3 ms·
You can see: http://blog.authy.com/authenticator http://blog.authy.com/authenticator But in general terms: 1. Authy tokens automatically sync even if you lose
by danielpal 13y ago
You can see: http://blog.authy.com/authenticator http://blog.authy.com/authenticator
But in general terms:
1. Authy tokens automatically sync even if you lose, change or upgrade phone.
2. Ability to do encrypted backups of Google Auth tokens. Same as above, they will sync if you lose, change or upgrade phone.
3. Bluetooth: Takes the hassle out of Two-Factor Auth.
4. Automatic time sync: Always makes sure your tokens work no matter what.
5. Key Rotation: We can automatically rotate keys if masters are compromised.
6. Privacy: WE DO NOT TRACK app usage or anything like it. We don't share data with anyone. Compare it to GAuth privacy policy.
- mseebach 13y ago> 1. Authy tokens automatically sync even if you lose, change or upgrade phone. So the tokens are stored on Authy's servers? Doesn't that defeat the purpose of two-factor? How do I (or an attacker) recover my tokens if I loose my phone?
- chimeracoder 13y agoYou're correct - there are serious security concerns with Authy's product, which were pointed out on an earlier HN thread: https://news.ycombinator.com/item?id=4916983 https://news.ycombinator.com/item?id=4916983 Personally, I'd be concerned with trusting my credentials with any company unless all members of the leadership team (yes, including "nontech" people) are incredibly familiar with basic security terminology and practices. (Note that the founder is unclear when PBKDF2 and AES are being used in the product, which is concerning, because they have very different use cases and should be hard to confuse).
- sahaskatta 13y agoDoes the Bluetooth pairing functionality only work for OS X?
- ISL 13y agoWhat happens if Authy is compromised?
- cheald 13y agoMy tokens being sent to an external server that I don't control is a dealbreaker for me, sorry. I get the convenience factor, but my security relies on the absolute secrecy and control of those tokens; I'm not willing to trust those to anyone else. Any company that requires 2FA is likely to have a similar policy; leaking the keys to the kingdom to a third party which is not subject to security audits is going to be a non-starter. Bluetooth integration is a compelling feature, though.