Live data from Hacker News

End of Life for Twilio Authy Desktop App

help.twilio.com

141–150 of 180 posts

Re: End of Life for Twilio Authy Desktop App

#143
post #22
post #2

They intentionally make it really hard to migrate your data off their app under the premise of "security". Now, they are EOL'ing desktop apps, which are extremely convenient to use, despite the terrible UX. https://support.authy.com/hc/en-us/articles/1260805179070-Ex... The process for exporting is doable, but requires fairly deep technical knowledge and it isn't 100% clean. In order to do so, you need that desktop a…

I had some good luck with https://github.com/token2/authy-migration

I have a rooted Android phone and with a simple su and cp I copied the Authy XML to another folder which you can import into the app Aegis directly (from there you can export further if you don't like Aegis). I'm currently looking at Ente Auth because it's end2end encrypted and also provides a web UI for viewing the codes. Or I use another Keepass file.

Re: End of Life for Twilio Authy Desktop App

#144
post #99
post #8

Earlier quoted context omitted.

> not sure how I feel about passwords and totp being in the same app I felt the same way and I've come to realize that it is not a big deal. One advantage is that with a shared password manager account, you can also share the TOTP along with it. Very convenient for a bunch of usecases.

Is it really multifactor then, with everything in Bitwarden?

The second factor is not meant or designed to safe you against a compromised PC or phone (your session or cookies could be probably more easily stolen even when second factor on another device). Many people have passwords and totp on the same phone too. The second factor is more meant to verify that you are really you to a web site and safeguard your account on that web site.

Re: End of Life for Twilio Authy Desktop App

#145

I’m not sure why people who mainly used TOTP and mobile are saying they are going to migrate to something else. I also used the Desktop application, but I could have used my phone in those cases 99% of the time, and if you’re using the Backup feature, you should still be able to recover your account in case you lose your phone, no? Or am I missing something? I migrated from Google Authenticator before it offered back…

I do not like being dependent on having a working phone to log in to my digital life.

Any break in my phone will take weeks for me to be able to afford to replace, meanwhile what? Im locked out of everything?

Why would I risk that?

Phone battery is dead so I got to wait 5 minutes to log into my forums while it charges enough to allow me to boot it and then boots?

Might as well move purely to yubikey in that case.

The whole point of using authy was the reliability of cloneable auth tokens between my desktop, laptop (desktop os) and phone.

3 piece holy trinity.

and what? you want to move that down to one?

Even if its backed up, what do I do while it is stolen or off for repairs?

The ENTIRE point of using authy over any other solution was that its wide app base made it more reliable.

They adversely selected for the userbase that would get mad over this

Re: End of Life for Twilio Authy Desktop App

#146
post #60
post #45

As someone who just uses good old passwords managed with TXT files and sticky notes: Security engineers (marketers?) never seem to understand most people by far value convenience over security.

You're gonna get pwned, and you're gonna get pwned hard. Brace for it because it's coming sooner or later. It's convenient until you lose all of your passwords.

I can count the passwords truly critical to my livelihood on one hand (and those are unique). I couldn't care less about everything else (and they all more or less share the same or similar passwords), pwn away.

Re: End of Life for Twilio Authy Desktop App

#147
I'm unsure what to switch to as another easy to use desktop cloud based 2factor app that's encrypted

I liked the peace of mind of having it in the cloud so I don't randomly lose all of my accounts if I decide to replace my phone

This is extremely disappointing, I don't trust many other companies and this is a baffling decisio

Re: End of Life for Twilio Authy Desktop App

#149
post #4

Earlier quoted context omitted.

Is sad because that one got posted too early and probably won't reach the top of the feed and fewer people will see it. .. and mods will probably delete this one.

That one was just another discussion a month ago, might have some extra tips for alternatives etc. This one is fine, official, and was first for today.

Naa, the official source was posted 36 days ago: [0], the one you reference was a more popular dupe posted 7 hours later from a lesser source that referenced the original.

[0]: https://news.ycombinator.com/item?id=38916798

Re: End of Life for Twilio Authy Desktop App

#150
post #70

Earlier quoted context omitted.

Of course, if you have an Apple product, you can also use the TOTP function built-in to Keychain. iPhone doc here: https://support.apple.com/guide/iphone/automatically-fill-in...

The downside to this, is that you're tied into Apple's ecosystem. The nice thing about Authy was that I had the same access on Android, iOS, Windows, Mac, and Linux.

Consider 1Password, with the added bonus of the `op` CLI tool and a variety of other dev conveniences.

CLI: https://developer.1password.com/docs/cli/get-started/

Shell plugins: https://developer.1password.com/docs/cli/shell-plugins

Secrets automation: https://developer.1password.com/docs/secrets-automation

Post reply on HN