Live data from Hacker News

Google Authenticator cloud sync: Google can see the secrets, even while stored

defcon.social

81–90 of 149 posts

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#81
post #45

It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…

The whole writeup seems like missing the forest for the trees - Google as root access on the Android device where this app runs, so they can certainly see everything if they want ....

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#82
post #45

It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…

> Google know

www.reddit.com/r/degoogle

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#83
post #81
post #45

It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…

The whole writeup seems like missing the forest for the trees - Google as root access on the Android device where this app runs, so they can certainly see everything if they want ....

Google pushing malicious updates would leave forensic traces, not to mention it'd be difficult to establish a legal framework allowing a government to force Google to do so.

In contrast, subpoena'ing data from the cloud is routine for police in countries all over the world.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#85
post #34
post #7

Earlier quoted context omitted.

Until people stop using SMS codes it's still way more safe from cell phone cloning attacks.

People should have stopped using SMS codes when NIST told them to stop six years ago. The fact that there are websites that still support it is an abomination and should come with hefty legal penalties.

People? It's banks, who all insist on SMS, not people,

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#87
post #62

Earlier quoted context omitted.

Looks good at a first glimpse. Please don't write "it's free". That's a non-message many companies give, Google of course one of them. We know that it means you pay by providing your data. Other models could be "run by volunteers" or "fully funded by donations".

But it is free, both by the casual definition (zero cost) and by FSF definition (Free Software).

He wants to distinguish between "free: you pay with your privacy and we share your data with whoever wants it!" or "free: but only basic features, want more? pay" and "free: because people like you help it being 100% free and we have no pressure to use your data and everything is open so you can look at the code"

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#88
post #81

Earlier quoted context omitted.

The whole writeup seems like missing the forest for the trees - Google as root access on the Android device where this app runs, so they can certainly see everything if they want ....

Google pushing malicious updates would leave forensic traces, not to mention it'd be difficult to establish a legal framework allowing a government to force Google to do so. In contrast, subpoena'ing data from the cloud is routine for police in countries all over the world.

This may sound like a naive question, but what stops countries with flexible ethical standards from abusing this power?

For example, in the past I've worked with an AI company with presence in China, where the data of their Chinese clientele must be stored on a separate data centre operated by a local enterprise.

Despite the provider being ISO compliant and holds internationally recognised certs, is there realistically a chance that those data could be accessed without the permission or consent of the users?

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#89
post #81
post #45

It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…

The whole writeup seems like missing the forest for the trees - Google as root access on the Android device where this app runs, so they can certainly see everything if they want ....

There is a lot of difference between being as secure as practically possible with password data, and allowing anyone with root access to see all your password data.
Post reply on HN