Live data from Hacker News

Google Authenticator cloud sync: Google can see the secrets, even while stored

defcon.social

71–80 of 149 posts

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#71
post #18

Earlier quoted context omitted.

Why would google have access to that material? Is their general secret mechanism not E2EE? I'm fairly cynical on google's approach to privacy but I would be shocked if they're normal syncing isn't actually secure and private.

Chrome passwords are encrypted with your Google password by default, it's just not e2ee. This isn't even encrypted in that way it seems. The only real "threat" is your Google account itself being compromised by a third party able to phish their way into your account or bypass your 2fa mechanisms (e.g. by SMS sim swapping). As always, https://landing.google.com/advancedprotection/ The people here saying "privacy" are…

>Chrome passwords are encrypted with your Google password by default, it's just not e2ee.

Source?

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#72
post #45

It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…

> Google knows

TBF knowing which online service you bothered to activate 2FA on is an information a lot more interesting than which mailing list you forgot to unsubscribe for instance.

Now I don't think they'd use if for ads, I'd assume it would probably be more long term, like knowing which service to buy next, or where the trends are going.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#73
post #46

Is there anyone who operates an authentication service which: - Has a contractual obligation to keep your data secure. - Accepts financial responsibility for data compromise. - Carries insurance and bonding to back that responsibility. - Does not require binding arbitration or forbid class actions. - Has their employees bonded in the way bank employees are bonded. Well?

Outside of the price issue, this service would also be a prime target go get compromised: I'd assume it would get the juiciest users, and national agencies would have the strongest incentives to backdoor it for later use.

We'd need a bunch of services to get to that level first to see any meaningful choice IMHO. I have no idea how that would happen.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#74
post #47
post #16

Earlier quoted context omitted.

Security keys can be built into the phone and still provide a reasonable expectation of security, e.g. Apple's Passkeys. Obviously, a YubiKey would be better, but Passkeys don't require you to carry an additional thing and are still more secure than TOTP apps.

> can be built into the phone I don’t like this idea. As a person whose had a phone break, like many others, tying auth to something so fragile should not be preferable. I’ll never forget my phone breaking and the process of trying to order a new one: the online shopping here, Shopee, demanded SMS 2FA (only option) which I needed to purchase a new phone so I found a different vendor but then my bank required SMS 2FA…

who’s* had a phone break

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#75

Earlier quoted context omitted.

The problem with security keys is that they're expensive and you have to carry them around. TOTP is cheap and much better 2FA than OTP over SMS.

This is sort of willfully missing the point, I concede, but I have my U2F token physically embedded in my arm and have minimal fear of losing it/being without it. Right now it runs OpenPGP and a Yubikey U2F emulator, but it can run just about any flavor of MFA with the appropriate companion app (full subdermal Java Card platform). https://dangerousthings.com/product/flexsecure/ Hard agree, though, TOTP >>>>>> OTP via…

That's some wild Bourne Identity stuff. The thing permanently bricks itself after a specific number of failed attempts. About 3cm long and does TOTP and PGP. Wild.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#77
post #34
post #7

Earlier quoted context omitted.

Until people stop using SMS codes it's still way more safe from cell phone cloning attacks.

People should have stopped using SMS codes when NIST told them to stop six years ago. The fact that there are websites that still support it is an abomination and should come with hefty legal penalties.

The Australian Government's national website for its citizens to interact with gov services uses SMS based 2FA, and doesn't appear to support any other type. :/

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#78
post #46

Is there anyone who operates an authentication service which: - Has a contractual obligation to keep your data secure. - Accepts financial responsibility for data compromise. - Carries insurance and bonding to back that responsibility. - Does not require binding arbitration or forbid class actions. - Has their employees bonded in the way bank employees are bonded. Well?

How much would you pay for it?

Huh, can't I get this service for free or at most $1 a month...What are you saying? :)

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#79
post #45

It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…

I don't think Google will use those secrets to look into your other accounts, but they can be politely requested by some governments to divulge the secrets, and not tell you about it. Then those governments would have no problems looking into your other accounts. And I'm not talking only about the US government, other governments can have dubious standards for requesting user data, such as failure to parrot the "fact…

I appreciate this. A lot of people think your tech is between you and the provider, but they forget about the governments that have power over those providers.
Post reply on HN