11 ms·
Authy: Faster Two-Factor Authentication
- andreros 13y agoAssuming an attacker has complete control over your computer, and your phone is within bluetooth range, can he make the phone generate a token without user interaction? I was assuming the user would have to click a button on the phone or something, but I couldn't see it in the video.
- patio11 13y agoAssuming the attacker has complete control over your computer... ... the end user just lost, absent substantially more defense-in-depth on the provider side than just using TFA. TFA mostly helps you against "We lost credentials or a low-privilege session, let's prevent that from escalating to a high-privilege session." If your device is rooted, you'll eventually cough up a high-privilege session, either by passive monitoring or by something more clever like e.g. using your own computer as the MITM to ask you to provide a valid TFA to do something which really only requires a low-privilege session. Now the attacker has both factors. Game set match.
- danielpal 13y agoYeah exactly, if the attacker has complete control over the computer, the least of your worries is Bluetooth. He can steal your cookies, keylog your password/token, poison your dns and compromise your SSL Keys or simply steal a session.
- danielhunt 13y agoPossibly silly question, but how do you intend to make money from this? The mobile app is free, the desktop app is free, and once I have them installed, I don't have any more communication with you or your servers, right?
- danielpal 13y agoHi, we already do. We charge websites, banks and apps to enable two-factor auth on their sites. See https://www.authy.com/developer/pricing https://www.authy.com/developer/pricing.
- danielhunt 13y agoAh, I see, thank you. Another question: If for some reason, your company shut down tomorrow morning, what would that mean for users of your app? Would it stop working?
- michaelmior 13y agoYou could just disable two-factor auth and continue password-only until you find an alternative provider.
- danielhunt 13y agomichael: Wouldn't I need to do that for every provider that Authy is wrapping?
- danielpal 13y agoNo the app doesn't talk to Authy servers. It's completely independent. You could just keep using it.
- danielpal 13y agoHi, I'm Daniel, Authy Founder. We've worked almost 18 months on this product, it's surreal to finally see it out. Anyway, you can read more about why we did this here: http://blog.authy.com/thefuture http://blog.authy.com/thefuture
- dfamorato 13y agoHello, This looks awesome. When could we expect a Windows 7/8 app ? Congrats
- danielpal 13y agoProbably. At this point we are testings things out and want to move as fast as possible. We want to make Two-Factor Authentication completely transparent, and we'll be launching other exciting things to see how they work in the real world. Once we have the experience nailed out, we'll ported to other platforms.
- ChrisClark 13y agoI hope you are planning a Linux release too. So many companies leave us out, even though we're even more willing to work past bugs and set things up correctly.
- nodata 13y agoPresumably their is an HTML5 app available?
- canthonytucci 13y agoQuite handsome and useful looking. Good job! Just a quick question, under security it says: >>". Authy Bluetooth will only talk to pre-approved computers and all messages are encrypted." Just wondering if you can speak to what sort of encryption and safeguards you've got going on here. The docs cover how the tokens are created, but not the communication between phone and mac. Seems like an awesome thing but I wouldn't feel comfortable using it for work without knowing a bit more.
- jamestkirk 13y agoI like the design, the website, the phone app, etc. However, the desktop app does not feel right. Maybe I am missing something. - Are the HMAC keys stored or synced to the desktop? - Is there a password protection similar to the keychain to access these passwords? If my desktop is hacked into and a key logger has my password as they usually do, it will now also be able to copy these one time passwords at will and use it frequently to log into my account. I would prefer to use my laptop and a separate phone for my OTPs. I like the Google Authenticator app as it does nothing more than generate OTPs, no sync to server, etc..
- danielpal 13y agoHey James, "- Are the HMAC keys stored or synced to the desktop? No, nothing is stored in the desktop. Everything remains on your phone." "- Is there a password protection similar to the keychain to access these passwords? We store the pair phone details on the keychain. But this is only the phone bluetooth id etc." "If my desktop is hacked into and a key logger has my password as they usually do, it will now also be able to copy these one time passwords at will and use it frequently to log into my account." No, again nothing is stored on your computer.
