4 ms·
I have to disagree with the Authy recommendation. I switched to Authy a few years ago, but it was nothing but painful and I have recently migrated away from it.
by wrboyce 10y ago
I have to disagree with the Authy recommendation. I switched to Authy a few years ago, but it was nothing but painful and I have recently migrated away from it. For a long time the "TouchID Prompt" was slow and buggy, but that does appear to be fixed now.
The real pain point is that it managed to corrupt one of my keys (how??) and the app tries to get me to backup my keys to their servers with multiple popups (which I cannot disable) prompting me to backup every time I use the app. I don't know why they are so determined to get hold of my OTP keys, but it isn't happening.
I'm currently using an app called "OTP Auth" and it seems quite nice, and is quick to use.
- rtpg 10y agoa major advantage is if I throw my phone into the ocean(not a theoretical attack!) I can still recover my OTP on another machine. Authy offers this pretty nicely I would recommend testing theories of : - losing phone - losing computer - losing both and have reasonable backup strategies for these scenarios.
- teach 10y agoI use Google's authenticator on my phone and a 50-line python script on my desktop PC. I store the OTPs in a JSON file and the python script runs them through the TOTP algorithm and spits out my 6-digit code on the console. I'm less worried about losing my "computer" since I don't own a laptop, plus the secrets are backed up using my normal backup process.
- dublinben 10y agoA good 2FA system involves backup keys which can be stored in a safe or safety deposit box, not handing your private key over to a third party.
- gengkev 10y agoIsn't that the point of having backup codes for Google, etc.? I can use those to restore my account, and secure them however I like. Backing up the secrets to a third party makes them vulnerable to anyone who can hack your Authy account. I'm not sure what that requires, possibly hacking a phone number. Of course, there's also a backup password, but then you're just replacing the "physical" factor in 2FA with another password. Without Authy, to compromise my account, you need physical access to my phone, my backup codes, or another backup mechanism I've specified. Authy just provides an additional way to compromise my account, and I don't think it provides any real benefit in exchange for that risk.
- kyrias 10y agoYou should have the backup codes stored somewhere more secure than your computer either way, quite possibly printed out.
- tdkl 10y ago> the app tries to get me to backup my keys to their servers That's the idea for using Authy.