Live data from Hacker News

End of Life for Twilio Authy Desktop App

help.twilio.com

61–70 of 180 posts

Re: End of Life for Twilio Authy Desktop App

#61
post #58

Getting a user to install software on a desktop is probably one of the hardest things for a company to ask for in 2024. It's wild that you would have built up a userbase of ... tens of thousands? ... of technically knowledgeable people who want your product, get them to install and rely on your product on their actual 2024 desktop computer where they do actual work, then have some decision makers determine "ok time t…

I agree, seems short-sighted - they could have even just started charging a bit for it to keep it alive if necessary.

No surprise though, after a fantastic start, twilio has turned into a sh*t company, unfortunately - I was a very early adaptor of many of their tools and services, and 1 by 1, they have all gone downhill.

They should have sold the company while it still had a decent reputation, at this rate there will be nothing of worth left.

Re: End of Life for Twilio Authy Desktop App

#67
post #38

Earlier quoted context omitted.

I use Authy. I've read a few comments about how migrating away is difficult. What do you use instead? I also use bitwarden, but not sure how I feel about passwords and totp being in the same app.

> I also use bitwarden, but not sure how I feel about passwords and totp being in the same app. I guess this depends on your threat model. In what cases would your password vault be compromised, but your TOTP vault still be secure? If someone gets access to your unlocked PC/phone, don't they then have access to both? Do you store your TOTP vault password in your password vault (obvious)? If someone gets into your pas…

>In what cases would your password vault be compromised, but your TOTP vault still be secure?

If the password vault is on one device and the TOTP app on another then it would be harder for an attacker to get into both.

I have the same concerns about passkeys. How is it secure if the only thing an attacker needs is a single method of accessing a single device?

Re: End of Life for Twilio Authy Desktop App

#69

How do folks use two factor auth for 1password logins? It feels wrong to me to use 1password as the second factor for 1password itself. My last remaining authy second factors are for primary email and 1password. All other second factors are in 1password.

Two ways: - a Yubikey - a sparingly used email account with no 2FA, just a very long password 2FA through the sort-of-secret email account lets me get back into Bitwarden (and thus everything else) even if my house burns down and I lose access to all of my yubikeys. And auth on a device that doesn't easily support yubikeys, like older iPhones. 2FA is very useful, but highly overrated. If you have a sufficiently long…

Small side tangent - I’m on Mint Mobile and enabled 2FA for my account there, which is required for all customer calls. This would stop SIM swapping attacks which are the main failure point for SMS 2FA, right?

Re: End of Life for Twilio Authy Desktop App

#70
post #53

This was mentioned below (HT to Eric_WVGG for pointing it out [0]) but I think it warrants a top level comment: If you have an ARM Mac you can install the Authy iPad app and use it just like the Desktop app. If you want to have a desktop backup but aren't ready to migrate yet, this is a fantastic stop-gap solution. [0] https://news.ycombinator.com/item?id=39360950

Of course, if you have an Apple product, you can also use the TOTP function built-in to Keychain. iPhone doc here:

https://support.apple.com/guide/iphone/automatically-fill-in...

Post reply on HN