13 ms·
Google Authenticator cloud sync: Google can see the secrets, even while stored
- You-Are-Right 3y ago[dead]
- ggm 3y agoIt's a dual facing problem. Not only do users have no defence against google snooping, but google has no defence against requests to snoop: Apple seems to drive harder to "we'd help if we could, but we can't: to us its just blobs"
- heavyset_go 3y agoApple regularly gives up customers' private data when requested, and they keep logs of it themselves[1]. [1] https://www.apple.com/legal/transparency/us.html https://www.apple.com/legal/transparency/us.html
- goalieca 3y agoSo far apple has not been compelled by the courts to make a tool so they could decrypt the e2e stuff which now pretty much includes all iCloud content. As far as we publicly know.
- waboremo 3y agoPrior to ADP, agencies like FBI could actually access a lot of information from Apple, primarily because Apple stored keys alongside your data. Which meant even though iMessage content was encrypted (and therefore useless), they could still get a lot of information from a request to Apple -- and Apple hands over quite a lot. FBI had a document all about that in 2021. Also important to note, ADP is opt-in currently.
- SXX 3y agoBut Apple now has Advanced Data Protection that add E2EE for majority of iCloud data and they only keep keys on your devices. Not that I have absolute trust in Apple, but Google don't even have that.
- lern_too_spel 3y agoGoogle had that four years before Advanced Data Protection existed. https://security.googleblog.com/2018/10/google-and-android-have-your-back-by.html https://security.googleblog.com/2018/10/google-and-android-h... Warning: this blog post has meaningless marketing-speak. It starts by saying Android is about choice but instead of announcing the ability to set your own backup provider, it just says how Google's Android backup service works, which is wholly unrelated to that first sentence.
- j16sdiz 3y agoIf you are talking about device backup, apple had it encrypted before Advanced data protection. If you are talking about other data, Google don't have it encrypted even today.
- lern_too_spel 3y ago> If you are talking about device backup, apple had it encrypted before Advanced data protection. Not end to end: https://www.wired.com/story/apple-end-to-end-encryption-icloud-backups/ https://www.wired.com/story/apple-end-to-end-encryption-iclo...
- v4dok 3y agoParent talks about device backup. Your link talks about iCloud backup. Different things
- lern_too_spel 3y agoDevices are backed up to iCloud. Same thing. https://support.apple.com/guide/iphone/back-up-iphone-iph3ecf67d29/ios https://support.apple.com/guide/iphone/back-up-iphone-iph3ec... https://support.apple.com/guide/icloud/view-and-manage-backups-mm122d3ef202/icloud https://support.apple.com/guide/icloud/view-and-manage-backu...
- hammyhavoc 3y agoUsers have defence against snooping, it's not using Google in the first place if this is a consideration in their threat model. Does or should grandma care? No. Should a political dissenter living in an oppressive regime think twice? Yes.
- sneak 3y agoTOTP (the six digit codes) is bad and outdated 2FA anyway. It's vulnerable to phishing. Use WebAuthn with security keys.
- gleenn 3y agoUntil people stop using SMS codes it's still way more safe from cell phone cloning attacks.
- px43 3y agoPeople should have stopped using SMS codes when NIST told them to stop six years ago. The fact that there are websites that still support it is an abomination and should come with hefty legal penalties.
- justinclift 3y agoThe Australian Government's national website for its citizens to interact with gov services uses SMS based 2FA, and doesn't appear to support any other type. :/
- EVa5I7bHFq9mnYK 3y agoPeople? It's banks, who all insist on SMS, not people,
- ocdtrekkie 3y agoSomeone will, of course, claim Google would never do this, but this presumably would make it trivial for Google itself to log into all of your accounts. In many cases they are already syncing a copy of your passwords.
- gleenn 3y agoIt's 2FA so it would only get them half way there right?
- db3pt0 3y ago> In many cases they are already syncing a copy of your passwords. No, that gets them the full way there. They have your 2FA codes, and if you use Chrome and opt into it syncing passwords for you (passwords.google.com), this gives them both pieces of the puzzle.
- cleanchit 3y agoIf you use chrome, they could just download your cookies if they really wanted to.
- hsbauauvhabzb 3y agoI’d love it if google did this to me. I wouldn’t settle for anything less than a 9 figure payout.
