3 ms·
DuoSec's iOS app replaced the never-updated Google Authenticator app for me after they added support for third-party token generation. It even works with QR-cod
by flyt 13y ago
DuoSec's iOS app replaced the never-updated Google Authenticator app for me after they added support for third-party token generation. It even works with QR-code scanning, just like the Google App.
The advantage here is obvious: it's an app that is a primary business concern for a security-focused company. It's unlikely it'll go out of date as long as Duo is around.
https://blog.duosecurity.com/2012/11/announcing-two-factor-authenticaton-for-third-party-accounts/ https://blog.duosecurity.com/2012/11/announcing-two-factor-a...
- stock_toaster 13y agoI use Duo as well. The only thing I miss is a countdown timer.
- mseebach 13y agoNever mind that the Google Authenticator app does get updated, why would it be suspect that it wasn't? Since when did it become a mark of quality that something changes constantly? It's sole purpose in life is to run a well-defined, never-changing calculation and display a 6 digit number on the screen. Not changing is absolutely preferred here.
- kalleboo 13y agoIt's not confidence-inspiring when an app you use is missing both retina graphics and iPhone 5 support.
- rdl 13y agoAnd if a security bug did pop up, I'd sure rather bet on Duo, Authy, etc. fixing their app quickly than Google doing so, given that I don't think anyone is actually on the Authenticator team. I'm sure someone within Google would consider it a high priority to fix, but it wouldn't be as easy for them to quickly address something.
- icebraining 13y agoWhat kind of security bug? The only thing the program should need is a secure place to store the tokens - which I expect is provided by Android, no? - and to read the time from the system. It shouldn't be exposed to anything else.
- rdl 13y agoSome theoretical bug. It happens, even in simple stuff. More likely would be e.g. a platform finally getting a halfway decent way to store secrets (which iOS got with the 3GS and even better with iOS 5/6/7), and which Android as a whole still lacks (specific manufacturers are adding it, like Samsung, but it's not a standard due to Google being insane). I don't see a zombie client rapidly adopting those new storage technologies.
- andreif 13y agoI have only used it on iPhone 5 without any problem, so I am not sure what you mean here. I only use it for a few seconds to read the number and do not really understand how retina graphics would help you.
- flyt 13y agoNot updating an extremely simple app with Retina support (which they've had at least three years to implement since the iPhone 4's release) would seem to indicate that it's not under any active development.
- mseebach 13y agoIt doesn't need to be under active development to perform its job flawlessly.
- rdl 13y agoThe Duo app is really nice. I was really happy to find out you could use it without their (fairly expensive) service; it's essentially a drop-in replacement for the Google Authenticator app. I've still been using both, though. The thing I dislike most is when sites don't allow you to link your own OATH credential (i.e. a hardware token); I don't consider any of the cellphone apps or services to be as secure as the hardware token, and there are nice ways to use the hardware tokens for role accounts (locking the physical token in a safe, or leaving it in the custody of a third party without direct access to the account, like a CFO). The ideal implementation of OATH/2FA for a site allows users to specify their own, get the QR code, or get a text code. Coinbase, for instance, only shows the QR code; I can't either use my own hardware token or back up the character string (which I feel I can do safely) to let me re-generate the token. I generally like having >1 device with my OATH credentials for any given account, particularly if the device is needed to change security settings later. It's awesome that they support 2FA, but doing better would be better.