Live data from Hacker News

Google Authenticator cloud sync: Google can see the secrets, even while stored

defcon.social

61–70 of 149 posts

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#61
post #57

Can the title get changed? - E2E in this case is nebulous, this isn't a chat or email client, it isn't client client with Google acting as an intermediary. It is between your Google account/Google's Server and Google's software. - It isn't clear if during transportation it is encrypted (e.g. HTTPS?); since seemingly this post isn't about that (or if it is the evidence or technical information is lacking). The term "E…

> The actual complaint SEEMS to be: Google Authenticator backup isn't encrypted at rest on Google's Servers Encryption at rest would NOT solve the problem being described here. Even if the data was encrypted both in transit and at rest, that does not mean that Google is incapable of getting access to the data. The data needs to be encrypted from the moment it leaves the device until the moment it arrives back on the…

The "not encrypted at rest" part seems to be pure speculation: "As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers." Is there some actual evidence for this claim that I'm not noticing?

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#62

After my phone was stolen last month, I switched to https://2fas.com and couldn't be any happier. It's free, open source and has tons of great features.

Looks good at a first glimpse. Please don't write "it's free". That's a non-message many companies give, Google of course one of them. We know that it means you pay by providing your data. Other models could be "run by volunteers" or "fully funded by donations".

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#63
post #61
post #57

Earlier quoted context omitted.

> The actual complaint SEEMS to be: Google Authenticator backup isn't encrypted at rest on Google's Servers Encryption at rest would NOT solve the problem being described here. Even if the data was encrypted both in transit and at rest, that does not mean that Google is incapable of getting access to the data. The data needs to be encrypted from the moment it leaves the device until the moment it arrives back on the…

The "not encrypted at rest" part seems to be pure speculation: "As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers." Is there some actual evidence for this claim that I'm not noticing?

That sentence doesn't imply anything about whether they're encrypted at rest or not. Even if they were encrypted at rest (but not E2E encrypted), Google can just decrypt the secrets to see them. The problem here doesn't involve encryption at rest in any way and there's nothing being claimed about whether the secrets are encrypted at rest or not.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#64
post #45

It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…

I don't think Google will use those secrets to look into your other accounts, but they can be politely requested by some governments to divulge the secrets, and not tell you about it. Then those governments would have no problems looking into your other accounts. And I'm not talking only about the US government, other governments can have dubious standards for requesting user data, such as failure to parrot the "facts" approved by their ministry of truth (China, Russia, and everyone in their sphere).

Not to mention Google can be hacked.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#65
post #15

Earlier quoted context omitted.

Under what conditions do you suggest "Google itself also has access to all your 2FA secrets"? (Without cloud backup, & without the installation of a malicious version of 'Google Authenticator', how would they – especially, say, on iOS?)

I think they are referring to the scenario where cloud backup is enabled.

Aha, thanks. But, if the 2FA secrets were end-encrypted as the top link suggests, Google then wouldn't in fact have them - so the ggp-comment accusation that the link "overlooks" this factor is nonsensical.

(And if Google were denied access to the cleartext 2FA secrete this, way, then briefly compromising someone's Google account – say by hacking or abuse of legal process – wouldn't automatically compromise all other 2FA-key-protected accounts.)

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#66
post #62

After my phone was stolen last month, I switched to https://2fas.com and couldn't be any happier. It's free, open source and has tons of great features.

Looks good at a first glimpse. Please don't write "it's free". That's a non-message many companies give, Google of course one of them. We know that it means you pay by providing your data. Other models could be "run by volunteers" or "fully funded by donations".

But it is free, both by the casual definition (zero cost) and by FSF definition (Free Software).

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#69
post #18

Earlier quoted context omitted.

Why would google have access to that material? Is their general secret mechanism not E2EE? I'm fairly cynical on google's approach to privacy but I would be shocked if they're normal syncing isn't actually secure and private.

Chrome passwords are encrypted with your Google password by default, it's just not e2ee. This isn't even encrypted in that way it seems. The only real "threat" is your Google account itself being compromised by a third party able to phish their way into your account or bypass your 2fa mechanisms (e.g. by SMS sim swapping). As always, https://landing.google.com/advancedprotection/ The people here saying "privacy" are…

[deleted]

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#70
post #46

Is there anyone who operates an authentication service which: - Has a contractual obligation to keep your data secure. - Accepts financial responsibility for data compromise. - Carries insurance and bonding to back that responsibility. - Does not require binding arbitration or forbid class actions. - Has their employees bonded in the way bank employees are bonded. Well?

How much would you pay for it?
Post reply on HN