- ocdtrekkie 3y agoBear in mind, you would probably not see this as a covert/criminal act, but something sold as a feature. "Our artificial intelligence now can assist you by analyzing your transaction habits with your bank and can help manage your Facebook account." The sort of thing as a tech crowd would horrify many of us, but the public would largely go "oh neato".
- judge2020 3y agoChrome passwords are encrypted with your password (just not e2ee) so it'd have to be a targeted attack where they log your password the next time you log in and then use that to decrypt your chrome passwords. Chrome also allows you to set your own sync passphrase different from your Google account password.
- nomilk 3y ago> if someone obtains access to your Google Account, all of your 2FA secrets would be compromised. This overlooks that fact Google itself also has access to your 2FA secrets, which could be even worse considering Google could be requested to peer not just into the user's google account, but into accounts they have with other companies/organisations too.
- Rookie42 3y agoHey, I am about to start writing a position paper covering Social login providers the company should enable/support. Do you have any references you can share for the above comment please ?
- gojomo 3y agoUnder what conditions do you suggest "Google itself also has access to all your 2FA secrets"? (Without cloud backup, & without the installation of a malicious version of 'Google Authenticator', how would they – especially, say, on iOS?)
- cogitoergofutuo 3y agoI think they are referring to the scenario where cloud backup is enabled.
- gojomo 3y agoAha, thanks. But, if the 2FA secrets were end-encrypted as the top link suggests, Google then wouldn't in fact have them - so the ggp-comment accusation that the link "overlooks" this factor is nonsensical. (And if Google were denied access to the cleartext 2FA secrete this, way, then briefly compromising someone's Google account – say by hacking or abuse of legal process – wouldn't automatically compromise all other 2FA-key-protected accounts.)
- olliej 3y agoWhy would google have access to that material? Is their general secret mechanism not E2EE? I'm fairly cynical on google's approach to privacy but I would be shocked if they're normal syncing isn't actually secure and private.
- modeless 3y agoWhat? Why would this not get the same end-to-end encryption as Android backups? They'd have to do extra work to make this less secure. Edit: oh I guess because it supports syncing between Android and iOS? Still lame, they should at least have an option to use the normal Android backup system. Which should have been the default since the start.
- jeroenhd 3y agoEven if they synchronize cross platform, there's no reason why they can't take the Android backup algorithm and stuff it into their iOS app. Google owns both side of the connection here and the Android code is even open source.
- Someone1234 3y agoCan the title get changed? - E2E in this case is nebulous, this isn't a chat or email client, it isn't client <-> client with Google acting as an intermediary. It is between your Google account/Google's Server and Google's software. - It isn't clear if during transportation it is encrypted (e.g. HTTPS?); since seemingly this post isn't about that (or if it is the evidence or technical information is lacking). The term "E2EE" typically is referring to encryption from client <-> client through a blind intermediary, but again that doesn't describe the relationship here. The actual complaint SEEMS to be: > Google Authenticator backup isn't encrypted at rest on Google's Servers My big complaint is that this is a misuse of the term "E2E" (E2EE). It simply doesn't apply in this situation. That doesn't mean it isn't discussion worthy (e.g. not using HTTPS is a major red flag, and not encrypting at rest on Google's Servers is discussable). In general the linked post doesn't do a good job describing what they found and how they found it.
- deleted 3y ago[deleted]
- jchw 3y agoEnd-to-end is being used to mean encrypted on the client and decrypted on other clients. "Encrypted at rest" is overloaded, it's often used to refer to secrets stored encrypted by an HSM or something where the key is still accessible by whoever is storing the data; pretty common for compliance where the threat model being addressed is someone stealing a hard drive from a data center, but not very useful for when you want a secret to remain secret even to the server operator. This is pretty common use for the term E2EE as far as I can tell. That all of the "clients" for which the encryption would be end-to-end for are all run by the same user is not really a big deal; I've seen it used similarly for things like "end-to-end encrypted notes" and that sort of thing. Example: https://standardnotes.com/ https://standardnotes.com/
- amarshall 3y agoE2EE is a valid term. Just because both ends are controlled by the same person doesn’t make it not “client ↔ client”. Just because Google wrote the software and stores the backups does not mean that those backups should be readable to someone (e.g. Google servers) with access only to the backup. E2EE means that no one other then the end-users can see the data—in this case, that is just the one user. Neither transit encryption nor encryption at rest provide that. Encryption at rest is not really part of the discussion. There’s no way to verify client side that it is happening, and it does not prevent Google servers from seeing the plaintext backup. > In general the linked post doesn't do a good job describing what they found and how they found it Seemed pretty clear: they did MITM to bypass any transit encryption and saw the plaintext secrets being sent, and thus Google servers can see all the secrets.
