Can the title get changed? - E2E in this case is nebulous, this isn't a chat or email client, it isn't client client with Google acting as an intermediary. It is between your Google account/Google's Server and Google's software. - It isn't clear if during transportation it is encrypted (e.g. HTTPS?); since seemingly this post isn't about that (or if it is the evidence or technical information is lacking). The term "E…
> The actual complaint SEEMS to be: Google Authenticator backup isn't encrypted at rest on Google's Servers Encryption at rest would NOT solve the problem being described here. Even if the data was encrypted both in transit and at rest, that does not mean that Google is incapable of getting access to the data. The data needs to be encrypted from the moment it leaves the device until the moment it arrives back on the…
Google Authenticator cloud sync: Google can see the secrets, even while stored
61–70 of 149 posts
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#62After my phone was stolen last month, I switched to https://2fas.com and couldn't be any happier. It's free, open source and has tons of great features.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#63Earlier quoted context omitted.
> The actual complaint SEEMS to be: Google Authenticator backup isn't encrypted at rest on Google's Servers Encryption at rest would NOT solve the problem being described here. Even if the data was encrypted both in transit and at rest, that does not mean that Google is incapable of getting access to the data. The data needs to be encrypted from the moment it leaves the device until the moment it arrives back on the…
The "not encrypted at rest" part seems to be pure speculation: "As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers." Is there some actual evidence for this claim that I'm not noticing?
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#64It's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One pa…
Not to mention Google can be hacked.
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#65Earlier quoted context omitted.
Under what conditions do you suggest "Google itself also has access to all your 2FA secrets"? (Without cloud backup, & without the installation of a malicious version of 'Google Authenticator', how would they – especially, say, on iOS?)
I think they are referring to the scenario where cloud backup is enabled.
(And if Google were denied access to the cleartext 2FA secrete this, way, then briefly compromising someone's Google account – say by hacking or abuse of legal process – wouldn't automatically compromise all other 2FA-key-protected accounts.)
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#66After my phone was stolen last month, I switched to https://2fas.com and couldn't be any happier. It's free, open source and has tons of great features.
Looks good at a first glimpse. Please don't write "it's free". That's a non-message many companies give, Google of course one of them. We know that it means you pay by providing your data. Other models could be "run by volunteers" or "fully funded by donations".
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#67Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#68Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#69Earlier quoted context omitted.
Why would google have access to that material? Is their general secret mechanism not E2EE? I'm fairly cynical on google's approach to privacy but I would be shocked if they're normal syncing isn't actually secure and private.
Chrome passwords are encrypted with your Google password by default, it's just not e2ee. This isn't even encrypted in that way it seems. The only real "threat" is your Google account itself being compromised by a third party able to phish their way into your account or bypass your 2fa mechanisms (e.g. by SMS sim swapping). As always, https://landing.google.com/advancedprotection/ The people here saying "privacy" are…
Re: Google Authenticator cloud sync: Google can see the secrets, even while stored
#70Is there anyone who operates an authentication service which: - Has a contractual obligation to keep your data secure. - Accepts financial responsibility for data compromise. - Carries insurance and bonding to back that responsibility. - Does not require binding arbitration or forbid class actions. - Has their employees bonded in the way bank employees are bonded. Well?