- chilgart 13y agoPrevious discussion: https://news.ycombinator.com/item?id=4916983 https://news.ycombinator.com/item?id=4916983
- krrrh 13y agoI've been using authy for months since it handles 2-factor auth for dnsimple. Just saw the update that supports bluetooth come in on the App Store this morning. Congrats to the team on this big release! One thing that's nice about seeing a modern two-factor auth app with a solid business model behind it, is that Google seems to have abondoned their Authenticator app - no releases since 2011, doesn't yet work properly on iOS 7.
- iosdeveloper 13y agoAll this nonsense about applications not working on iOS 7 is beginning to grind my gears. Developers aren't currently allowed to submit their apps for iOS 7. The beta is still in early stages. It'll change. A lot. Chances are that if you're complaining about applications not working on iOS 7 you shouldn't have the beta build on your phone in the first place.
- sehrope 13y ago> ... Google seems to have abondoned their Authenticator app What exactly would you like improved in Google Authenticator? It's not like it does anything special, it just scans TOTP QR codes and generates TOTP codes, and it does both of those pretty well. I actually like the fact that it has no additional functionality. Everything stays on the device itself and is not sent to Google or saved "to the cloud"[1]. The only thing I think that would be an improvement would be for it fit the entire iPhone 5 screen (it's letter boxed) but that doesn't really bother me that much. [1]: I've heard it gets backed up to iCloud but I don't use that.
- harshreality 13y agoRe-arranging the damned accounts, that's what. It's the highest starred bug on the google code issues page, and they're ignoring it.
- karlshea 13y agoI would like for the "Edit" button to work.
- M4v3R 13y agoI've tried to setup Authy using bluetooth, but I failed :(. Mac OSX 10.8 on Macbook Air, iOS 7 on iPhone 4S. It did ask me on the phone to give access for Bluetooth to Authy, which I approved. But On the desktop app there is an empty list of devices and nothing else shows on my phone's screen.
- danielpal 13y agoHi Maver, unfortunately is likely your Mac doesn't have a Bluetooth 4.0 chip and Apple doesn't have an API on the iPhone to talk via 2.0. It will work on an Android though.
- M4v3R 13y agoIt's a 2012 Macbook Air, so it should have Bluetooth 4.0 chip. Any other thoughts? Edit: For the reference - I went to Authy support chat room, and it seems that even though I have a 2012 Mac, system profiler says that I have LMP version 4, which means Bluetooth 2.1. That's why it doesn't work. The support was top notch though.
- jroll 13y agoI've met Daniel and implemented Authy on a web site before. It was super simple, and it's super simple from the user perspective as well. This update makes it even easier. Congrats on this launch!
- stephanos2k 13y agoA word about the website: The video is really great, enjoyable and fresh (very positive vibe, extremely well executed). But I'd rather see something different than a (blurry) image of the founder looking somewhere off screen. I mean it's "personal", I get it - but this can be improved. While this might sound superficial, it's the first thing that came to my mind ...
- Shank 13y agoI love the concept of this, but I'm out of the use case for the time being (Windows / Linux user). The other key annoyance is that none of my desktop computers have bluetooth, because I built them for gaming, not wireless peripherals. That being said, you probably already thought about using a centralized server or other methods of communication. Either it'll kill battery, or require some intermediary server - which would probably need two-factor authentication to authenticate. Though, overall, I love this idea a lot more than backing up my Google Authenticator app with Titanium Backup and restoring it each time I change phones/ROMs.
- dspillett 13y ago> none of my desktop computers have bluetooth USB based bluetooth dongles are dirt cheap, so this should not be an expensive or otherwise overly inconvenient issue to resolve.
- blakeshall 13y agoI think he is saying that it isn't worth it/ too inconvenient to go out and get a bluetooth dongle just for this app.
- fiskfiskfisk 13y agoCould be a possible way of branding / selling "The Authy Solution". A small BT dongle and a year of pre-paid subscription in a bundle.
