6 ms·
So I have used Authy, which apparently is somehow protocol compatible with Google Authenticator, and you can back up your tokens with a password. I got a new p
by joncrane 4y ago
So I have used Authy, which apparently is somehow protocol compatible with Google Authenticator, and you can back up your tokens with a password. I got a new phone, installed the app, entered the password, and all my tokens were there.
- iosjunkie 4y agowhich apparently is somehow protocol compatible with Google Authenticator Nothing mysterious. Authy and Google Authenticator simply implement the same standard, RFC 6238. https://datatracker.ietf.org/doc/html/rfc6238 https://datatracker.ietf.org/doc/html/rfc6238
- Nostrada 4y agoThat is the answer. Authy can be used on several machines at the same time. Totally rocks - and is free
- hobo_mark 4y agoSo now your second factor is... the Authy master password?
- Freak_NL 4y agoAnd the private key material Authy has in its database.
- throwanem 4y agoWhich is still strongly preferable to getting locked out of everything because Google Authenticator refuses to participate in device backups. Lucky for me I found out about that well before I moved to "2FA wherever possible", but I still had to send some vendors scans of my driver's license to get back into my accounts with them. Maybe they've fixed that since then, but I don't care. I'd rather risk a theoretical flaw in Authy's E2EE than risk getting screwed again, and by now much more thoroughly, by the flaw I know about in Google Authenticator.
- ROARosen 4y agoHa. Happens to be there is a script out there somewhere which allows you to extract the private key of any of your MFA codes from Authy through Chrome DevTools (it's an Electron app) so you can use it in whichever MFA solution you want.
- throwanem 4y agoTOTP ("Time-based One-Time Password") isn't exactly a "protocol", just a big random number as a pre-shared key plus a method for hashing that with the current time to produce a six-digit number. Whatever you're authenticating to does the same computation with the key and, if the result you provide matches the one it got, it knows you have the same key it does. SMS 2FA is a different proposition, in that the authentication provider sends you the intended response directly. This is a little easier for nontechnical users in that it doesn't require an app that can compute TOTP responses, but it's markedly less secure in that anyone receiving or intercepting the SMS can immediately respond to the challenge, and less resilient in that you can't authenticate at all if you don't receive the SMS - which is the failure mode under discussion here.
- kitsune_cw 4y agoI've moved from using Authy to Aegis Authenticator [0], it's open source and allows you to export an (optionally encrypted) backup of your OTP secrets offline. I trust that more than a cloud backup. Plus you can more easily migrate if Aegis ever goes unmaintained. [0] https://getaegis.app/ https://getaegis.app/
- Eric_WVGG 4y agoThe problem is that one has to enable phone MFA before they can enable Authy/other-app MFA. I have no idea why, only theory I can come up with is the value of tying accounts to outside marketing databases using phone numbers as IDs.
- pan69 4y agoI just installed Authy on my other Android phone and I need to login with my "phone number".... WTF...?
- pieter_mj 4y agouse aegis or keepassXC/Keepassium/Keepass2Android. These apps allow to keep (backups of) your (T)OTP secrets offline and don't require additional PII info to set up.