- soheilpro 3y agoAfter my phone was stolen last month, I switched to https://2fas.com https://2fas.com and couldn't be any happier. It's free, open source and has tons of great features.
- fortuna86 3y ago[dead]
- usr1106 3y agoLooks good at a first glimpse. Please don't write "it's free". That's a non-message many companies give, Google of course one of them. We know that it means you pay by providing your data. Other models could be "run by volunteers" or "fully funded by donations".
- warkdarrior 3y agoBut it is free, both by the casual definition (zero cost) and by FSF definition (Free Software).
- jve 3y agoHe wants to distinguish between "free: you pay with your privacy and we share your data with whoever wants it!" or "free: but only basic features, want more? pay" and "free: because people like you help it being 100% free and we have no pressure to use your data and everything is open so you can look at the code"
- blitzar 3y agoMany open source enthusiasts are really 'dont like paying money for things' enthusiasts.
- prepend 3y agoThat’s certainly a big part for me. But it’s not about saving $2, I think that free is sustainable therefore likely to run in 50 or 100 years where any non-zero amount decreases that probability. So if I don’t pay money for things there’s not a service element, or a phone home to activate element, or other things that require an ongoing cost.
- Animats 3y agoBut all that juicy data they could steal would just be going to waste when they did this. I was really annoyed when iDrive, the backup service, pulled this stunt. Originally, they didn't have access to your encryption key. Then they put a dark pattern on their site to encourage users to give them the encryption key, to support the "the Cloud interface". Then you needed to give them the encryption key for some support functions.
- patmcc 3y agoIt's a tradeoff. They could let (or require) a password be entered to encrypt/decrypt it on each device, but then people would be ticked off when they forget their password and can't recover their 2FA stuff. They should have handled it the same way they do Sync in chrome, and I expect they will eventually. But, as always, unless a service advertises that it's full E2EE and you can verify that, assume it's not. One part of this that's funny to me: >>>Also, 2FA QR codes typically contain other information such as account name and the name of the service (e.g. Twitter, Amazon, etc). Since Google can see all this data, it knows which online services you use, and could potentially use this information for personalized ads. I guarantee you, Google knows which online services you use in about 800 other ways, it doesn't need to scrape it from your 2FA accounts.
- jxy 3y agoThe problem is now they know your TOTP secrets, they are only one password away from pretending to be you. And actually, they serve you emails, so password is moot for most of the sites today.
- koolba 3y agoThey always knew your TOTP secrets. The algorithm requires both parties to know the plaintext secret as it’s an input to the HMAC. It’s not a public key operation and they can’t store it as a hashed representation. It’s possible to have 2FA methods that are verify only (usually using public keys and signing), but TOTP is not one of them.
- MereInterest 3y agoThe website you log into with TOTP has always known the TOTP secret. Now, Google also knows your TOTP secret.
- koolba 3y agoAh! I misunderstood this being applied to non-Google accounts. Yes that’s scary.
- Animats 3y agoIs there anyone who operates an authentication service which: - Has a contractual obligation to keep your data secure. - Accepts financial responsibility for data compromise. - Carries insurance and bonding to back that responsibility. - Does not require binding arbitration or forbid class actions. - Has their employees bonded in the way bank employees are bonded. Well?
- duckmysick 3y agoHow much would you pay for it?
- baridbelmedar 3y agoHuh, can't I get this service for free or at most $1 a month...What are you saying? :)
- makeitdouble 3y agoOutside of the price issue, this service would also be a prime target go get compromised: I'd assume it would get the juiciest users, and national agencies would have the strongest incentives to backdoor it for later use. We'd need a bunch of services to get to that level first to see any meaningful choice IMHO. I have no idea how that would happen.
- Animats 3y agoIt would make sense as a service offered by banks. They already have to verify ID. They're usually required to take financial responsibility for their errors, too.
- yencabulator 3y agoSo, just like okta.com, used by lots of huge companies.
