5 ms·
I'm not really in favor of putting 2FA codes in the Cloud, see that password manager that got hacked a few months ago. Granted, we can expect better from Google
by obarthelemy 3y ago
I'm not really in favor of putting 2FA codes in the Cloud, see that password manager that got hacked a few months ago. Granted, we can expect better from Google, but still, they're not accepting any liability.
Google Authenticator already has a QR-Code based very easy export procedure, I just backup my GAuth to my spare phone and tablet. It feels safer because it's physical.
Of course, not everyone has several devices, and physical security is not granted to everyone. I guess cloud-backedup 2FA is better than no 2FA, or than 2FA with no backup at all. But... Cloud ? for security stuff ?
- ris 3y agoThis. For me a TOTP app/tool will only ever output codes. If it offers to let me do anything else with the key, it's a no-go.
- bombolo 3y agoSo what do you do when your phone falls down and breaks?
- obarthelemy 3y agoI take my previous phone out of its drawer. Or my tablet.
- bombolo 3y agoVery funny. But how do you login into things without the otp seed?
- iavael 3y agoUse another device with _another_ seed (since this is auth factor of ownership you must not share seed between multiple devices just like pki private keys and pgp keys). Or if you don't have backup otp generator then use backup codes.
- obarthelemy 3y agoIt's standalone 2FA, not a paswword manager. There's no seed.
- bombolo 3y agoOooooh, you don't understand how google authenticator works!
- obarthelemy 3y agoTry it: it works offline.
- bombolo 3y agoIt doesn't work from a broken phone.
- ris 3y agoAccount recovery codes & other means of backup authentication until I can generate new MFA tokens. It's really not a big deal, whereas it looks like the next big cloud hack will be.
- notfed 3y agoI think rest assured your backups will be encrypted-by-password. Though, I often find myself wondering if this represents going in circles with security. If the security surface of all of your 2FA keys now reduce to one measly password, well, wait a second, does protecting everything with two passwords count as 2FA?
- obarthelemy 3y ago"encrypted by password" doesn't mean much by itself: is the whole security chain open source ? audited by a third party ? as well as any changes ? Secured by the provider accepting responsibility for breaches and their consequences ? ... Employees down to subcontractor's trainees can modify the code or pwd store... FYI, the industry standard for "risk of corruption" is: 3 months of wages. In low-pay countries, this means, literally, pocket change. How sure are you that whatever Google does is impervious to such insider bad actors, even if at a specific time their setup was indeed secure ?
- notfed 3y agoLooks like I was wrong, not password-protected. Oops.