4 ms·
You are replacing one privacy nightmare with another: https://www.twilio.com/legal/privacy/authy https://www.twilio.com/legal/privacy/authy The only privacy f
by qwerty10001 5y ago
You are replacing one privacy nightmare with another:
https://www.twilio.com/legal/privacy/authy https://www.twilio.com/legal/privacy/authy
The only privacy friendly method is no 2FA, just long secure passwords. Which is why 2FA is pushed so hard ...
- CarelessExpert 5y ago> The only privacy friendly method is no 2FA, just long secure passwords. Which is why 2FA is pushed so hard ... This is absolutely ridiculous and so clearly false I can't help but wonder if it's intentional misinformation. There are numerous open source TOTP authenticators for both the desktop and mobile that require absolutely no data to be stored in the cloud or shared with third parties. I myself use KeepassXC and Keepass2Android.
- joshuamorton 5y agoNot to mention, like, fido/u2f based systems which don't have any privacy concerns I can think of, even theoretically.
- megapatch 5y agoSo you store the password and the TOTP in KeePass? Seems that you have 1FA, hacking your KeePass is enough to own you.
- CarelessExpert 5y agoNo, that would be silly. They're stored in separate databases with different passwords. If I was really paranoid I'd keep the TOTP database on a separate device but, frankly, I don't anticipate being the target of a motivated attacker so that's more than I feel is necessary given the threat models I'm concerned about, those being untargeted hacks (service breaches, driveby attacks, etc) and social engineering.
- weird-eye-issue 5y agoI use Authy specifically because of their backup options. That obviously requires collecting my phone number and email address. I have no problem with that because if I'm traveling and somebody steals my laptop, phone, and backup Yubikey I won't be completely shit out of luck. If you don't want to use Authy then use something else that doesn't backup the 2FA codes for you. But don't say 2FA is inherently a privacy concern. It isn't.