Live data from Hacker News

End of Life for Twilio Authy Desktop App

help.twilio.com

121–130 of 180 posts

Re: End of Life for Twilio Authy Desktop App

#121
post #38

Earlier quoted context omitted.

> I also use bitwarden, but not sure how I feel about passwords and totp being in the same app. I guess this depends on your threat model. In what cases would your password vault be compromised, but your TOTP vault still be secure? If someone gets access to your unlocked PC/phone, don't they then have access to both? Do you store your TOTP vault password in your password vault (obvious)? If someone gets into your pas…

> I guess this depends on your threat model. In what cases would your password vault be compromised, but your TOTP vault still be secure? If Bitwarden is compromised, like LastPass was. Of course the vault should still be encrypted, but I don't want to rely on a single company managing everything correctly. It seems much less likely that two different companies will be compromised at the same time.

that's been my attitude, both are keyed to my face id, otherwise encrypted. my phone times out really quickly if i'm not typing away on it. I feel relatively safe. I wonder though how much longer they will maintain the phone apps. All my desktop versions are verified from my phone, so them dropping the desktop sucks but isn't catastrophic.

Re: End of Life for Twilio Authy Desktop App

#122
post #2

They intentionally make it really hard to migrate your data off their app under the premise of "security". Now, they are EOL'ing desktop apps, which are extremely convenient to use, despite the terrible UX. https://support.authy.com/hc/en-us/articles/1260805179070-Ex... The process for exporting is doable, but requires fairly deep technical knowledge and it isn't 100% clean. In order to do so, you need that desktop a…

And they try to lock you in to their own ecosystem. If you use sendgrid, it requires an authy specific 2fa code that can only be generated in their app.

Yes, and, if you create a SendGrid account and therefore an Authy account, this may immediately enroll other accounts of yours on entirely unrelated websites/services/platforms into Authy, presumably by correlating your phone number. (Even if the email address is different!) This includes big sites like Twitch, and also includes sites where you had selected the "only allow 2FA via security keys" option. Of course some of the blame here probably falls on those platforms, but both the fact that this is possible and the fact that Twilio encourages these patterns are reprehensible.

Re: End of Life for Twilio Authy Desktop App

#124

I just got done moving all of my accounts over to Aegis. At the same time, I put the new TOTP key into Proton Pass. Aegis makes it easy to backup your keys and use more than one 2fa app for redundancy.

This is probably my next step as well. It was nice while authy worked though, never had a single issue with it, almost 0 maintenance.

Re: End of Life for Twilio Authy Desktop App

#125
post #99

Earlier quoted context omitted.

Is it really multifactor then, with everything in Bitwarden?

The way I see it, your password manager becomes the central point of failure. Therefore, secure your password manager with a hardware security key (yubi). Not all accounts stored in a password manager are created equal... some need more security than others. If there are accounts that you want additional 2FA security on, just use a separate TOTP app. It doesn't have to be an all or none option.

[deleted]

Re: End of Life for Twilio Authy Desktop App

#126
I’m not sure why people who mainly used TOTP and mobile are saying they are going to migrate to something else. I also used the Desktop application, but I could have used my phone in those cases 99% of the time, and if you’re using the Backup feature, you should still be able to recover your account in case you lose your phone, no? Or am I missing something?

I migrated from Google Authenticator before it offered backups too precisely for the backups/restoration.

Re: End of Life for Twilio Authy Desktop App

#128
post #58

Getting a user to install software on a desktop is probably one of the hardest things for a company to ask for in 2024. It's wild that you would have built up a userbase of ... tens of thousands? ... of technically knowledgeable people who want your product, get them to install and rely on your product on their actual 2024 desktop computer where they do actual work, then have some decision makers determine "ok time t…

> Getting a user to install software on a desktop is probably one of the hardest things for a company to ask for in 2024.

Really? What do people use desktops for then? Why doesn't everyone just use phones and Chromebooks?

There's no point in buying a desktop if you aren't going to run software on it.

Re: End of Life for Twilio Authy Desktop App

#130
post #46

Earlier quoted context omitted.

Important point out of that reddit Bitwarden thread: If you migrate to another app and then delete your authy account, you risk having 2FA removed for some integrated accounts if they're set up to directly use the Authy backend. Twitch in some cases was pointed out.

Twitch refused to return me access to one of my accounts for this exact reason (the account that had subscriptions on it was returned, the one without was not).

I've abandoned a twitch account because of 2FA nonsense. If you set a phone number as your 2FA and then lose access to it you're screwed. They don't care.
Post reply on HN