Live data from Hacker News

Google Authenticator cloud sync: Google can see the secrets, even while stored

defcon.social

121–130 of 149 posts

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#121
Why don’t people use their own TOTP provider, like KeepassXC/Strongbox, storing the DB in an encrypted manner on a cloud of their choice.

Then use across multiple devices.

It took time for this to sync in, so maybe that’s why so many others do not see that there is really no need to have a third party involved in this pattern?

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#122

Earlier quoted context omitted.

Progress, not perfection. Sms should never be used or offered, and needs congressional action to be stopped as a practice. TOTP at least prevents turning Wireless carriers into security providers and is "good enough" for nearly everything. And yes, WebAuthn/U2F is top of totem pole and should be something we're striving for nearly everything.

> Sms should never be used or offered It's better than nothing.

No, it's WORSE than nothing. You're turning a 3rd party [wireless provider] into a security service that can authenticate you without your knowledge.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#123
post #100

Earlier quoted context omitted.

They always knew your TOTP secrets. The algorithm requires both parties to know the plaintext secret as it’s an input to the HMAC. It’s not a public key operation and they can’t store it as a hashed representation. It’s possible to have 2FA methods that are verify only (usually using public keys and signing), but TOTP is not one of them.

The website you log into with TOTP has always known the TOTP secret. Now, Google also knows your TOTP secret.

Ah! I misunderstood this being applied to non-Google accounts. Yes that’s scary.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#124

Someone will, of course, claim Google would never do this, but this presumably would make it trivial for Google itself to log into all of your accounts. In many cases they are already syncing a copy of your passwords.

Chrome passwords are encrypted with your password (just not e2ee) so it'd have to be a targeted attack where they log your password the next time you log in and then use that to decrypt your chrome passwords. Chrome also allows you to set your own sync passphrase different from your Google account password.

Google says it's encrypted "with your Google account", not with your password. I don't know what the former means, but they do not say they're using your password to encrypt it.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#125
post #5

> if someone obtains access to your Google Account, all of your 2FA secrets would be compromised. This overlooks that fact Google itself also has access to your 2FA secrets, which could be even worse considering Google could be requested to peer not just into the user's google account, but into accounts they have with other companies/organisations too.

I think this is a little far fetched as a scenario.

Under which assumptions should Google be forced to "peer into accounts a user has with other services"?

This is not only not enforceable, it would be illegal.

Companies can not be enlisted to do such things governmental agencies are doing. How should a company decide what to look for? Google is not the police and can not be made an investigator just-for-fun. FBI's search engine?!

Also, you need the first factor. Do you expect Google would also send the "password reset"-request, reset the password, use your 2nd factor... Just to be nice to the authorities?

Wild theory if you ask me...

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#126
post #125
post #5

> if someone obtains access to your Google Account, all of your 2FA secrets would be compromised. This overlooks that fact Google itself also has access to your 2FA secrets, which could be even worse considering Google could be requested to peer not just into the user's google account, but into accounts they have with other companies/organisations too.

I think this is a little far fetched as a scenario. Under which assumptions should Google be forced to "peer into accounts a user has with other services"? This is not only not enforceable, it would be illegal . Companies can not be enlisted to do such things governmental agencies are doing. How should a company decide what to look for? Google is not the police and can not be made an investigator just-for-fun. FBI's…

Legality doesn't matter when the authorities pull out the magic National Security Letter, slap you with a gag order, and fine you an amount doubling from $50,000 per day until you comply.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#127
post #46

Is there anyone who operates an authentication service which: - Has a contractual obligation to keep your data secure. - Accepts financial responsibility for data compromise. - Carries insurance and bonding to back that responsibility. - Does not require binding arbitration or forbid class actions. - Has their employees bonded in the way bank employees are bonded. Well?

Outside of the price issue, this service would also be a prime target go get compromised: I'd assume it would get the juiciest users, and national agencies would have the strongest incentives to backdoor it for later use. We'd need a bunch of services to get to that level first to see any meaningful choice IMHO. I have no idea how that would happen.

It would make sense as a service offered by banks. They already have to verify ID. They're usually required to take financial responsibility for their errors, too.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#128
post #96

Earlier quoted context omitted.

> If you are talking about device backup, apple had it encrypted before Advanced data protection. Not end to end: https://www.wired.com/story/apple-end-to-end-encryption-iclo...

Parent talks about device backup. Your link talks about iCloud backup. Different things

Devices are backed up to iCloud. Same thing.

https://support.apple.com/guide/iphone/back-up-iphone-iph3ec...

https://support.apple.com/guide/icloud/view-and-manage-backu...

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#129
post #98

After my phone was stolen last month, I switched to https://2fas.com and couldn't be any happier. It's free, open source and has tons of great features.

How does this unknown Delaware company support 12 employees working on a free mobile app? There's zero verifiable information available about its history, and the founder seems to be heavily involved in cryptocurrency.

My guess is they're all contractors and work as needed

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#130
post #125

Earlier quoted context omitted.

I think this is a little far fetched as a scenario. Under which assumptions should Google be forced to "peer into accounts a user has with other services"? This is not only not enforceable, it would be illegal . Companies can not be enlisted to do such things governmental agencies are doing. How should a company decide what to look for? Google is not the police and can not be made an investigator just-for-fun. FBI's…

Legality doesn't matter when the authorities pull out the magic National Security Letter, slap you with a gag order, and fine you an amount doubling from $50,000 per day until you comply.

Wow.

Fine for what?

Gag order? Does not help them.

Legality? That would count, if it was something I could order them to do, but again, what do you think would happen there?

"Dear Google, we know you have user TechBro8615@gmail.com, could you please:

- Go through all your data, and gather which Accounts for which services TechBro8615 has

- Go through all these accounts TechBro8615 has with every possible service and reset all his passwords with these accounts (without him noticing)

- And use the second factor TechBro8615 has to login

- Make a user data takeout for all the data TechBro8615 has with all these services

- Create an index of this data, because, well we ask you to, although we can't make you do that

- Tell us if TechBro8615 likes Cranberry juice???

Legality does matter, if you request something from third parties. Why on earth should Google ever cooperate beyond step 1? Would you do that?!

Post reply on HN