but that would limit their application. If you convince people biometrics are great, such database will inevitably be…

Sure, but keep in mind the prerequisites for using that leaked data. You have to either place yourself in between the sensor and the rest of the device or physically recreate the biometric with enough fidelity to fool the sensor. These are both possible, yes, but they’re significantly less trivial than using a password.

This, by the way, still also requires physical access to the device if used for local authentication. And in the event biometrics are used in a physical location (which I’m not personally a fan of, but let’s consider it anyway), there’s often also a human there as well. Your clever mask may fool the sensor, but it probably also still looks like a mask to the guard behind the desk.

Re: Downsides of Google Authenticator

#120
post #89
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS). Without backups, having a phone die or get lost is a very frustrating experie…

Use the text based secret and save a copy in an encrypted file and keep it on a usb memory stick. Put that in a safety deposit box if are paranoid enough. Either way, you lose your phone you have all your auth secrets available to re-enter.
Post reply on HN