8 ms·
CloudFlare partners with Authy to implement two-factor authentication
- jgrahamc 14y agoDetails on how this works for CloudFlare customers: http://blog.cloudflare.com/2-factor-authentication-now-available http://blog.cloudflare.com/2-factor-authentication-now-avail... Also, Authy is a YC company with a nice solution.
- Koldark 14y agoNot against 2-factor, but now I have to install yet another application of questionable origin to trust my access to. Why not just use Google Authenticator?
- gqdev 14y agoAh thats my problem .. only if authy can integrate and let us add what we already have on Google authenticator . i will dump Google auth.
- danielpal 14y agoYou will be very pleasently surprised very soon. We will support google authenticator and it'll be awesome...I can't wait to share - I wish apple was quicker approving apps - If you want a version sooner I can share via testflight if you wish, that way you can also help us make it better. E-mail me at d@authy.com and I'll make it happen.
- ChrisClark 14y agoDoes this mean you have Google Authenticator support in the Android app already, since there aren't any approval times? Or are you specifically delaying updating the Android app to wait for Apple? That's not fun. :(
- rdl 14y ago"Google Authenticator" actually is any RFC 4226/6238 compatible HOTP/TOTP client, actually, including hardware dongles or phone apps or whatever. I'm not sure if Authy is using the same protocol. What really surprises me is that Twitter doesn't support any OTP solution; Twitter accounts getting hacked is a fairly common thing (@mat), and there's basically no solution to it now. Facebook doesn't use OTP but uses the information they have to do probably the best knowledge based authentication on the Internet (plus, shows IPs in use, and does geo-IP based fraud prevention, but Twitter doesn't really know anything secret about you. I've bugged Twitter people about this several times.
- jgrahamc 14y agoAuthy is based on the same standards.
- omh 14y agoSo I can install just the Google app and enter my Authy codes there, and vice versa?
- jgrahamc 14y agoMy understanding is that Authy uses a key that is twice the length of the Google Authenticator key and so they are not compatible. Also, there are other things that Authy does way better than Google Authenticator: 1. If you change phones you have to reconfigure all your accounts that are using Google Authenticator. With Authy it just works when you install the Authy app on the new phone. 2. Authy fixes time sync problems between your phone and UTC in the background so you do not have to worry. 3. And if you lose your phone with Google Authenticator there's no simple way to revoke access to all your accounts. With Authy there is. 4. Authy has a way to revoke tokens across all devices. If (like what happened to RSA) the private information were stolen from Authy they can invalidate all the tokens and securely reissue new ones.
- marshray 14y agoAccording to https://www.authy.com/help/faq https://www.authy.com/help/faq, it looks like they're using http://tools.ietf.org/html/rfc4226 http://tools.ietf.org/html/rfc4226 HOTP with some version of SHA-2 and a 256 bit seed. The suggested default for HOTP/TOTP is SHA-1 with a 160 bit seed and that's what most systems seem to use.
- zhuzhuor 14y agoI'm a little puzzled by the way authy works. It seems to me the authy app refreshes a new code whenever I turn the screen off and on. I don't know how it syncs with the authentication server. The app must not only based on time ticks, like other 2-factor apps. One way I thought is to notify the authentication server in background network requests. But I guess this isn't the case, because it won't work if you don't have network signal (you can try it in the airplane mode). The other way I thought is the code must be self-verifiable. That means half of the code is a random number, and the other half is the real code computed based on the rand numb and some credentials. If it is really in this case the security strength is only half of the length of the code, i.e. 3.5 digits. That's not very safe to me, especially the website of authy itself only needs one code to log in (without any `first-factor` password). Any thoughts?
- jgrahamc 14y agohttp://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm http://en.wikipedia.org/wiki/Time-based_One-time_Password_Al...
- zhuzhuor 14y agoI don't think it is solely based on time. Did you read my comment carefully?
- marshray 14y agoI have implemented HOTP/TOTP. HOTP is based on the secret seed and a counter value (e.g., button presses). TOTP substitutes time for the counter value. I read your comment carefully and it didn't make any sense to me. The other way I thought is the code must be self-verifiable. No, code verification requires knowledge of the secret seed value.
