Earlier quoted context omitted.
As long as you use encrypted backups with iPhone, your GA keys are backed up and you can restore a new phone with them also.
GA keys are not in icloud backups. You mean local “usb” backups?
Downsides of Google Authenticator
111–120 of 139 posts
Re: Downsides of Google Authenticator
#112Since we're apparently all sharing our 2fa methods I've really been liking the yubico authenticator. All the secrets are on the yubikey itself so if something dumb happens to my phone or computer I don't have to worry about them. Plus, the same device does my FIDO2 / u2f / whatever it is this month for the services that support it.
https://www.openssh.com/txt/release-8.2
https://www.phoronix.com/scan.php?page=news_item&px=OpenSSH-...
Re: Downsides of Google Authenticator
#113Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
Re: Downsides of Google Authenticator
#114Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS). Without backups, having a phone die or get lost is a very frustrating experie…
Re: Downsides of Google Authenticator
#115Earlier quoted context omitted.
I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS). Without backups, having a phone die or get lost is a very frustrating experie…
Totally agree, I had my phone stolen a few years back. Had to buy a new one. What a surprise when I restored Google Authenticator and all my sites were gone. However I do have an issue with 1password's feature of auto-filling those codes, seems like it's just invalidated the whole "something you have" party of MFA. For me Authy is a happy medium
Re: Downsides of Google Authenticator
#116I don't know what the current situation is for iOS, but on Android I've been using andOTP and it addresses pretty much all of the author's pain points (except for automated syncing between devices and the need to install it per-device, but you really should keep the number of TOTP-generating devices to a minimum; more devices = more opportunities for someone to steal that second factor of authentication).
Re: Downsides of Google Authenticator
#117Last time I checked, by default, Authy codes were susceptible to SIM-swap attacks.[0] This is a bad article. You should perhaps consider switching off of Authenticator to an Open Source manager like AndOTP; I think that's something reasonable to propose. But I don't understand the argument that I should be very concerned a lack of biometric locks, but not concerned about invalidating the "something you have " part of…
Re: Downsides of Google Authenticator
#118Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
> - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. And it's easy enough to synchronize multiple devices to the same qrcode when setting up 2FA so that you can generate codes from a backup device if one goes missing.
Re: Downsides of Google Authenticator
#119Earlier quoted context omitted.
They are a weak mechanism against individual targeted attacks, but a great mechanism for herd immunity. It's not perfect, for sure, but it helps raise the posture for the general user in a way that's easy and accessible. That's a win, imo.
> They are a [...] great mechanism for herd immunity. I don't see how, could you elaborate what you mean? Imagine a leak from a database storing biometric keys, is this a disaster on par with a normal leak? In my opinion it's even worse! You might say we only use biometrics for a local authentication, but that would limit their application. If you convince people biometrics are great, such database will inevitably be…
This, by the way, still also requires physical access to the device if used for local authentication. And in the event biometrics are used in a physical location (which I’m not personally a fan of, but let’s consider it anyway), there’s often also a human there as well. Your clever mask may fool the sensor, but it probably also still looks like a mask to the guard behind the desk.
Re: Downsides of Google Authenticator
#120Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…
I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS). Without backups, having a phone die or get lost is a very frustrating experie…