Live data from Hacker News

End of Life for Twilio Authy Desktop App

help.twilio.com

91–100 of 180 posts

Re: End of Life for Twilio Authy Desktop App

#91
post #70
post #53

This was mentioned below (HT to Eric_WVGG for pointing it out [0]) but I think it warrants a top level comment: If you have an ARM Mac you can install the Authy iPad app and use it just like the Desktop app. If you want to have a desktop backup but aren't ready to migrate yet, this is a fantastic stop-gap solution. [0] https://news.ycombinator.com/item?id=39360950

Of course, if you have an Apple product, you can also use the TOTP function built-in to Keychain. iPhone doc here: https://support.apple.com/guide/iphone/automatically-fill-in...

The downside to this, is that you're tied into Apple's ecosystem. The nice thing about Authy was that I had the same access on Android, iOS, Windows, Mac, and Linux.

Re: End of Life for Twilio Authy Desktop App

#92
post #60
post #45

As someone who just uses good old passwords managed with TXT files and sticky notes: Security engineers (marketers?) never seem to understand most people by far value convenience over security.

You're gonna get pwned, and you're gonna get pwned hard. Brace for it because it's coming sooner or later. It's convenient until you lose all of your passwords.

> Brace for it because it's coming sooner or later.

I wonder if it will be his passwords, or one of the providers of those impenetrable password replacement keys will be breached first, in a way that leaks everything.

Re: End of Life for Twilio Authy Desktop App

#93

This was literally the only reason to use Authy.

I've only ever used it on mobile, so no. For me the reason was sharing TOTP between phones in case my primary gets lost or damaged.

That's fair. I should say, it was my main reason for using Authy as there wasn't anything else out there that could do synced mobile and desktop easily for free.

Re: End of Life for Twilio Authy Desktop App

#94

How do folks use two factor auth for 1password logins? It feels wrong to me to use 1password as the second factor for 1password itself. My last remaining authy second factors are for primary email and 1password. All other second factors are in 1password.

I use Authy on my phone and watch, but not Authy on the desktop for exactly this reason; if my computer is compromised and 1password is accessible, they still don't have access to my TOTP codes. Having it on both my watch and phone means I can break a device and not lose access.

Re: End of Life for Twilio Authy Desktop App

#95
post #21
post #2

They intentionally make it really hard to migrate your data off their app under the premise of "security". Now, they are EOL'ing desktop apps, which are extremely convenient to use, despite the terrible UX. https://support.authy.com/hc/en-us/articles/1260805179070-Ex... The process for exporting is doable, but requires fairly deep technical knowledge and it isn't 100% clean. In order to do so, you need that desktop a…

What should I replace it with? Any recommendations for a functionally equivalent cross-device 2FA app?

KeePass databases with KeepassXC. I like to use Strongbox on macOS/iOS though (still save to Keepass databases though so I don't have to depend on Strongbox).

Re: End of Life for Twilio Authy Desktop App

#96

Earlier quoted context omitted.

And they try to lock you in to their own ecosystem. If you use sendgrid, it requires an authy specific 2fa code that can only be generated in their app.

Sendgrid was my go to email provider for clients pre-acquisition. Once they got bought out & forced their poorly implemented 2fa with mobile phone requirements, I had no choice but to find different providers.

Postmark FTW

Re: End of Life for Twilio Authy Desktop App

#98
post #65
post #63

I assume many companies are using Twilio for their SMS OTP auth. Does that mean Twilio has a financial interest in steering users away from using Authy?

Twilio owns Authy

Right. Which is why they were noting the implication that if Twilio earns a higher margin from an SMS 2FA vs an Authy 2FA, maybe the owners of Authy would discourage the use of Authy through actions like this.

Re: End of Life for Twilio Authy Desktop App

#99
post #8

Earlier quoted context omitted.

I use Authy. I've read a few comments about how migrating away is difficult. What do you use instead? I also use bitwarden, but not sure how I feel about passwords and totp being in the same app.

> not sure how I feel about passwords and totp being in the same app I felt the same way and I've come to realize that it is not a big deal. One advantage is that with a shared password manager account, you can also share the TOTP along with it. Very convenient for a bunch of usecases.

Is it really multifactor then, with everything in Bitwarden?

Re: End of Life for Twilio Authy Desktop App

#100
post #54

Earlier quoted context omitted.

And they try to lock you in to their own ecosystem. If you use sendgrid, it requires an authy specific 2fa code that can only be generated in their app.

I installed Authy on a rooted phone just to yoink the SendGrid token out and put it in our usual shared authentication service. Such a pain in the ass. I would highly recommend against SendGrid in basically all circumstances fwiw.

> I would highly recommend against SendGrid in basically all circumstances fwiw.

To add another reason: their API will return an error if you send it more than one simultaneous request.

Post reply on HN