3 ms·
The actual TOTP secrets are (or should be) encrypted with the backup password that the user chose, so access to the backups wouldn't automatically result in com
by Deathmax 4y ago
The actual TOTP secrets are (or should be) encrypted with the backup password that the user chose, so access to the backups wouldn't automatically result in compromised TOTP secrets unless the backup password was weak.
- i67vw3 4y agoAs far as I know, the backup password is not needed for recovery using this method. When you have 'Multi-device' enabled in settings and install Authy on second device then the backup password is used/useful. But for this method, your phone number linked to Authy Account, email Id linked to Authy Account are needed. The Process is Started by old-school SMS based OTP sent to the linked number. You then have to Cancel it via a email sent to you, if you think some is doing is maliciously without your consent.