4 ms·
Is this "condoned" by Google or does Authy just emulate the algorithm that Google uses? If they are just implementing their own version, then what secret info
by scottmp10 14y ago
Is this "condoned" by Google or does Authy just emulate the algorithm that Google uses? If they are just implementing their own version, then what secret info do they need for the algorithm?
- danielpal 14y agoBoth Authy and Google are based on open standards: Specifically: http://tools.ietf.org/html/rfc6238 http://tools.ietf.org/html/rfc6238 So you can add support as long as you support the standard. When you scan the QR Code with you camera we read a secret key and store it inside your phone securely.
- scottmp10 14y agoOk that makes sense, thanks.
- dtjohnnymonkey 14y agoI'm reading RFC 6238 and it looks like it's based on a single shared secret: > Basically, the output of the HMAC-SHA-1 calculation is truncated to > obtain user-friendly values: > > HOTP(K,C) = Truncate(HMAC-SHA-1(K,C)) > > where Truncate represents the function that can convert an HMAC-SHA-1 > value into an HOTP value. K and C represent the shared secret and > counter value; Does that mean it's formally/theoretically equivalent to simply having two separate passwords?
- danielpal 14y agoAbsolutly not. It's one secret seed but you use the time to generate different One Time Passwords every 10 seconds, which means you never reuse passwords. This would be the equivalent of having 2 passwords, one of which you change every-time you use it and it's fully random.
- dtjohnnymonkey 14y agoSo just to rephrase it to make sure I understand, it's more secure because even if the OTP is compromised, the entire system is not compromised, is that correct? However, if the original secret is compromised (K), then could an attacker easily generate OTPs?
- X-Istence 14y agoYes. Just like with a physical RSA hardware token ...
- Zikes 14y agoIt seems like the algorithm is actually fairly simple, according to the wikipedia page: http://en.wikipedia.org/wiki/Google_Authenticator http://en.wikipedia.org/wiki/Google_Authenticator
- danielpal 14y agoIt is very simple, as it should be.