Live data from Hacker News

Authy corrupted my 2FA backup and all I got was this lousy blogpost

cmb.weblog.lol

21–28 of 28 posts

Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost

#21
post #19
post #17

Earlier quoted context omitted.

Typically the way these codes are compromised is when they are stored in a non-HSM location like Google drive or transferred somehow. Then again, if you are just trying to keep people out of your Facebook account it's not a big deal. But if you are trying to keep people from financial accounts I wouldn't recommend transferring TOTP keys. Instead using a backup method like a printed out one time use sheet would be bet…

It sucks Yubikey (or other hardware based auth) isn't more prevalent in the financial/banking world. It helps mitigate a lot of types of attacks: - No tokens to exfiltrate off a computer - Avoids keylogger style attacks - More durable than cell phones That said, for people that have high amounts of money in certain accounts (> 1m), it might also present physical dangers (e.g. kidnapping, home invasion) for thieves at…

The rubber hose attack is always the most reliable and most dangerous method of breaching high value targets like this.

https://xkcd.com/538/

Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost

#22
If not for a backup on the very old, insecure phone, Authy would cut me off from my codes.

They refuse to start the app on GrapheneOS literally because they cannot be arsed, offloading the claim of security of the handset to Google (which says an old handset not patched in the last 8 years is secure, but the most recent, best patched OS is not).

When the shit hit the fan Authy even removed the way to export the seeds from the desktop version of the app. Big FU to customers.

Never again.

Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost

#24

tl;dr > Much to my surprise, when checking the App Store page, I saw that an update to the app had been approved by Apple only 14 minutes prior. I downloaded the update, tapped upon one of the previously "locked" items, and entered my backup password. Boom, the previously locked 2FA codes were now unlocked and restored, ready for use.

I think you missed that part where they subsequently tried to gaslight the user again and told him to do the thing he explained in the ticket he can't.

Or what is the purpose of your comment? :)

Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost

#25

Earlier quoted context omitted.

"Security reasons" is pretty insane, considering how easy it is to lose access to a good number of accounts if any 2FA app breaks from a bad update. Google Authenticator has done this before too, way back in 2013: https://news.ycombinator.com/item?id=6325760

It is indeed the very epitome of sanity, if you simply consider that the codes are secrets , and this entire practice is derived from having hardware dongles with secure enclaves, where secrets go in but never come out. It is the utmost in security when this one-way relationship is observed. The ability to export secrets is an unfortunate compromise which vendors make for consumer markets. The MFA apps were not desig…

> The reason that you don't lose access to accounts when losing your MFA apps is that you took down the emergency backup codes and you committed them to paper, or some other durable medium, in a place where they can easily be accessed during a crisis. You did this scrupulously with each MFA activation, didn't you? Didn't you?

Not all TOTP implementations, especially indie PHP websites, are robust enough to have implemented backup codes.

Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost

#26

Earlier quoted context omitted.

It is indeed the very epitome of sanity, if you simply consider that the codes are secrets , and this entire practice is derived from having hardware dongles with secure enclaves, where secrets go in but never come out. It is the utmost in security when this one-way relationship is observed. The ability to export secrets is an unfortunate compromise which vendors make for consumer markets. The MFA apps were not desig…

> The reason that you don't lose access to accounts when losing your MFA apps is that you took down the emergency backup codes and you committed them to paper, or some other durable medium, in a place where they can easily be accessed during a crisis. You did this scrupulously with each MFA activation, didn't you? Didn't you? Not all TOTP implementations, especially indie PHP websites, are robust enough to have imple…

Well, that's pretty sad, but surely, in every case, there is some procedure that's delineated for account recovery when something goes wrong?

I have been dismayed at some supposedly professional implementations, such as when I telephoned Wal-Mart to ask what can be done if I lost my phone (SMS is their only 2FA) and they said that they were prohibited from changing anything in account settings or profiles, and the best idea was to create a new account. (That is crazy -- if you shop at a marketplace like that, they've stored all your receipts, your membership, a potentially years-long trail of paperwork that you may need for taxes, or reimbursement, or refunds later on!)

Even worse, I had a bad time with the United States Postal Service. If I recall correctly, I'd lost access to the registered email address, and I was requesting to change it to something within my control, and they said "no can do", and they told me that my only recourse would be to create a new account, so that's what I did. Interestingly, USPS offers 2FA via either email or SMS, and their SMS gateway service is frequently out of order, so I always use email when logging in there.

Once, around 2021, I contacted GitLab to inform them that their account recovery process was a backdoor to circumvent MFA. They denied any such problem. I suggest that any account recovery implementation be just as secure as the front door to sign in, but also not impossible, because why do you want loyal customers to lose their accounts completely?

Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost

#27
I switched to Ente Auth back when Twilio screwed ppl over by eliminating the desktop application. Literally everything about Ente Auth has a better experience than Authy ever was, even before the incident.

Highly recommended by a highly satisfied user.

Re: Authy corrupted my 2FA backup and all I got was this lousy blogpost

#28
Tarsnap should partner with Apple and Google to offer a per-app minimal important data backup API/service to offer revisioned backups (not just replication) of critical data. This is something Tarsnap could offer app developers as an SDK at first, but then gather momentum to be integrated into mobile/dekstop OSes.
Post reply on HN