A while ago the Android version was replaced by a new app (instead of just an upgrade), allegedly because the team LOST THE SIGNING KEY FOR THE ORIGINAL APP [1]. If there is one team you'd expect not to lose a signing key I would have thought it would be that one! Everyone makes mistakes, but it's pretty scary to hear this happening too. [1] http://www.androidpolice.com/2012/03/22/psa-googles-authenti...
Warning: Google Authenticator upgrade loses all accounts
141–150 of 176 posts
Re: Warning: Google Authenticator upgrade loses all accounts
#142Re: Warning: Google Authenticator upgrade loses all accounts
#143When I add sites to Authenticator, I take a screenshot of the QR code and tuck it away in an encrypted document (OneNote for the record, which uses uses AES to encrypt).
Re: Warning: Google Authenticator upgrade loses all accounts
#144Re: Warning: Google Authenticator upgrade loses all accounts
#145Earlier quoted context omitted.
Which can be turned off
Which 99% of iOS users won't do even if they are aware of it.
Re: Warning: Google Authenticator upgrade loses all accounts
#146I keep backup codes for each of my 2FA services in a Truecrypt container, which is mirrored on Dropbox. Additionally, I keep a copy printed out and kept in a fire safe. Phone backups for personal accounts have my wife's phone on record, and I try to keep printed copies of the QR codes I used to set up the account.
About a year ago, my phone was shattered while on the road, and while I was able to regain access to those accounts due to existing login sessions on my home computer, I'd have been sunk without them. Make sure you have a plan for what you do if your phone authenticator becomes unavailable.
Re: Warning: Google Authenticator upgrade loses all accounts
#147Too late for me, but a pleasingly fast and pro-active response from AWS (which rather shows Google up) just received by email: "If you are an AWS customer who uses Google Authenticator for iOS as a multi-factor authentication device to secure your AWS account via AWS MFA ( http://aws.amazon.com/mfa/ ), please read on. We are writing to inform you that Google has recently released an update to the Google Authenticator…
And no word yet from Google... Their lack of customer service is going to end up killing them in a number of markets. I would never use Google for any critical business function (email, payments, cloud computing).
Re: Warning: Google Authenticator upgrade loses all accounts
#148Earlier quoted context omitted.
What's even worse is with a certain iOS update that may or may not be launching in the next few weeks will make this advice impossible. 3 words for you - Auto updating apps
Which can be turned off
Open market "want to always auto update apps?". No.
Update an app after reading the change log. "want to always auto update apps?". No.
Update the next app... You get the idea.
Also, what's the fallacy about giving you a change log for each version of apps, but not allowing to install other versions? This is the sole reason people will give up those stores. Will not even be the abusive control and price for no added safety.
Re: Warning: Google Authenticator upgrade loses all accounts
#149For those looking for Google Authenticator alternatives, I recommend either Duo Mobile from Duo Security or Authy. I ditched Google Authenticator a while ago and haven't missed it one bit -- having a single app manage my two-factor tokens / keys is much more convenient.
Re: Warning: Google Authenticator upgrade loses all accounts
#150Earlier quoted context omitted.
I'm sorry, I don't follow your logic. Are you trying to say you think Google actually had a rationale for this behavior? Where does "the cloud" come into the equation? This data isn't being synced to iCloud. That defeats the whole purpose.
Because Google fundamentally wants everyone to use Google+ for everything, and their Google Accounts to sign into it. If they weren't thinking about the security implications, Google Authenticator would definitely be a "sync your credentials to your Google Account" app. I assume that the implementation of 2FA was a 20%-time project (it's sort of sloppily integrated; you need to find a special page that isn't linked f…
It's linked from https://security.google.com/settings/security which is itself linked from https://www.google.com/settings/account ...