Live data from Hacker News

Google Authenticator cloud sync: Google can see the secrets, even while stored

defcon.social

1–10 of 149 posts

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#5
> if someone obtains access to your Google Account, all of your 2FA secrets would be compromised.

This overlooks that fact Google itself also has access to your 2FA secrets, which could be even worse considering Google could be requested to peer not just into the user's google account, but into accounts they have with other companies/organisations too.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#6

Someone will, of course, claim Google would never do this, but this presumably would make it trivial for Google itself to log into all of your accounts. In many cases they are already syncing a copy of your passwords.

It's 2FA so it would only get them half way there right?

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#8
What? Why would this not get the same end-to-end encryption as Android backups? They'd have to do extra work to make this less secure.

Edit: oh I guess because it supports syncing between Android and iOS? Still lame, they should at least have an option to use the normal Android backup system. Which should have been the default since the start.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#9
post #6

Someone will, of course, claim Google would never do this, but this presumably would make it trivial for Google itself to log into all of your accounts. In many cases they are already syncing a copy of your passwords.

It's 2FA so it would only get them half way there right?

> In many cases they are already syncing a copy of your passwords.

No, that gets them the full way there. They have your 2FA codes, and if you use Chrome and opt into it syncing passwords for you (passwords.google.com), this gives them both pieces of the puzzle.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#10
post #5

> if someone obtains access to your Google Account, all of your 2FA secrets would be compromised. This overlooks that fact Google itself also has access to your 2FA secrets, which could be even worse considering Google could be requested to peer not just into the user's google account, but into accounts they have with other companies/organisations too.

Hey, I am about to start writing a position paper covering Social login providers the company should enable/support. Do you have any references you can share for the above comment please ?
Post reply on HN