7 ms·
Show HN: Authenticator by 2Stable
- headmelted 6y agoIt looks like a nice UI for a 2FA app but I don’t understand what’s missing in existing options that this solves? I also don’t know what encrypted while in iCloud means. Is it your key, my key or Apple’s key? Is the key also backed up to iCloud? It’s important as 2FA is the most critical thing we need to get right next to whatever mechanism secures passwords.
- bombcar 6y agoI wish more sites would integrate a two factor option into their apps instead of requiring a second app - for example I should be able to two factor Amazon via the Amazon app instead of having to use a second app for the one time key generation. Microsoft and Salesforce have made it pretty slick but it’s still two more apps I have to keep that I don’t really want.
- toomuchtodo 6y agoTransferwise nailed this. 2FA request pops up as a notification, touch or Face ID approves it. It’s the canonical example I use when poking other apps to provide a similar UX.
- the_svd_doctor 6y agoI actually hate this, because now I need to install a bunch of apps, 1 per service, just for 2FA. Even if I don’t use them. I much rather prefer Google authenticator, personally. Having an extra option is nice though. But it’s often one or the other.
- scrollaway 6y agoAgreed. It's not a bother when you already have the app, so for Wise i don't mind so much, but it is annoying. And since I use my password manager as my 2fa app, i have a degraded user experience when logging in to it compared to using 1Password. (I'm aware of the implications, don't need a lecture)
- tialaramex 6y agoIf they do WebAuthn they can basically authenticate web visitors and app users via the same approach. A modern iPhone or high end Android both offer the same API where you can get the phone to give your app effectively proof this is the same phone that previously enrolled being used by the same person. Did the phone decide that by examining their fingerprint, video of their face, a blood sample? - you don't know, but it assures you it verified the user and it's definitely the same phone your user used to enroll. You may notice this is the same feature as WebAuthn and is driven by the same technology. If you have server backend code for WebAuthn, the scenario for an app is essentially the same except, where you need your site's domain name for WebAuthn, these iOS/Android APIs need you to do a little bit of work in your app development cycle, get an ID out of that which is effectively unique for your app, and stick that ID into your backend code where the domain name goes. So, users cannot enroll once and have it work both in the app and on a web login, because if that could work an iOS or Android app could exist that just gives bad guys all your WebAuthn credentials - but if your users only do one or the other, they don't care, and either will work with only a small tweak to your backend. If you have users who have the app but don't realise your web site isn't the app, I believe there are already mechanisms to "help" them get where they should be.
- georgyo 6y agoHaving your 2FA tokens on something where the keys available to the user changes it to something you know. An encrypted file with that an application decrypts is still available to the user. ie, they keys are loaded into memory. In most phone and hardware tokens the key is done by a dedicated security chip and is never loaded into main memory.
- UncleMeat 6y agoSo? The code is what matters, not the key. Keeping the key on a dedicated chip doesn't matter if the adversary wants the code and has the capability of reading your process memory. "One thing you have, one thing you know" is a nice heuristic but it isn't an actual threat model analysis.
- 3np 6y agoWhat’s the missing piece compared to Authenticator Plus or Authy? What’d be my actual missing piece would be backups to my own infra, rather than iCloud or any other third party.
- traceroute66 6y agoBackups to own infra has already been taken care of years ago. Look at OTP Auth[1] for example. That will make encrypted backups which you can save wherever. [1] https://apps.apple.com/us/app/otp-auth/id659877384 https://apps.apple.com/us/app/otp-auth/id659877384
- njacobs5074 6y agoLooks like Authenticator App has a macOS version as well. OTP Auth seems be purely an iOS app. Edit: OTP Auth has a macOS version, too. Separate purchase.
- IgorPartola 6y agoI like Authenticator Plus but I really wish it had a search feature. I have so many damn accounts in there and lots of them don’t have their own icons.
- Eric_WVGG 6y agoThe UI of Authy on the Mac is terrible. One of the worst examples of adapting a mobile UI to a mouse+windows interface I’ve ever seen. Also not native. And its iPhone interface isn’t particularly good in the first place. I was desperate for an app like this a couple years ago, but 1Password wound up adding mfa. Regardless, I wish the creators luck, this looks very good! A real “mac-assed app” https://daringfireball.net/linked/2020/03/20/mac-assed-mac-apps https://daringfireball.net/linked/2020/03/20/mac-assed-mac-a...
- rorykoehler 6y agocommand + a select all shortcut doesn't work on the text search field.
- seized 6y agoIt looks like Aegis so I don't see what's been missing... Aegis does backups, biometrics and is open source.
- imwillofficial 6y agoI vastly prefer RememBear for this use case. Plus, who doesn’t love having their own bear? Edit: Choice is great! Keep up the fantastic work. I found the user interface to be clean, a big plus in my book.
- gnrlst 6y agoI fell in love with 1Password (and immediately switched from LastPass) once I discovered it can parse and save the Authenticator qr code and auto-paste it at every 2FA step.
- barbazoo 6y agoWhat?!? I have to try that. I hope I can get my codes out of Authy somehow.
- Freaken 6y agoReally? I completely missed that feature.... thanks for the tip!
- gnrlst 6y agoNo problem! When you go on a website that supports 2FA, it usually shows you a QR code to scan in order to setup a 2FA token. Just open 1Password to your current login and click on the tiny little QR code button. 1P detects it and adds it to that login. Blew my mind as well.
- bdcravens 6y agoAll that's in the QR code is a shared secret string, passed into the TOTP algorithm. https://en.wikipedia.org/wiki/Time-based_One-Time_Password https://en.wikipedia.org/wiki/Time-based_One-Time_Password
- 6y ago
- barbazoo 6y agoLooks neat. Hopefully it'll be available on non Apple devices someday. > All data is encrypted even if is stored in iCloud, so you never have to worry about nasty hackers. That looks like there's a word missing or something.
- Nextgrid 6y agoWhat problems does this solve? This seem to negate the whole purpose of 2FA - now your second factor becomes "something you know" instead of "something you have". What I really want (and would consider a "missing authenticator app") is an app that stays on the phone and keeps all keys there with a client companion app for desktop that communicates with the mobile via Bluetooth to automatically fill the 2FA codes.
- hirsin 6y agoCaBLE may be of interest to you. It's better than 2fa codes, since it's effectively FIDO/web AuthN (unphishable). https://github.com/w3c/webauthn/pull/909 https://github.com/w3c/webauthn/pull/909
- anang 6y agoI use krypton for this and I think it works well.
- CharlesW 6y agoHere's the URL, since finding it via search is hard: https://krypt.co/ https://krypt.co/
- watermelon0 6y agoIt seems like it hasn't been actively developed since 2019, when Akamai bought them, which is quite a shame. Does anyone know of a suitable alternative?
- toomim 6y agoWhat part about this app is "something you know"? It looks to me like it stores a private key in the app, just like all other 2FA apps.
- Nextgrid 6y agoIt talks about iCloud sync, so this means anyone who knows your iCloud credentials can now download your second factors.