3 ms·
> Google Authenticator stores the key unencrypted in an sqlite database, which you can look at if you have rooted your phone. Interesting, actually that's exac
by yokohummer7 10y ago
> Google Authenticator stores the key unencrypted in an sqlite database, which you can look at if you have rooted your phone.
Interesting, actually that's exactly the reason why I like the TOTP algorithm over other two factor mechanisms. I can see what my private keys are, I can back up them, and I can even copy them to other phones I maintain.
Some would tell me it's not good for security, but I'd like to manipulate them in the same way I manipulate my SSH keys. It's just so convenient. If they are moved to TrustZone or something I'd be massively upset.
- Godel_unicode 10y ago> but I'd like to manipulate them in the same way I manipulate my SSH keys. You don't have per-client SSH keys so that only one needs to be revoked if you lose control of a particular client? I bet the red team LOVES you.
- tptacek 10y agoWhy are you backing TOTP keys up? I hear this all the time and it never makes sense to me. You have a backup: they're your backup codes. You use them to enroll the device you get to replace the one you lost. The whole point of TOTP keys is that there's one per device; the idea is to simulate bearer tokens.
- my_first_acct 10y ago(replying to a dead thread, I guess) One issue: where/how to store the backup codes? Paper in a box in the bank? Not very convenient if you are traveling and lose your primary device. Paper in your wallet? Not very secure (and the probabilities of losing your wallet and losing your phone are correlated). Encrypted file on dropbox? I don't trust myself not to make a stupid mistake and leave an unencrypted copy in a "temporary" file somewhere. TOTP key: load it onto 3 password-protected Y4 keys. Take two of them with you on your trip, and leave one in the bank. No way (without very expensive expertise) to extract the TOTP keys from the Y4, which also means that a user blunder won't expose the keys, and hopefully your Y4 password is strong enough to give you time to change the TOTP keys before anyone cracks a lost Y4.
- greenleafjacob 10y agoLots of vendors offer TOTP but not backup codes.