3 ms·
Well, Google Authenticator uses a standard, well documented algorithm (TOTP) and there is really no reason to touch it unless they discover a security issue, it
by atleta 4y ago
Well, Google Authenticator uses a standard, well documented algorithm (TOTP) and there is really no reason to touch it unless they discover a security issue, it becomes incompatible with the latest version of android or there is a pressing need to improve the UX. But the UX is pretty simple.
I also have Authy, because that seems to be the only one that SendGrid will work with, but exactly because of this I thought that was non-standard. But as I can see now, they probably also support standard TOTP. But they rely on SMS for initial authenticaion (when you install or re-install the app) and I don't trust that. On a side note, Microsoft also has an Authenticator app, which also supports the TOTP standard. (So it can work wherever you would use the Google Authenticator.)
- TedDoesntTalk 4y ago> But they rely on SMS for initial authenticaion (when you install or re-install the app) It's been a long time since I installed it, so I'll take your word for it. They have my email address displayed in the app, so maybe I can do authentication on a new device over email, too. But regardless of how you initially authenticate a reinstall (email or SMS), as long as you are using the Authy cloud backup -- which is password-protected and cannot be reset over SMS or email -- what is your concern (genuine question)? I do not see the security risk, but I'm no expert.
- atleta 4y agoMainly the SMS thing. As far as I can remember, when I reinstalled it on my new phone (about a year ago) I just had to verify my phone number via the SMS they sent. Also, as I have already been using the Google Auth app, I was somewhat ignorant to check out Authy more in detail. Up to know I thought it wasn't using standard TOTP but some in-house developed algorithm by Twilio (or maybe a lesser known/less standard one) because SendGrid specifically tells you to use Authy. Which in itself seemed like a red flag.