3 ms·
While Twilio does a lot right, they still only offer SMS and their own proprietary Authy solution for 2FA for their website. No TOTP (and still no plan to offer
by casca 7y ago
While Twilio does a lot right, they still only offer SMS and their own proprietary Authy solution for 2FA for their website. No TOTP (and still no plan to offer the industry standard) means that this has a whiff of hypocrisy.
- philnash 7y agoThe Twilio 2FA API actually allows you to generate secrets and QR codes for generic authenticator applications now. Check out the documentation here: https://www.twilio.com/docs/authy/api/one-time-passwords#other-authenticator-apps https://www.twilio.com/docs/authy/api/one-time-passwords#oth...
- booi 7y agoThe argument then goes back to, why pick up an external dependency and cost for open standard authenticator when you could just include a library and generate it yourself.
- philnash 7y agoThis allows a developer to have all the benefit of the Authy API, including enhancing the experience using push authentication or dropping back to SMS if needed, as well as allowing users to use an authenticator app of their choice. It's the best of all worlds in this case. But if building and maintaining app based TOTP using a library is good enough for you, then go for it. I'm certainly not going to make you use Twilio's APIs, but plenty of businesses do see the benefit.
- casca 7y agoPerhaps, but you still cannot use this to authenticate to Twilio itself. Twilio requires either using unsafe SMS or some version of EEE[1] in their console. [1] https://en.wikipedia.org/wiki/Embrace%2C_extend%2C_and_extinguish https://en.wikipedia.org/wiki/Embrace%2C_extend%2C_and_extin...
- inopinatus 7y agoTwilio seems to have some great engineers and I'm often impressed by the quality of their technical writing, but you'd never know it from their console horrowshow UX. See also: AWS.
- mxuribe 7y agoTHIS 10x!