Live data from Hacker News

End of Life for Twilio Authy Desktop App

help.twilio.com

81–90 of 180 posts

Re: End of Life for Twilio Authy Desktop App

#81
post #2

They intentionally make it really hard to migrate your data off their app under the premise of "security". Now, they are EOL'ing desktop apps, which are extremely convenient to use, despite the terrible UX. https://support.authy.com/hc/en-us/articles/1260805179070-Ex... The process for exporting is doable, but requires fairly deep technical knowledge and it isn't 100% clean. In order to do so, you need that desktop a…

And they try to lock you in to their own ecosystem. If you use sendgrid, it requires an authy specific 2fa code that can only be generated in their app.

Sendgrid was my go to email provider for clients pre-acquisition.

Once they got bought out & forced their poorly implemented 2fa with mobile phone requirements, I had no choice but to find different providers.

Re: End of Life for Twilio Authy Desktop App

#82
For me, the desktop app always sucked (but it was still more convenient that going to my phone). The TOTP would often get completely out of sync unless I backed out of an app's section and went back in, and then waiting for the TOTP to flip.

Re: End of Life for Twilio Authy Desktop App

#83

Earlier quoted context omitted.

>In what cases would your password vault be compromised, but your TOTP vault still be secure? If the password vault is on one device and the TOTP app on another then it would be harder for an attacker to get into both. I have the same concerns about passkeys. How is it secure if the only thing an attacker needs is a single method of accessing a single device?

Generally the threat model that TOTP protects against is not someone breaking into your device. The threat model that it protects against is someone compromising your other credentials. So, although not recommended, you could post your login credentials on twitter and still nobody would be able to get into your account. An attacker hacking into your laptop/desktop/phone with access to install keyloggers and hijack co…

>Generally the threat model that TOTP protects against is not someone breaking into your device.

And yet, in some realistic scenarios TOTP does protect me against that, if the second factor is on a different device, kind of like a poor man's yubikey.

Re: End of Life for Twilio Authy Desktop App

#84

Earlier quoted context omitted.

>In what cases would your password vault be compromised, but your TOTP vault still be secure? If the password vault is on one device and the TOTP app on another then it would be harder for an attacker to get into both. I have the same concerns about passkeys. How is it secure if the only thing an attacker needs is a single method of accessing a single device?

Generally the threat model that TOTP protects against is not someone breaking into your device. The threat model that it protects against is someone compromising your other credentials. So, although not recommended, you could post your login credentials on twitter and still nobody would be able to get into your account. An attacker hacking into your laptop/desktop/phone with access to install keyloggers and hijack co…

In a corporate setup, it also somewhat protects against intentional policy-violating password sharing between employees.

Re: End of Life for Twilio Authy Desktop App

#85
post #61
post #58

Getting a user to install software on a desktop is probably one of the hardest things for a company to ask for in 2024. It's wild that you would have built up a userbase of ... tens of thousands? ... of technically knowledgeable people who want your product, get them to install and rely on your product on their actual 2024 desktop computer where they do actual work, then have some decision makers determine "ok time t…

I agree, seems short-sighted - they could have even just started charging a bit for it to keep it alive if necessary. No surprise though, after a fantastic start, twilio has turned into a sh*t company, unfortunately - I was a very early adaptor of many of their tools and services, and 1 by 1, they have all gone downhill. They should have sold the company while it still had a decent reputation, at this rate there will…

I would have been happy to pay something to have Authy on desktop and mobile.

I switched to them after my phone died and I saw how hard accessing my accounts was without a backup OTP device.

Re: End of Life for Twilio Authy Desktop App

#86
post #38

Earlier quoted context omitted.

I use Authy. I've read a few comments about how migrating away is difficult. What do you use instead? I also use bitwarden, but not sure how I feel about passwords and totp being in the same app.

> I also use bitwarden, but not sure how I feel about passwords and totp being in the same app. I guess this depends on your threat model. In what cases would your password vault be compromised, but your TOTP vault still be secure? If someone gets access to your unlocked PC/phone, don't they then have access to both? Do you store your TOTP vault password in your password vault (obvious)? If someone gets into your pas…

> I guess this depends on your threat model. In what cases would your password vault be compromised, but your TOTP vault still be secure?

If Bitwarden is compromised, like LastPass was. Of course the vault should still be encrypted, but I don't want to rely on a single company managing everything correctly. It seems much less likely that two different companies will be compromised at the same time.

Re: End of Life for Twilio Authy Desktop App

#87
post #21
post #2

They intentionally make it really hard to migrate your data off their app under the premise of "security". Now, they are EOL'ing desktop apps, which are extremely convenient to use, despite the terrible UX. https://support.authy.com/hc/en-us/articles/1260805179070-Ex... The process for exporting is doable, but requires fairly deep technical knowledge and it isn't 100% clean. In order to do so, you need that desktop a…

What should I replace it with? Any recommendations for a functionally equivalent cross-device 2FA app?

Aegis 2FA

Re: End of Life for Twilio Authy Desktop App

#88

What is so hard to maintain an already finished Electron app?

I can imagine a scenario where it needs dependency updates, engineers bring this up, bean counters say “well this doesn’t make us money, spend time on things that make us money instead” until eventually the bean counters say “okay we are no longer doing this, shut it down”

Re: End of Life for Twilio Authy Desktop App

#90

Can anyone recommend an alternative with similar ux? I use it almost every day, it's very convenient for me! I don't always have my phone around, and also have used it more than once to prevent being locked out of a service

I use a browser extension from https://authenticator.cc/

While I do not know whether its UX is similar, it does have a sync feature (but not cross-browser), an export feature, can backup its data to Google Drive, can store everything encrypted (but not by default), is recommended by at least one government website (SSS Employer Portal in the Philippines), and is there for a long time. Oh, and it also remembers which site each secret comes from, and hides others.

The downside is no automatic synchronization with the mobile phone.

Post reply on HN