- LukeHoersten 13y agoI've been using Authy for all my accounts that support 2-factor auth for a while now and it's awesome! Google's app is crap and Authy's app is sexy and fast. It really kinda annoys me now when websites don't support 2-factor auth. It's easy enough for them with the Authy API and adds so much for me. More and more I see major websites having their hashed password databases stolen (just search HN). The situation's only getting worse.
- LukeHoersten 13y agoStripe needs a logo in the Authy app. Also someone needs to force NameCheap to get 2-factor auth.
- pilif 13y agoI really don't like giving out my phone number to a small company with no apparent revenue model, no matter what they are saying they are going to do or not do with that number. Sorry for being cynical, but judging from all these services coming and going all over the place, any of the following is going to happen within a year: 1) authy gets bought by $COMPANY. With some likelihood it's not a company I want to have my phone number. 2) authy runs out of money and needs a revenue stream. Thus it changes the TOS and starts selling phone numbers. 3) authy shuts down. Who knows what's going to happen with my phone number then. No. I'd rather use any other HOTP app that doesn't require any personal data (which is one of the basic ideas behind HOTP). Authentication and my phone number are the two things you have to really prove you have got your act together before I trust you with them.
- grimtrigger 13y agoMaybe its just me, but I never pick up numbers I don't have in my phone book. I just let them leave a voice mail or assume its not important. Never quite understood the HN fetishism about keeping emails and phone numbers private. I hand them out like candy and haven't felt a price for it.
- pilif 13y agoCellphone numbers can very easily be abused to steal money (premium SMS), to steal my identity, to spam me in the middle of the night, to pull me out of the "zone" by calling me/messaging me during work hours, to track my location while roaming and probably a lot more stuff that's not currently apparent to me. Also, my phone number is known to some identity providers I trust. If they sent me an SMS asking me to click a link, I might be inclined to follow that link. This is quite right despite the sender being very easily spoofable because nobody but these identity providers know my phone number. No. I'd rather be very careful with that number.
- hillbillyjack 13y agoIt is ridiculous to think that your number is private and even moreso to think that someone can steal money with just your cellphone number. Of course you could be phished or tricked by SMS but to expect your number to be private is to expect everyone ever who you give the number to go to extreme to keep it private as well. If you ever gave your number to someone who downloaded an app which has permission to contacts your number is no longer private (Facebook has taken big advantage of this, I'm sure there are less than reliable apps that took bigger advantage).
- Osmium 13y agoHas anyone here used both Authy and Duo Mobile and would like to recommend one over the other?
- bitsweet 13y agohaven't used Duo Mobile but Authy has been great for us
- jmj42 13y agoWe use Duo for various things around here. Love it. It's much more feature complete than Authy (which, unfortunately will not work for any of our use cases). More importantly, the company is run by well know and respected security researchers (Dug Song and Jon Oberheide).
- segmondy 13y agoI highly recommend Duo Security, the guys behind have a solid track record in the industry. They started it first with phones. Prior to that everyone else was using expensive RSA like secureid tokens that take more to deploy. Read the man page for ssh and you see Dug's name in there. Jon has a solid track record on the mobile side. They just developed Rekey to fix the Android master key vulnerability issue about 2 weeks ago.
- rdl 13y agoIs it just copying a totp auth token over bt to the desktop app (which would be most compatible on the backed) or doing something different than totp (hotp or some kind of PK thing)?
- danielpal 13y agoIt's just copying the current TOTP token over Bluetooth to your Mac. Nothing fancy. Simple yet very useful.
- Nodex 13y agoand for those of us who are sane and don't own a mac ?
- sandyarmstrong 13y agoVideo doesn't play in Firefox 23 on Mac. Watched in Chrome though, great stuff! Looking forward to trying it out.
- dcu 13y agoTo know if your mac is support before installing the app run this command: system_profiler -detailLevel full SPBluetoothDataType | grep "LMP Version" it should be >= 6
- karlshea 13y agoSo this won't work with a 2011 MacBook Pro. Which I don't consider that old. Sure would be nice if they mentioned that anywhere at all.
