TOTP (the six digit codes) is bad and outdated 2FA anyway. It's vulnerable to phishing. Use WebAuthn with security keys.
Google Authenticator cloud sync: Google can see the secrets, even while stored
11–20 of 149 posts
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#12TOTP (the six digit codes) is bad and outdated 2FA anyway. It's vulnerable to phishing. Use WebAuthn with security keys.
TOTP is cheap and much better 2FA than OTP over SMS.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#13It's a dual facing problem. Not only do users have no defence against google snooping, but google has no defence against requests to snoop: Apple seems to drive harder to "we'd help if we could, but we can't: to us its just blobs"
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#14It's a dual facing problem. Not only do users have no defence against google snooping, but google has no defence against requests to snoop: Apple seems to drive harder to "we'd help if we could, but we can't: to us its just blobs"
Apple regularly gives up customers' private data when requested, and they keep logs of it themselves[1]. [1] https://www.apple.com/legal/transparency/us.html
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#15> if someone obtains access to your Google Account, all of your 2FA secrets would be compromised. This overlooks that fact Google itself also has access to your 2FA secrets, which could be even worse considering Google could be requested to peer not just into the user's google account, but into accounts they have with other companies/organisations too.
(Without cloud backup, & without the installation of a malicious version of 'Google Authenticator', how would they – especially, say, on iOS?)
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#16TOTP (the six digit codes) is bad and outdated 2FA anyway. It's vulnerable to phishing. Use WebAuthn with security keys.
The problem with security keys is that they're expensive and you have to carry them around. TOTP is cheap and much better 2FA than OTP over SMS.
Obviously, a YubiKey would be better, but Passkeys don't require you to carry an additional thing and are still more secure than TOTP apps.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#17Someone will, of course, claim Google would never do this, but this presumably would make it trivial for Google itself to log into all of your accounts. In many cases they are already syncing a copy of your passwords.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#18> if someone obtains access to your Google Account, all of your 2FA secrets would be compromised. This overlooks that fact Google itself also has access to your 2FA secrets, which could be even worse considering Google could be requested to peer not just into the user's google account, but into accounts they have with other companies/organisations too.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#19Someone will, of course, claim Google would never do this, but this presumably would make it trivial for Google itself to log into all of your accounts. In many cases they are already syncing a copy of your passwords.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#20It's a dual facing problem. Not only do users have no defence against google snooping, but google has no defence against requests to snoop: Apple seems to drive harder to "we'd help if we could, but we can't: to us its just blobs"
Apple regularly gives up customers' private data when requested, and they keep logs of it themselves[1]. [1] https://www.apple.com/legal/transparency/us.html