Live data from Hacker News

Google Authenticator cloud sync: Google can see the secrets, even while stored

defcon.social

141–149 of 149 posts

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#141
post #91

Earlier quoted context omitted.

How exactly?

I guess the person meant this: encrypt-than-upload of backups with backup passkey managed by yourself, details e.g. in this blogpost: https://authy.com/blog/how-the-authy-two-factor-backups-work...

Yes. What I meant was that Authy does encrypted backups. You can criticize how it's implemented, but it's there, it works, and your 2FA secrets aren't just sitting in the cloud.

I think I'll refrain from posting on topics about Google — clearly there is a huge pro-Google sentiment among HN readers and anything detracting from that gets instantly downvoted.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#142
post #71

Earlier quoted context omitted.

>Chrome passwords are encrypted with your Google password by default, it's just not e2ee. Source?

Chrome settings -> sync -> encryption

I believe that's off by default (even when you turn on sync), and I believe that if you do turn it on, it's not using your Google password, but a separate password of your choosing.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#144
post #68

Authy gets this right. Not sure why anyone would trust Google with their 2FA secrets.

Authy has custom derivation time and makes it very difficult to export keys for use elsewhere.

I will only use 2fa applications that do standard 30 second TOTP. Bonus points if it can set custom times and hash algos. A good application like this is Aegis Authenticator for mobile.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#145
post #113

Earlier quoted context omitted.

Google pushing malicious updates would leave forensic traces, not to mention it'd be difficult to establish a legal framework allowing a government to force Google to do so. In contrast, subpoena'ing data from the cloud is routine for police in countries all over the world.

So your threat model is a sovereign state able to subpoena cloud data. Under this model, if Google gets a court order to root-break a specific phone (push malicious update), they will be forced to, and that's all the legal framework necessary, so end-to-end encryption doesn't protect you in this case either.

In the US at least, there’s not a lot of precedent for forcing a company to do something like that. (Yet.) Saying hand over your user’s files is demanding information. Compelling them to write and distribute malware is a lot closer to compelling speech. A 1st amendment problem.

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#146

Earlier quoted context omitted.

Progress, not perfection. Sms should never be used or offered, and needs congressional action to be stopped as a practice. TOTP at least prevents turning Wireless carriers into security providers and is "good enough" for nearly everything. And yes, WebAuthn/U2F is top of totem pole and should be something we're striving for nearly everything.

> Sms should never be used or offered It's better than nothing.

Your comment is aging well: https://arstechnica.com/information-technology/2023/05/t-mob...

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#148
post #129
post #98

Earlier quoted context omitted.

How does this unknown Delaware company support 12 employees working on a free mobile app? There's zero verifiable information available about its history, and the founder seems to be heavily involved in cryptocurrency.

My guess is they're all contractors and work as needed

Yup - that! Plus we have donations. We know it's not a perfect way to earn money, but our priority is to deliver the best, most secure and private 2FA app out there!

Re: Google Authenticator cloud sync: Google can see the secrets, even while stored

#149
post #103
post #94

Earlier quoted context omitted.

And Apple

Where does Ape use SMS based 2FA? Do you have a Windows computer maybe?

If you don't log into an Apple OS with your account

Apple specifically says for Apple School Manager they want: a work email address that is not associated with an App Store or iCloud account, and has not been used as an Apple ID for any other Apple service or website

Post reply on HN