Live data from Hacker News

TOTP tokens on my wrist with the smartest dumb watch

blog.singleton.io

41–50 of 131 posts

Re: TOTP tokens on my wrist with the smartest dumb watch

#41
post #2

Cool hack. That said: A security reminder to anyone who is in the target audience here: if you're clever enough to have TOTP 2FA enabled on your Google account, get some cheap USB security keys and enable Advanced Protection, which completely disables non-hardware 2FA. It requires two different tokens (and you should really get one for each computer you have/use, plus at least one offsite backup) because once enabled…

> which completely disables non-hardware 2FA

Does this make Google stop asking for my phone number?

Re: TOTP tokens on my wrist with the smartest dumb watch

#42
post #26

If you are not that a hacker but already own a Smartwatch such as the Apple Watch, Authy[1] is a pretty rock solid option. I use Authy for a few key credentials, and I have used my watch for the keys. FYI, Authy was bought and is now owned by Twilio 1. https://authy.com

I use Duo Mobile [1] with my Apple Watch. Authy gets recommended often here but got turned off of them because they require a phone number to set up the app on iOS. There's no phone number requirement for TOTP implementations so I eventually found Duo Mobile. This was before they got bought by Cisco. 1: https://apps.apple.com/us/app/duo-mobile/id422663827

I use AndOTP on Android. You can export to a PGP-encrypted JSON file so your keys are really your own and not locked into a walled garden like Authy.

Re: TOTP tokens on my wrist with the smartest dumb watch

#43
post #26

If you are not that a hacker but already own a Smartwatch such as the Apple Watch, Authy[1] is a pretty rock solid option. I use Authy for a few key credentials, and I have used my watch for the keys. FYI, Authy was bought and is now owned by Twilio 1. https://authy.com

I use Duo Mobile [1] with my Apple Watch. Authy gets recommended often here but got turned off of them because they require a phone number to set up the app on iOS. There's no phone number requirement for TOTP implementations so I eventually found Duo Mobile. This was before they got bought by Cisco. 1: https://apps.apple.com/us/app/duo-mobile/id422663827

The phone number gets used during account recovery; when I reset my iPhone once without a second Authy device to activate it, I was locked out for 24h while it bombarded my number with calls and texts about the impending restore. I appreciated that safety measure.

Re: TOTP tokens on my wrist with the smartest dumb watch

#44
post #35

If you are not that a hacker but already own a Smartwatch such as the Apple Watch, Authy[1] is a pretty rock solid option. I use Authy for a few key credentials, and I have used my watch for the keys. FYI, Authy was bought and is now owned by Twilio 1. https://authy.com

I use Authy as well. Best part is it backups your stuff.

Are those backups E2EE?

Also to be totally honest, each device should have their own TOTP key and while backups are fine*, key sharing isn't.

Re: TOTP tokens on my wrist with the smartest dumb watch

#45
post #26

Earlier quoted context omitted.

I use Duo Mobile [1] with my Apple Watch. Authy gets recommended often here but got turned off of them because they require a phone number to set up the app on iOS. There's no phone number requirement for TOTP implementations so I eventually found Duo Mobile. This was before they got bought by Cisco. 1: https://apps.apple.com/us/app/duo-mobile/id422663827

I use AndOTP on Android. You can export to a PGP-encrypted JSON file so your keys are really your own and not locked into a walled garden like Authy.

AndOTP is great. Especially if you compare it with all the iOS options.

iOS TOTP apps all suck, it's amazingly bad. I installed like ~15 different ones. After the fifth try, I just had to know if it was just my poor initial selection or a general problem.

Each and every iOS TOTP app has at least one crucial problem - requiring a subscription, mandatory sync to a proprietary cloud, having no export-import, not having a watch companion, being from an unknown/generic developer, no support for longer TOTP codes (worse, some display it truncated!) or they're simply very buggy.

I settled on Step Two because it was like all the others, but not an eyesore...

Re: TOTP tokens on my wrist with the smartest dumb watch

#46

If you are not that a hacker but already own a Smartwatch such as the Apple Watch, Authy[1] is a pretty rock solid option. I use Authy for a few key credentials, and I have used my watch for the keys. FYI, Authy was bought and is now owned by Twilio 1. https://authy.com

There's also Step Two, for iOS, Watch OS and even macOS. I quite like it.

Re: TOTP tokens on my wrist with the smartest dumb watch

#47

If you are not that a hacker but already own a Smartwatch such as the Apple Watch, Authy[1] is a pretty rock solid option. I use Authy for a few key credentials, and I have used my watch for the keys. FYI, Authy was bought and is now owned by Twilio 1. https://authy.com

Ah yes, Twilio, the company that activated 2FA, forced users to activate it during login, and somehow forced it to be SMS auth (aka, completely jamming my account because I dared to login).

Had to manually contact them to resolve and then close the account because FUCK THAT, and fuck SendGrid too, which did the exact same thing after Twilio acquired them.

Sorry, I don't buy for a second that that was an accident or negligence. I'm sick of watching people play ball with companies that pull such moves. (Edit: you want to KYC me to prevent abuse? Fine. Don't make my startup insecure to achieve it.)

Authy is just not a good suggestion here when there are standard, non-needlessly-tied-to-sms options.

Re: TOTP tokens on my wrist with the smartest dumb watch

#48
post #26

Earlier quoted context omitted.

I use Duo Mobile [1] with my Apple Watch. Authy gets recommended often here but got turned off of them because they require a phone number to set up the app on iOS. There's no phone number requirement for TOTP implementations so I eventually found Duo Mobile. This was before they got bought by Cisco. 1: https://apps.apple.com/us/app/duo-mobile/id422663827

The phone number gets used during account recovery; when I reset my iPhone once without a second Authy device to activate it, I was locked out for 24h while it bombarded my number with calls and texts about the impending restore. I appreciated that safety measure.

And I don't appreciate being forced into a "feature" that specifically subverts the entire god damn point of 2FA codes and leaves them in an unprotected state on some third party server.

Great!

Re: TOTP tokens on my wrist with the smartest dumb watch

#49
post #35

Earlier quoted context omitted.

I use Authy as well. Best part is it backups your stuff.

Are those backups E2EE? Also to be totally honest, each device should have their own TOTP key and while backups are fine*, key sharing isn't.

No. They aren't. This thread is seriously upsetting to read. So many people clearly haven't even remotely begun to think about what they're doing or the implications thereof.

Re: TOTP tokens on my wrist with the smartest dumb watch

#50
Is there some Unix-ish tool to generate these TOTPs on a laptop? I don't like to keep the 2nd factor on a small mobile device that is easy to lose. So I ask about a laptop tool.

By Unix-ish I mean something that is small and does one thing well. Like pipe in a secret to it and it gives me a TOTP? Pipe in multiple secrets and it gives me multiple TOTPs? Then I don't have to remain beholden to a custom encryption format. I can encrypt my secrets with other Unix-ish tools, decrypt it, pipe it to this tool and get my TOTPs. Recommendations?

Post reply on HN