- eliotte 3y agoIf it is not E2E encrypted, 3-letter agencies can put their tap somewhere in the Google infrastructure.
- throwawaaarrgh 3y agotl;dr if a hacker gets access to your Google account it'll be like you didn't have 2FA at all to be fair, storing your 2FA seeds in 1Password is about the same, except 1Password supposedly can't see your secrets. but if a hacker gets access to your unlocked 1Password data it's the same tl;dr2 use offline TOTP or similar for real 2FA
- unobatbayar 3y agoAlso, all your private cloud storage photos and data are stored in publicly accessible urls.
- unobatbayar 3y agoThe people who are downvoting this comment, can you prove it otherwise?
- coding123 3y agoWeird no mention of authy
- jwr 3y agoAuthy gets this right. Not sure why anyone would trust Google with their 2FA secrets.
- psnehanshu 3y agoHow exactly?
- imrehg 3y agoI guess the person meant this: encrypt-than-upload of backups with backup passkey managed by yourself, details e.g. in this blogpost: https://authy.com/blog/how-the-authy-two-factor-backups-work/ https://authy.com/blog/how-the-authy-two-factor-backups-work...
- dvzk 3y agoI suspect the vast majority of Authy backups use passwords trivially susceptible to brute-force attacks despite only 1000 (!!!) iterations of PBKDF2. If Authy wanted to do things right, it would generate local encryption keys instead of asking normies for file encryption passphrases.
- yencabulator 3y agoargon2/scrypt with significantly larger costs sound like the right fix. Asymmetric crypto can make backing up still cheap, who cares if restoring takes 30 seconds.
- dvzk 3y agoThat would be a great improvement for technical users. But also consider that the target for Authy is the average mobile user. I’m not unconvinced that the typical backup password looks like S3cr3tP@s$w0rd, which no amount of key stretching will fix.
- jwr 3y agoYes. What I meant was that Authy does encrypted backups. You can criticize how it's implemented, but it's there, it works, and your 2FA secrets aren't just sitting in the cloud. I think I'll refrain from posting on topics about Google — clearly there is a huge pro-Google sentiment among HN readers and anything detracting from that gets instantly downvoted.
- nucivorous 3y agoImagine your google account getting deleted cuz you got banned from Google and the suddenly you lose all your 2FA secrets cuz they are part of that account
- jve 3y agoYou would have to loose your phone simultaneously.
- GvS 3y agoI can recommend Aegis Authenticator - https://getaegis.app/ https://getaegis.app/ It has an option for encrypted, automated backups to Google or Nextcloud.
- zamnos 3y ago> likely even while they’re stored on their servers. I'm all for castigating Google for not encrypting the TOTP seed which is (apparently) transmitted in the clear, but there's no actual proof (one way or the other) that the secrets are/are not being stored encrypted. Thus claiming "even while stored" claim is a bit much.
- kevincox 3y agoYeah, there isn't such thing as an unencrypted disk at Google. Most things are encrypted multiple times in different layers before hitting physical media. Not E2EE which is a serious concern, but definitely encrypted in some form in transit (exceptions for intra-datacenter transfers) and at rest.
- rurban 3y agoNow I wonder if this just a bad netsec beginners mistake (dev, tester, pm all being stupid), or if it's unencrypted on purpose? Both options are not thrilling.
- yrro 3y agoFreeOTP recently gained support for backups to local file storage or cloud providers. The backups are encrypted with a passphrase, so the cloud provider can't obtain your OTP keys.
- Simplicitas 3y agoWhy don’t people use their own TOTP provider, like KeepassXC/Strongbox, storing the DB in an encrypted manner on a cloud of their choice. Then use across multiple devices. It took time for this to sync in, so maybe that’s why so many others do not see that there is really no need to have a third party involved in this pattern?
- jqpabc123 3y agoIt's fairly easy to make your own TOTP provider. I wrote a simple CLI TOTP utility that works using an AES encrypted lookup table of secrets. I piggybacked access to this off an unrelated web site and it is now readily available from any device if you have the decrypt key and know the URL.
- nurettin 3y agoYou can just log out in the app to stop the synchronization. Problem solved.
- richij 3y agoI think Mysk just described "sync the secrets to your Google account." E2E would rather imply that there's a second E, but that's not the use case here. If you already have a second E, just use the QR export/import feature.