Has anyone here used both Authy and Duo Mobile and would like to recommend one over the other?
More importantly, the company is run by well know and respected security researchers (Dug Song and Jon Oberheide).
61–70 of 99 posts
Has anyone here used both Authy and Duo Mobile and would like to recommend one over the other?
More importantly, the company is run by well know and respected security researchers (Dug Song and Jon Oberheide).
Hi, I'm Daniel, Authy Founder. We've worked almost 18 months on this product, it's surreal to finally see it out. Anyway, you can read more about why we did this here: http://blog.authy.com/thefuture
From what I can tell, the user navigates to a site previously provisioned with Authy, they choose to authenticate via Authy, and then ??? happens resulting in their cell phone giving them a time-limited one-time passphrase.
Earlier quoted context omitted.
Cellphone numbers can very easily be abused to steal money (premium SMS), to steal my identity, to spam me in the middle of the night, to pull me out of the "zone" by calling me/messaging me during work hours, to track my location while roaming and probably a lot more stuff that's not currently apparent to me. Also, my phone number is known to some identity providers I trust. If they sent me an SMS asking me to click…
It is ridiculous to think that your number is private and even moreso to think that someone can steal money with just your cellphone number. Of course you could be phished or tricked by SMS but to expect your number to be private is to expect everyone ever who you give the number to go to extreme to keep it private as well. If you ever gave your number to someone who downloaded an app which has permission to contacts…
This monkey patched TFA solution is not "the future" of logins, by a long shot. Not even in the short term. Things like Persona are going to beat Authy before Authy ever sees a non-negligible amount of revenue.
At least Coinbase doesn't FORCE me to use them anymore.
--
Also, since I forgot.
IF YOU SYNC MFA KEYS, YOU'RE ONLY COMPLETELY DEFEATING THE POINT.
Why doesn't this work with iPhone 4 or below? Edit: According to this document iPhone 4 support all Bluetooth profiles: http://support.apple.com/kb/ht3647
Assuming an attacker has complete control over your computer, and your phone is within bluetooth range, can he make the phone generate a token without user interaction? I was assuming the user would have to click a button on the phone or something, but I couldn't see it in the video.
... the end user just lost, absent substantially more defense-in-depth on the provider side than just using TFA. TFA mostly helps you against "We lost credentials or a low-privilege session, let's prevent that from escalating to a high-privilege session." If your device is rooted, you'll eventually cough up a high-privilege session, either by passive monitoring or by something more clever like e.g. using your own computer as the MITM to ask you to provide a valid TFA to do something which really only requires a low-privilege session. Now the attacker has both factors. Game set match.
Has anyone here used both Authy and Duo Mobile and would like to recommend one over the other?
The Android app is over 9MB and can't be moved to the SD card. Too large for me, uninstalled.