Live data from Hacker News

End of Life for Twilio Authy Desktop App

help.twilio.com

71–80 of 180 posts

Re: End of Life for Twilio Authy Desktop App

#72
post #38

Earlier quoted context omitted.

> I also use bitwarden, but not sure how I feel about passwords and totp being in the same app. I guess this depends on your threat model. In what cases would your password vault be compromised, but your TOTP vault still be secure? If someone gets access to your unlocked PC/phone, don't they then have access to both? Do you store your TOTP vault password in your password vault (obvious)? If someone gets into your pas…

>In what cases would your password vault be compromised, but your TOTP vault still be secure? If the password vault is on one device and the TOTP app on another then it would be harder for an attacker to get into both. I have the same concerns about passkeys. How is it secure if the only thing an attacker needs is a single method of accessing a single device?

Generally the threat model that TOTP protects against is not someone breaking into your device. The threat model that it protects against is someone compromising your other credentials. So, although not recommended, you could post your login credentials on twitter and still nobody would be able to get into your account. An attacker hacking into your laptop/desktop/phone with access to install keyloggers and hijack connections is not really what it protects against.

Re: End of Life for Twilio Authy Desktop App

#74

Earlier quoted context omitted.

Two ways: - a Yubikey - a sparingly used email account with no 2FA, just a very long password 2FA through the sort-of-secret email account lets me get back into Bitwarden (and thus everything else) even if my house burns down and I lose access to all of my yubikeys. And auth on a device that doesn't easily support yubikeys, like older iPhones. 2FA is very useful, but highly overrated. If you have a sufficiently long…

Small side tangent - I’m on Mint Mobile and enabled 2FA for my account there, which is required for all customer calls. This would stop SIM swapping attacks which are the main failure point for SMS 2FA, right?

that depends entirely on Mint's 'lost 2fa' recovery process.

https://www.reddit.com/r/mintmobile/comments/104h7p2/locked_...

seems like some senior CSRs can still get you bypassed.

Re: End of Life for Twilio Authy Desktop App

#75
post #51
post #31

Earlier quoted context omitted.

I migrated to 2FAS, which is open source, free and has a nice UI. Used Authy for ages and just switched. Recommended… https://2fas.com/

But it also only has mobile apps. Authy is only killing the desktop app, not the mobile ones - at least not yet. What does 2FAS give, genuinely curious in case I'm missing something..

There's a browser extension: https://2fas.com/browser-extension/.

Re: End of Life for Twilio Authy Desktop App

#76

Earlier quoted context omitted.

I use Authy. I've read a few comments about how migrating away is difficult. What do you use instead? I also use bitwarden, but not sure how I feel about passwords and totp being in the same app.

I use Raivo for TOTP on iOS. It is open source and makes it easy to migrate to another app

I used to use it, but the author refuses to publish a desktop app. I actually was able to install the iOS app on my desktop, but if I ever remove it, it is gone forever because he revoked it from the appstore. He only wants you to use the desktop receiver.

It is also buggy af and doesn't sync properly. He's pretty much not doing any more updates of the app either.

That experience pushed me off it forever.

Edit: The app has been acquired by a third party. I'd move off it.

https://www.reddit.com/r/privacy/comments/158ihxd/raivo_auth...

Re: End of Life for Twilio Authy Desktop App

#80
post #21
post #2

They intentionally make it really hard to migrate your data off their app under the premise of "security". Now, they are EOL'ing desktop apps, which are extremely convenient to use, despite the terrible UX. https://support.authy.com/hc/en-us/articles/1260805179070-Ex... The process for exporting is doable, but requires fairly deep technical knowledge and it isn't 100% clean. In order to do so, you need that desktop a…

What should I replace it with? Any recommendations for a functionally equivalent cross-device 2FA app?

I just tried adding to KeePass XC - worked well, generates the same OTPs.
Post reply on HN