7 ms·
Authy (YC W12) launches two-factor auth as a service
- aresant 14y agoBrilliant timing for launch w/the recent DropBox debacle - did the Authy team push launch to draft on that story?
- klint 14y agoNo, I was already talking to them about the story. They just lucked out on the timing.
- aresant 14y agoAwesome, love getting the details on these things given my own experiences w/PR and how timing specific press opportunities can be. Would make an interesting follow-up to understand how they pitched TC / how the DropBox timing impacted publication (if at all). Either way thanks for responding.
- debacle 14y agoDoesn't Twilio already offer 90% of this functionality? > queue jokes about Microsoft security Cue, not queue.
- sjwalter 14y agoIf you're able to build the solution using Twilio (or anything else), then I'm pretty sure Authy isn't for you. I think it's clear that their eventual product is going to be a simple, drop-in that enables two-factor on your mom's knitting forum.
- debacle 14y agoUnless my mom's knitting forum also is an online trading platform, why do they need two factor auth? And how likely is it that their software of choice doesn't have a Twilio plugin?
- wonderzombie 14y agoBecause your mom probably uses the same password on her knitting forum as she does for her bank website or email or ...
- Timothee 14y agoThe solution to that is not to add two-factor auth to the forum but to fix the problem at its source, with a password manager or something like that.
- wonderzombie 14y agoThat's not something the forum can control, though, is it? Nor anyone else who's the target audience for Authy, for that matter.
- Timothee 14y agoOf course the forum can't control that and neither can your bank, but out of the two, only the bank should care and implement two-factor auth. It doesn't matter if your knitting forum account is hacked into, so two-factor auth is overkill. Now, sure the password on that knitting forum might be the same as your bank online account. But the point is that only websites where your account is sensitive needs to add two-factor authentication. I should have phrased my comment above another way: the solution to password re-use is not to add two-factor auth to a knitting forum, but to add it to the bank website, email provider, etc. anywhere your account's safety matters. (I was thinking more from the point of view of the user: if they start to get worried about their accounts getting hacked, two-factor auth on the forum is not the solution, a password manager is)
- gliese1337 14y agoI'd think the biggest draw would be not developer ease as much as end-user ease. This way, an end user with an Authy account would only have to give their phone number out once, to Authy, or install one app from Authy, and automatically be able to use two-factor authentication on any site that supports it. It's like OpenID for the second half of two-factor auth.
- michaelmior 14y agoGive your phone number once to Authy and then to every app that wants to use Authy.
- gliese1337 14y agoWhy? If that's necessary, Authy is doing it wrong. A client app ought to be able to request an auth token that Authy sends to the user without ever having to reveal the user's number to the client app.
- jonotron 14y agoTotally agree... site specific TFA apps is already starting to get a big silly. Battle.net, Google, my Bank... three is already starting to be a pain to manage and install.
- klint 14y agoThanks, fixed it.
- deleted 14y ago[deleted]
- tpr1m 14y agoI wish them luck, since two-factor auth is something which should be implemented more often.
- deleted 14y ago[deleted]
- stcredzero 14y agoI want interaction-free TFA in my phone. I want to be able to walk up to a computer, put in my username and maybe a PIN, and subsequently have every website log me in because the browser knows my phone is on the same LAN as the browser or is in NFC or Bluetooth range. But I would especially want this if the TFA is running on a separate system from the main CPU in my smartphone, only sharing radio/networking hardware at most. This wouldn't be foolproof, but if my smartphone OS company can patch security holes in a timely manner and deliver the patches on-air, then this is good enough for me. If Authy can deliver the 2nd factor automatically from my iPhone to my other devices through Bonjour, I will rave favorably about them to everyone who will listen.
- semenko 14y agoI wouldn't be surprised if Google has tried this. Remember their short-lived QR code-based logon system? http://www.theverge.com/2012/1/17/2714263/google-experiment-qr-code-secure-login-sesame http://www.theverge.com/2012/1/17/2714263/google-experiment-... http://www.zdnet.com/blog/igeneration/googles-qr-code-log-in-experiment-concluded/14679 http://www.zdnet.com/blog/igeneration/googles-qr-code-log-in...
- drivebyacct2 14y agoThis is a horrifying prospect. One that you would trust a LAN, two that you would want any external device to QUERY the credentials and access the creds of another device. Horrifying. There are so many better ways of providing zero interaction auth that is secure: BrowserID, NFC (smartphones that can thus do asymmetric encryption), the QR experiment Google did. Even if you just tweaked your idea to do something along the lines of what Google did... You go to a browser, type gmail.com, enter your email address. They push an event via GCM and your phone asks if you trust the computer that just asked for auth. You click "YES". Similar flow, but no where near as horrifying.
- stcredzero 14y ago> This is a horrifying prospect. One that you would trust a LAN, two that you would want any external device to QUERY the credentials and access the creds of another device. I'm horrified that people jump to such stupid conclusions. There is no need for one machine to query credentials of the phone or vice versa. The browser just sends out a signal and the phone can supply the 2nd factor to the server.
- mehuln 14y agoConsidering all the security issues these days, this is just awesome. Democratization of 2-factor security is really needed. Congrats to Daniel and team!
- semenko 14y agoVery neat service. The Duo Security team also has a similar product with a lot of features: http://www.duosecurity.com/ http://www.duosecurity.com/ They make the X-Ray Android vulnerability scanner (http://www.xray.io/ http://www.xray.io/)
- deleted 14y ago[deleted]
- rdl 14y agoDuo is more mature, but seems to be positioned more as an enterprise alternative to hardware tokens. They seem to charge per user per month, somewhere around $2, which would be crazy for someone like Facebook with a billion users.
- deleted 14y ago[deleted]
- dcu 14y agoyou have to use a valid token at least one time(via sms or authy app) to validate your account. that's explained in the docs: http://docs.authy.com/#section-12 http://docs.authy.com/#section-12
- fsckin 14y agoI don't want another token application. I already have FOUR two-factor-auth apps on my phone, each with multiple tokens: Google RSA Blizzard SWTOR If I can add all the above tokens into your app, I would consider using it. Otherwise... well, good luck with that.
- danielpal 14y agoI hear you. I designed authy so that 1 token would work accross sites for this same reason. Unfortunately its not technically possible for us to allow you to install RSA, Google in our App, as that would mean we would need access to their private seed, which they don't allow.
- blake8086 14y agoAre you sure? http://en.wikipedia.org/wiki/Google_Authenticator http://en.wikipedia.org/wiki/Google_Authenticator
- thej 14y agoGoogle Auth is easy to use in any app https://bitbucket.org/thejeshgn/py2fa https://bitbucket.org/thejeshgn/py2fa
- fsckin 14y agoIs it really not possible? Here is an example of a third party Blizzard app: http://code.google.com/p/winauth/ http://code.google.com/p/winauth/
- winry 14y agoThat logo looks a lot like Shazam's logo.
- dcu 14y agonow that big companies have been hacked, it's the time to start looking for solutions like Authy to prevent phishing attacks.
- jumby 14y agoor you can just implement a google authenticator & HOTP for your own site. it's open source and a billion libraries exist
- dcu 14y agoin the other hand, Authy has few libraries (opensource too), one nice, simple and easy to use app (0 config), and 1 token for all apps.
- kirillzubovsky 14y agoI think this is really cool. Authy guys are making 2-factor authentication main stream, which is incredible. I've used them before on some sites and the process is as easy as you would want it to be. Great job!
- deleted 14y ago[deleted]