3 ms·
If you use Google Authenticator App this is true. If you use Authy App without backups, this is also true. But if you enable Authy Backups then you will always
by danielpal 14y ago
If you use Google Authenticator App this is true. If you use Authy App without backups, this is also true. But if you enable Authy Backups then you will always be able to get your accounts back, no matter what.
- chimeracoder 14y agoThis isn't true on Android - if you've done a full backup, you can restore Google Authenticator without disabling and re-enabling the service.
- danielpal 14y agoThis doesn't work the way you think it does. The app itself it's backed up by Android OS, who know were, with every single account without any encryption.
- chimeracoder 14y agoI don't know what you're talking about - the kind of backup I'm talking about isn't a built-in Android feature, as far as I'm aware. There's no "who knows where" - if you back it up, you know where you're putting that backup. Furthermore, Titanium Backup (and the like) provide you with the option to encrypt your backups. Finally, Android ICS and later also provides full-disk encryption of the application storage area (which iOS does not).
- rdl 14y agoI'm not sure what you mean on the last point -- iOS user storage is all encrypted with a key inside the device since the 3GS, and meaningfully since the 4S, which is unlocked in hardware whenever you enter your passcode. Everything is actually encrypted (except parts of the kernel, I think, but the bootloader is signed and does signature checks), but there are 4 classes of files, ranging from always encrypted to encrypted just with a key also stored on disk. No Android devices (as far as I know) have hardware data protection; there is software full-disk encryption, but with that, you can extract the encrypted image and then brute force it at your leisure offline (or in EC2, FPGA cloud, etc.) (the S3 might or might not, but it's not officially supported in the APIs last time I checked) It's a meaningful distinction because you have to enter passcodes to unlock ~frequently on a small screen, so they tend to be shorter than even screen saver passwords on desktops. As far as I know, blackberry is still the only mobile OS which does full device encryption with a user key natively with platform security, but the parts of iOS which are not encrypted (some OS parts and the application binaries) aren't particularly security sensitive. It would be better if they had encryption as well -- I'm not sure if there is any protection applied to them for integrity. I could be wrong; I haven't checked on the details recently, especially on Android, although I need to do so in the next few weeks for a talk at RSA 2013. I'm still basically amazed at how good a job Apple did on iOS security on the 3GS and later. I wish Google would step their game up and implement NSA SE Android features and some hardware data protection (just buy RIM if you have to!).
- mannkind 14y agoI wish it worked that way on iOS; I'm not sure what Google is doing with the app that prevents it ... other apps+accounts work just fine after restoring from backup.
- X-Istence 14y agoIt works without issues for me when doing it locally using iTunes, not sure what would be different about iCloud based backups ...
- bonzoesc 14y agoiCloud backups don't include all keychain items, while iTunes encrypted backups do: https://ssl.apple.com/ipad/business/docs/iOS_Security_May12.pdf https://ssl.apple.com/ipad/business/docs/iOS_Security_May12.... page 12.