8 ms·
Not against 2-factor, but now I have to install yet another application of questionable origin to trust my access to. Why not just use Google Authenticator?
by Koldark 14y ago
Not against 2-factor, but now I have to install yet another application of questionable origin to trust my access to. Why not just use Google Authenticator?
- gqdev 14y agoAh thats my problem .. only if authy can integrate and let us add what we already have on Google authenticator . i will dump Google auth.
- danielpal 14y agoYou will be very pleasently surprised very soon. We will support google authenticator and it'll be awesome...I can't wait to share - I wish apple was quicker approving apps - If you want a version sooner I can share via testflight if you wish, that way you can also help us make it better. E-mail me at d@authy.com and I'll make it happen.
- ChrisClark 14y agoDoes this mean you have Google Authenticator support in the Android app already, since there aren't any approval times? Or are you specifically delaying updating the Android app to wait for Apple? That's not fun. :(
- rdl 14y ago"Google Authenticator" actually is any RFC 4226/6238 compatible HOTP/TOTP client, actually, including hardware dongles or phone apps or whatever. I'm not sure if Authy is using the same protocol. What really surprises me is that Twitter doesn't support any OTP solution; Twitter accounts getting hacked is a fairly common thing (@mat), and there's basically no solution to it now. Facebook doesn't use OTP but uses the information they have to do probably the best knowledge based authentication on the Internet (plus, shows IPs in use, and does geo-IP based fraud prevention, but Twitter doesn't really know anything secret about you. I've bugged Twitter people about this several times.
- jgrahamc 14y agoAuthy is based on the same standards.
- omh 14y agoSo I can install just the Google app and enter my Authy codes there, and vice versa?
- jgrahamc 14y agoMy understanding is that Authy uses a key that is twice the length of the Google Authenticator key and so they are not compatible. Also, there are other things that Authy does way better than Google Authenticator: 1. If you change phones you have to reconfigure all your accounts that are using Google Authenticator. With Authy it just works when you install the Authy app on the new phone. 2. Authy fixes time sync problems between your phone and UTC in the background so you do not have to worry. 3. And if you lose your phone with Google Authenticator there's no simple way to revoke access to all your accounts. With Authy there is. 4. Authy has a way to revoke tokens across all devices. If (like what happened to RSA) the private information were stolen from Authy they can invalidate all the tokens and securely reissue new ones.
- marshray 14y agoAccording to https://www.authy.com/help/faq https://www.authy.com/help/faq, it looks like they're using http://tools.ietf.org/html/rfc4226 http://tools.ietf.org/html/rfc4226 HOTP with some version of SHA-2 and a 256 bit seed. The suggested default for HOTP/TOTP is SHA-1 with a 160 bit seed and that's what most systems seem to use.
- rdl 14y ago#1 is the biggest problem with Google Authenticator today (as well as inconsistent use of Authenticator across various Google properties, but that wouldn't matter to a third party site). AWS supports the same system in a less brain-dead way, treating the authentication as a separate feature per account profile, and letting you re-enroll a new token and delete the old one. I'm pretty sure this is a Google Account problem, not a Google Authenticator problem. (AWS IAM is actually a pretty awesome product, but not very well documented, and from what I've seen of AWS users, not being correctly used to even 5% of its potential by most users.) It's obviously more secure to make changes to the authentication system harder than just "any single valid login from any device lets me reset authentication requirements for future logins", though. The real problem is being able to get a one-time authenticated login, use that session to add a new "always let me log in" credential, and leave everything else as-is. The legitimate owner then has no reason to be suspicious, and you can continue to subversively use the account. It's almost better when the legit owner is forced out of his account on a change like that, as he can then contact Google's excellent customer support (...) to resolve the issue. Of course, Google exposes themselves to THAT with application specific passwords, which are neither application-specific nor otherwise limited, and can be created easily once you log in.