Live data from Hacker News

End of Life for Twilio Authy Desktop App

help.twilio.com

171–180 of 180 posts

Re: End of Life for Twilio Authy Desktop App

#171

Earlier quoted context omitted.

Not if I'm on your device and hijacking your already-authenticated connection. I just need to be careful enough to do it in the background in such a way that you don't notice.

If my device got stolen I would remove the device from my accounts immediately. And without the second factor you wouldn't be able to do anything about it.

The threat is that your device is infiltrated right now.

Re: End of Life for Twilio Authy Desktop App

#172

I regret immensely that I ever endorsed or recommended Authy. My experience witnessing the regression and functional decline of this app over the years has utterly wrecked my opinion of Twilio. Although I still have a couple of operational Twilio integrations, I no longer have any desire to use any of their products or services ever again.

2FAS Auth is fully exportable and you can even modify any of your token settings natively in the app.

They don't have a desktop app.

Re: End of Life for Twilio Authy Desktop App

#173

I’m not sure why people who mainly used TOTP and mobile are saying they are going to migrate to something else. I also used the Desktop application, but I could have used my phone in those cases 99% of the time, and if you’re using the Backup feature, you should still be able to recover your account in case you lose your phone, no? Or am I missing something? I migrated from Google Authenticator before it offered back…

As has been mentioned, not all of us want to have our whole infrastructure relying on a single device (mobile). The desktop app was both convenient but also a backup plan for me.

The seemingly unnecessary depreciation of a tool we all use gives of dangerous vibes for the future.

It is not that I think that the Authy mobile app is going away, but rather that the design and features of it will slowly become worse over time. History backs me up on this.

And honestly, for something as fundamental as 2FA we should be using self hosted and open source tools without any corporate ties anyways.

This was just the push I needed to make that happen (Aegis).

Re: End of Life for Twilio Authy Desktop App

#174

Earlier quoted context omitted.

Password Store works fine for me: https://www.passwordstore.org/ https://github.com/tadfisher/pass-otp Others have also said Bitwarden isn't too bad: https://bitwarden.com/

I see other replies also recommending password managers Why would I store my second authentication factor alongside the first? Aren't we effectively now back to 1FA?

I'd say password managers are a (slightly weaker) form of 2FA by design: it's something you have (a device with your password database installed) plus something you know (if using a master password) or something you are (if using biometrics).

Adding TOTP on top of that helps guard a bit more against some kinds of attacks. You can make it even stronger by not storing those keys in the same place and only using your phone, for example, but for some people (myself included) it's one bit too inconvenient. The good thing about using TOTP for 2FA is that you can find your own balance between convenience and security.

Re: End of Life for Twilio Authy Desktop App

#176
post #117

Earlier quoted context omitted.

Two ways: - a Yubikey - a sparingly used email account with no 2FA, just a very long password 2FA through the sort-of-secret email account lets me get back into Bitwarden (and thus everything else) even if my house burns down and I lose access to all of my yubikeys. And auth on a device that doesn't easily support yubikeys, like older iPhones. 2FA is very useful, but highly overrated. If you have a sufficiently long…

> 2FA is very useful, but highly overrated. What a bizarre statement. It protects you from any password leak. If you have 2FA, even if you get keylogged or phished or breached or shoulder peeked, your intruder still does not gain access.

Sorry, but my Article and Walmart.com accounts do not need 2FA. I'm fine with OTP, but most places use SMS 2FA, which exposes a unique identifier for myself and -- due to SIM swapping, which is a risk on literally every major carrier due to horrible customer service operations -- often makes it easier for a malicious actor to hijack my account.

You're generally correct, though: GOOD 2FA is not overrated and I would welcome it on any account. But it's obnoxious that almost every account I have uses SMS as a singular point of failure. I'd welcome a move back to email 2FA with a backup email for account recovery.

Re: End of Life for Twilio Authy Desktop App

#177
post #92
post #60

Earlier quoted context omitted.

You're gonna get pwned, and you're gonna get pwned hard. Brace for it because it's coming sooner or later. It's convenient until you lose all of your passwords.

> Brace for it because it's coming sooner or later. I wonder if it will be his passwords, or one of the providers of those impenetrable password replacement keys will be breached first, in a way that leaks everything.

Unsure though the OP’s laptop being stolen or a rogue program stealing their passwords.txt is a lot more likely. The providers being attacked will still require the keys themselves to be attacked since they hold the secrets.

Re: End of Life for Twilio Authy Desktop App

#178
post #60

Earlier quoted context omitted.

You're gonna get pwned, and you're gonna get pwned hard. Brace for it because it's coming sooner or later. It's convenient until you lose all of your passwords.

I can count the passwords truly critical to my livelihood on one hand (and those are unique). I couldn't care less about everything else (and they all more or less share the same or similar passwords), pwn away.

That’s the same for me. That being said, I don’t current me enough to make good security decisions for future me based on current knowledge, so I do what I can now instead. The overhead is extremely minimal if you use a password manager.

Re: End of Life for Twilio Authy Desktop App

#179
post #60

Earlier quoted context omitted.

You're gonna get pwned, and you're gonna get pwned hard. Brace for it because it's coming sooner or later. It's convenient until you lose all of your passwords.

The point still needs to be made. I always present security as a sliding scale with secure on one side and convenient on the other. Similar to low-cost and convenient streaming services reducing piracy, and then seeing the return of piracy as they become higher cost and less-convenient, any application needs to consider not only how to protect its users and their data, but also how to not drive away users with securi…

2FA definitely will protect you even if your passwords.txt is stolen, probably. I can’t imagine that trying to manage syncing and easy access to the passwords.txt is even remotely as secure or easy as something like 1Password.

Services, IMO, have a duty to do their utmost in protecting customer security and privacy. Fortunately Passkeys are becoming more common and I’m hoping more folks will choose them since they’re way better than plain passwords.

The problem with choosing convenience now is that you don’t know what the future holds, and a good chunk of security is stuff that people don’t know becoming known, sometimes very publicly so.

Eg a new 0day in Firefox is found, exploited, and the passwords.txt is gone before the user patches it (admittedly likely since I am unsure if the OP is up for the inconvenience of frequent browser or critical software updates).

If you’ve ever had anything important of yours being hacked you’ll probably understand how shitty it is and how it’s worth the inconvenience. Modern password managers are very convenient though. I love not knowing a single one of my service passwords. Plus, my laptop being stolen is probably gonna still protect my passwords since 1Password does protect them at rest, pending brute-forcing the (very long) master password. None of this is true or exists for a plaintext file.

Even then, say OP doesn’t care about getting hacked and someone gets into their email. Now, the hacker has their email and contact lists. They can use that info to target OP’s contacts with more-viable phishing or other attacks.

Post reply on HN