7 ms·
I feel like this misses the problem with Authy. There are hundreds, possibly thousands of 2FA alternatives for Authy. But when my 401K provider requires Authy
by secstate 2y ago
I feel like this misses the problem with Authy. There are hundreds, possibly thousands of 2FA alternatives for Authy. But when my 401K provider requires Authy to login in without providing a generic 2FA option, THAT is the problem.
- ezekg 2y agoIf we're talking OTP/TOTP -- it's all the same. Even if a provider instructs you to use a specific app, e.g. Google or Authy, you can simply scan the QR code with whatever authenticator app you're using. All the QR code does is encode a URI containing the secret and issuer.
- RockRobotRock 2y agoI don’t think that’s what they’re saying. Authy supports TOTP but they also have a proprietary format.
- roughly 2y agoAuthy supports TOTP, but also has its own proprietary TOTP-esque format that a bunch of sites & companies use (Twitch and my bank, among them) that can't be copied into another site. (Yes, it's bad, no, it shouldn't exist, no, I don't know why they don't just <...>, etc.)
- 77pt77 2y agoIs it standardized?
- kuon 2y agoI use keepassxc for twitch so it should be something fairly standard, I don't remember using special settings. Anyway, I wanted to share this gist which might be of some help to migrate away from authy: https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93 https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
- Wevah 2y agoTwitch supports regular TOTP now, thank goodness.
- dethmetaljeff 2y agoAuthy (the app) does support generic TOTP which as you mentioned, so do hundreds of others. Unfortunately, the authy app (and some well meaning but not so well versed companies) opt to use Authy's proprietary OTP which isnt compatible with other clients.
- omneity 2y agoThis is simply not true. Just today an app asked me to use Microsoft Authenticator, and scanning the QR code with Google Auth and Authy didn’t work, earning me an “Invalid QR code” error and forcing me to install the app from MS.
- ezekg 2y agoI don't think there's a formal spec for the otpauth URI yet [0], even if there is a spec by Google [1], so this may just come down to MS adding some incompatibility to force usage of their authenticator, or the app using some proprietary authentication scheme that is not otpauth. There's nothing complicated about otpauth provisioning URIs i.e. what's encoded into the QR code. [0]: https://shkspr.mobi/blog/2022/05/why-is-there-no-formal-specification-for-otpauth-urls/ https://shkspr.mobi/blog/2022/05/why-is-there-no-formal-spec... [1]: https://github.com/google/google-authenticator/wiki/Key-Uri-Format https://github.com/google/google-authenticator/wiki/Key-Uri-...
- nickburns 2y agoYou assume that because you were not able to overcome whatever error/s you encountered with Google Auth and Authy, that you were being forced to use MS Authenticator.
- omneity 2y agoPretty uncharitable interpretation on your end. I am a developer and went to the extent of verifying the content of the QR code and the optional URL for manually adding it. No OTP code in there. Try to be nicer next time.
- nickburns 2y agoI truly did not mean to come off as rude. The 'content of the QR code' would've revealed the actual seed and so would corroborate your assumption if you did, in fact, verify as much. I merey stated a troubleshooting fact. No offense intended.
- remuskaos 2y agoAuthy has this 7 digit TOTP, which seems kind of proprietary. But Aegis supports that too, and is open source.
- politelemon 2y agoIs it possible to 'transfer' the 7 digit account from Authy over or best to start over?
- brewdad 2y agoThere used to be a roundabout (unsupported) way to export from Authy Desktop to another app but Authy discontinued the Desktop app and Windows at least won't let you launch it anymore. I'm not aware of a way to export from the Authy phone app.
- xp84 2y agoTHE problem with Authy in my humble opinion isn’t just that it’s an obnoxious proprietary app I shouldn’t need — it’s that it forces you to accept SMS as a get-out-of-security-free card. Being able to get a reset text to your registered number (and you MUST register a number, of course) unlocks all your OTPs for the attacker (who slipped some teenaged phone salesman $50 or a fake ID to swap your sims.) SMS is cancer to security and I won’t use any system that forces me to accept something so easy to exploit as proof of my consent.
- nextos 2y agoRegulators should mandate 2FA with an OTP standard, such as OATH TOTP. Here in EU, lots of banks use their own proprietary OTP-like standard or SMS. I never understood why SMS are preferred to OTPs generated offline using credit cards and a card reader, which were fairly popular. Actually, EU regulations state SMS should be phased out, but banks largely ignore that. SIM cloning is fairly easy...
- benoliver999 2y agoThe readers cost money and people lose them. I still have one for one bank but otherwise it's SMS everywhere. They clearly just don't see it as a realistic threat, on top of all the other security measures in place (for me it's a password, and also a memorable word that isn't typed on the keyboard, then SMS OTP). It's not a great defence of SMS but perfect is the enemy of good, and SMS is just about ok. Most hacking stories I hear about seem to happen through social engineering, where people go to great lengths to authenticate themselves for someone over the phone. One thing that is starting to take hold is banking apps, which once installed can be used to authenticate payment. Again not perfect but better than SMS, and users are increasingly likely to have them installed because of ease of use.
- nextos 2y agoAt least here, SIM cloning is a very popular attack.
- wesapien 2y agoIs there a list of services that have a specific 2FA provider requirement? In my experience, my when my service ask for 2FA it usually says Google Authenticator and use Authy. I'm looking to migrate out of Authy in the near future.
- 1oooqooq 2y agooh boy, wait until you have to use anything under id.me, which is in bed with the federal govt. you will be crying for them to let you go back to authy and sms.