It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…
Google Authenticator cloud sync: Google can see the secrets, even while stored
81–90 of 149 posts
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#82It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…
www.reddit.com/r/degoogle
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#83It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…
The whole writeup seems like missing the forest for the trees - Google as root access on the Android device where this app runs, so they can certainly see everything if they want ....
In contrast, subpoena'ing data from the cloud is routine for police in countries all over the world.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#84Imagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part of that account
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#85Earlier quoted context omitted.
Until people stop using SMS codes it's still way more safe from cell phone cloning attacks.
People should have stopped using SMS codes when NIST told them to stop six years ago. The fact that there are websites that still support it is an abomination and should come with hefty legal penalties.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#86Authy gets this right. Not sure why anyone would trust Google with their 2FA secrets.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#87Earlier quoted context omitted.
Looks good at a first glimpse. Please don't write "it's free". That's a non-message many companies give, Google of course one of them. We know that it means you pay by providing your data. Other models could be "run by volunteers" or "fully funded by donations".
But it is free, both by the casual definition (zero cost) and by FSF definition (Free Software).
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#88Earlier quoted context omitted.
The whole writeup seems like missing the forest for the trees - Google as root access on the Android device where this app runs, so they can certainly see everything if they want ....
Google pushing malicious updates would leave forensic traces, not to mention it'd be difficult to establish a legal framework allowing a government to force Google to do so. In contrast, subpoena'ing data from the cloud is routine for police in countries all over the world.
For example, in the past I've worked with an AI company with presence in China, where the data of their Chinese clientele must be stored on a separate data centre operated by a local enterprise.
Despite the provider being ISO compliant and holds internationally recognised certs, is there realistically a chance that those data could be accessed without the permission or consent of the users?
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#89It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…
The whole writeup seems like missing the forest for the trees - Google as root access on the Android device where this app runs, so they can certainly see everything if they want ....
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#90It has an option for encrypted, automated backups to Google or Nextcloud.