- zhuzhuor 14y agoPlease read my comment to @danielpal. By self-verifiable I mean the half of the code is a random number, the other half is computed based on the secret seed and the random number. I guess another way without frequent sync is to generate a new code every sec, and the server check if it's one of the 25 codes in the last 25 seconds. But this might be unnecessary and inefficient.
- aioprisan 14y agoironic how the homepage shows a red lock icon (using resources over http) and their demo is completely on http:// http://
- danielpal 14y agoWe don't transfer any resources over HTTP on www.authy.com, we even use HSTS on www.authy.com. Demo is over http because it's not meant to be a secure site, only something you use to see how it works. Database is destroyed daily, but I agree we should change it to https.
- citricsquid 14y agoWhen sent an SMS from Authy (in the UK) the sender is listed as "BulkSMS", would be nice if it was "Authy" or something, I didn't recognise why I would have an SMS from that sender until I opened it. Looking at the pricing, is there any explanation of what "Users" and "Auths" mean exactly, is that people that can authenticate with the application, or people that do every month? Not entirely sure.
- danielpal 14y ago#1. We wish. We use around 14 different cellphone # to bypass Spam etc on SMS. Most people don't understand how hard is to reliably send SMS internationally (twilio makes it look easy in the US :)) 2. Auth's are times you call the verify/token API. Since it's an API you can decide when exactly when to call it. Most our clients authenticate tokens every 14 - 30 days. So people can authentication to your app via username - password or cookies and then sometimes via username - password - token. We only count an Auth when they do username - password - token.
- citricsquid 14y agoI believe Twilio supports the UK. Thanks for the clarification. Final question regarding the "large" plan, it lists "100,000+ Users" and "25,000+ Auth's/month", does the + mean there's no upper limit (with some degree of fair usage)?
- danielpal 14y agoThe + means at the plan we you can buy more auth's granularly. So you can buy 5000 more auth's if you need or users too. Prices depend on volume.
- citricsquid 14y agoGreat, thanks!
- eastdakota 14y agoHere's a blog post on the decision process we went though to select Authy and, in particular, why we didn't use the Google Authenticator app: http://blog.cloudflare.com/choosing-a-two-factor-authentication-system http://blog.cloudflare.com/choosing-a-two-factor-authenticat...
- csarva 14y agoIt's not very straightforward, but it does seem you can revoke the app via this page - https://accounts.google.com/b/0/SmsAuthConfig https://accounts.google.com/b/0/SmsAuthConfig
- danielpal 14y agoThis is something google specifically does. And it's not something you can really do if you loose your phone (i.e you need two-factor authentication to get there to disable two-factor authentication). Plus is not something that is centralized (if you have X accounts you have to go to all X accounts and disable them), and then you need to reconfigure all X accounts. Honestly that's a lot of work. I've been using Google Authenticator for 2 years now with 7 accounts. Everytime I change phones (twice now) it's been a nightmare. Also since I travel, half the time they don't work. I am going to build Google Auth support into Authy and it will be 10 times better that the Google Authenticator App....how I wish Google would do it, but they have abandoned Google Authenticator long time ago (they didn't even bother to support retina display's).
- Firehed 14y ago> And it's not something you can really do if you loose your phone (i.e you need two-factor authentication to get there to disable two-factor authentication). Backup codes. It's not the cleanest approach in the world, but it's still an actual second authentication factor. How can you safely disable Authy if you lose your phone without risking someone else having the same ability to do so? This is a solved problem. I agree that the process of switching phones sucks, but it almost needs to in order to keep the MFA keys difficult to clone.
- 14y ago
- blibble 14y agothis Authy service really misses the point: the numeric code is redundant when you have a separate secure device with an internet connection (i.e. a phone). when the user logs in issue a push notification, which when tapped sends the code back automatically. the numeric code can be used as a fallback if the net connection is down.
- danielpal 14y agoWe tried push notifications, but they were unreliable. (people disabled them, they were delayed etc, doesn't work with bad reception). We're working on something better.
- RobertLuand 14y agoIt's nice to see them start giving users a balance between security and user experience by implementing 2FA which allows us to telesign into our accounts. I know some will claim this make things more complicated, but the slight inconvenience each time you log in is worth the confidence of knowing your info is secure. I'm hoping that more companies start to offer this awesome functionality. This should be a prerequisite to any system that wants to promote itself as being secure.