Live data from Hacker News

Downsides of Google Authenticator

zdnet.com

101–110 of 139 posts

Re: Downsides of Google Authenticator

#101
post #71
post #9

Earlier quoted context omitted.

As long as you use encrypted backups with iPhone, your GA keys are backed up and you can restore a new phone with them also.

Last time I did a backup/restore between iphones using encrypted itunes usb, GA came up empty. Had to go through painful account recovery / lost 2fa procedures on a dozen accounts. Now I use "OTPAuth" instead. Even comes with an Apple Watch app!

I second every part of this comment. I ran into the same issue migrating GA to a new phone, none of my keys went with. Very frustrating experience.

I also switched to OTPAuth, great app, provides encrypted backups and switching to a new phone was seamless. Would absolutely recommend over Google Authenticator.

Re: Downsides of Google Authenticator

#102
post #77

Earlier quoted context omitted.

As a LastPass user, my main defense against the possibility of someone accessing my LastPass account is the fact that all of my important accounts have 2FA completely separate from LastPass. So if someone got a hold of my LastPass master password, they can't access my google account, banking, etc.

I'm curious about LastPass - it's what I use and work in politics.. Their security page says encrypted on device [1] before sending to them? is that not trustworthy or I'm not understanding? or maybe worried about compromised devices (where it's over anyways)? 1: https://www.lastpass.com/enterprise/security

I'd recommend 1password over LastPass. LastPass has had some real facepalm security issues, and 1Password has a reputation for passing some pretty strenuous audits. We used LastPass on the tech team at HFA and... I think everyone I know has switched to 1Password or something else. I do 1Password and Yubikeys.

Re: Downsides of Google Authenticator

#103

For those who have not seen the previous HN threads this past year on 2FA, Aegis has emerged on Android which a number of folks (myself included) have migrated to using: https://github.com/beemdevelopment/Aegis (links to G-Play/F-Droid in readme) A backup (encrypted or plain) of your seeds can be exported/imported.

This is amazing! Thank you very much, I will set it up along Google Auth in my phone and add it to my home "backup phone".

One thing that had bothered of Google Auth for a long time is the fear of losing my phone and having to go hunting down all the authentication information. And never considered Authy because using an "online service" for these kind of things just seems wrong to me.

Re: Downsides of Google Authenticator

#104
post #86

Earlier quoted context omitted.

MFA is a power tool for extra security. It deliberately sacrifices usability and integrity for security. If you want something more usable, you don't want MFA. Really though, I think "one-time passcodes" is the wrong escape hatch because it is actually just password auth, not a second factor. The way it ought to be is that you hook up multiple devices. (e.g. like having both a phone Authenticator app and a USB key.)

Or, I keep using single factor because services MFA implementation sucks tremendously, and as per service agreements service is liable in any security compromise case. Frankly, most of MFA is security masturbation, is nowhere near to being a real solution, not even a real problem. Its just neat from a technical standpoint (if done well, which nearly never happens). A minimum of 2 registered u2f keyfobs, that's all yo…

MFA is always better than single factor. At the very least it makes drive by/automated attacks significantly harder. Everything you read about SIM jacking and the like is at bare minimum, much harder than hacking your password.

Re: Downsides of Google Authenticator

#105

Use an alternative like andOTP or Authenticator Plus which allow you to backup your keys.

+1 to andOTP. It's on F-Droid and still gets semi-regular updates. It's a bit obnoxious that it requires a password, but that just means an autofill from my password manager for free at-rest encrypted storage.

Are you not using 2FA for your password manager?

Re: Downsides of Google Authenticator

#106
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

> - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface.

And it's easy enough to synchronize multiple devices to the same qrcode when setting up 2FA so that you can generate codes from a backup device if one goes missing.

Re: Downsides of Google Authenticator

#107
post #89
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS). Without backups, having a phone die or get lost is a very frustrating experie…

I've been using the OTP Auth[1] app on iOS as it has support for encrypted backups with a passphrase. It also offers iCloud backup but I have that disabled as I'd rather manage the backups myself. No affiliation, just a happy user.

[1]: https://apps.apple.com/us/app/otp-auth/id659877384

Re: Downsides of Google Authenticator

#108

Earlier quoted context omitted.

Your biometrics cannot be changed nor revoked; they are neither a login nor a password.

They are a weak mechanism against individual targeted attacks, but a great mechanism for herd immunity. It's not perfect, for sure, but it helps raise the posture for the general user in a way that's easy and accessible. That's a win, imo.

> They are a [...] great mechanism for herd immunity. I don't see how, could you elaborate what you mean?

Imagine a leak from a database storing biometric keys, is this a disaster on par with a normal leak? In my opinion it's even worse!

You might say we only use biometrics for a local authentication, but that would limit their application. If you convince people biometrics are great, such database will inevitably be created - what are the chances we store and guard biometrics better than we do with passwords?

Re: Downsides of Google Authenticator

#109
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

Security is a set of compromises.

Re: Downsides of Google Authenticator

#110
post #4

Strongly disagree with the premise of this article: - Passcode or biometric locks on an app are a gimmick and offer negligible value. - The keys not being backed up or or synchronised across devices is not a bug, but a feature. You're supposed to keep offline backup keys. Any sort of synchronization feature adds a ton of attack surface. - In particular, Authy, LastPass and 1password have a giant attack surface compar…

>> In particular, Authy, LastPass and 1password have a giant attack surface compared to a simple app like Google Authenticator.

Source? I've seen some vulnerabilities over time, but the "giant attack surface"?

Post reply on HN