- nathas 13y agoAs a dev I love the idea that there's 3rd party to handle the finer points of my 2-factor auth. As an end user, I don't want to touch your app with a 10ft pole since you're an untrusted/unvetted source holding on to some very important tokens.
- Osmium 13y agoAs long as they don't hold onto your passwords too, then it's not too bad right? A compromise for the sake of convenience, to be sure, but even in the worst case – if all Authy tokens are compromised – people still shouldn't have access to your accounts. For me at least (personal use, not company use) that's a worthwhile compromise: I doubt any attacker could get my main password in the time it'd take for me to change it in the unlikely event that Authy be compromised.
- tyilo 13y agoWhy doesn't this work with iPhone 4 or below? Edit: According to this document iPhone 4 support all Bluetooth profiles: http://support.apple.com/kb/ht3647 http://support.apple.com/kb/ht3647
- M4v3R 13y agoIt doesn't support Bluetooth 4.0 which is needed here.
- peterwwillis 13y agoTheir API URL gets an "F" rating from Qualys' SSL Server Test, due to insecure cipher suites. https://www.ssllabs.com/ssltest/analyze.html?d=api.authy.com https://www.ssllabs.com/ssltest/analyze.html?d=api.authy.com Specifically, an anonymous unsigned cipher is being allowed, and a victim browser can probably be forced to use it by an attacker. From http://www.ietf.org/rfc/rfc4492.txt http://www.ietf.org/rfc/rfc4492.txt: Note that the anonymous key exchange algorithm does not provide authentication of the server or the client. Like other anonymous TLS key exchanges, it is subject to man-in-the-middle attacks. Implementations of this algorithm SHOULD provide authentication by other means.
- kin3tic 13y agoI'm sorry. Authy is trying to push something that NEVER should have been a "startup". How the fuck is this a service ANYONE is going to pay for when it's trivial to set up an OTOP server and use the Google Auth app that everyone who uses TFA is already going to have installed. This monkey patched TFA solution is not "the future" of logins, by a long shot. Not even in the short term. Things like Persona are going to beat Authy before Authy ever sees a non-negligible amount of revenue. At least Coinbase doesn't FORCE me to use them anymore. -- Also, since I forgot. IF YOU SYNC MFA KEYS, YOU'RE ONLY COMPLETELY DEFEATING THE POINT.
- porker 13y agoThe Android app is over 9MB and can't be moved to the SD card. Too large for me, uninstalled.
- sneak 13y agoWorth noting: The Google Authenticator app lets _anyone_ generate a shared secret seed that can be added to the app (which, afaict, does not communicate with the network at all). I'm confused as to why you'd need a third-party for this. Example of how to generate a seed and share it with an ssh server: https://scottlinux.com/2013/06/02/use-google-authenticator-for-two-factor-ssh-authentication-in-linux/ https://scottlinux.com/2013/06/02/use-google-authenticator-f...
- jlgreco 13y agoThe Google Authenticator app is great. I recently got (TOTP) 2-factor auth for an IRC bot going with Google Authenticator; took about 5 minutes to code it up and set it up. It doesn't use any sort of 3rd party service, just the application running locally on my phone. TOTP/HOTP is dead simple and, with the open source Google Authenticator app, great for the end user.
- porges 13y agoThere is one terrible thing which is that adding an account for a different service but with the same email will overwrite any account with the same email without prompting you. e.g. setting up 2-factor with MS with the same email you use for Google will overwrite the Google one unless you rename it.
- deleted 13y ago[deleted]
- FuzzyDunlop 13y ago
- niftylettuce 13y agohave you guys seen Prove? https://getprove.com https://getprove.com
- deleted 13y ago[deleted]
- P3KLb82AhB 13y agoit's not "something you have" if you know the seed to seed it yourself, it's just an obfuscated "something you know". A real "something you have" in a 2 factor auth. would be a real token that has provisions to wipe itself on detecting it's being opened.