4 ms·
No. They aren't. This thread is seriously upsetting to read. So many people clearly haven't even remotely begun to think about what they're doing or the implica
by stoplying1 4y ago
No. They aren't. This thread is seriously upsetting to read. So many people clearly haven't even remotely begun to think about what they're doing or the implications thereof.
- bjord 4y agoeverything I've read suggests that they are, in fact, E2EE of course, they're not open source, so I'm not really going to bat for them here, but am I missing something? https://authy.com/blog/how-the-authy-two-factor-backups-work/ https://authy.com/blog/how-the-authy-two-factor-backups-work... https://www.ghacks.net/2022/08/10/twilio-the-company-behind-authy-suffered-a-data-breach/ https://www.ghacks.net/2022/08/10/twilio-the-company-behind-... etc.
- stoplying1 4y agoAnother user here pointed out that Authy uses a user provided password to encrypt the 2fa secrets on the server. That's definitely more secure than I had said, that's my mistake. (I still have my reservations, but that's getting too pedantic to matter here)