9 ms·
Warning: Google Authenticator upgrade loses all accounts
I upgraded Google Authenticator to the latest version this evening on my iPhone. It lost all my accounts.
DO NOT UPGRADE Google Authenticator or you'll have a really bad day.
People on Twitter are starting to complain:
https://twitter.com/search?q=google%20authenticator&src=typd
- michaelrbock 13y agoDon't upgrade! I just had this unpleasant experience and warned everyone about 15 minutes ago: https://news.ycombinator.com/item?id=6325745 https://news.ycombinator.com/item?id=6325745
- markwakeford 13y agoUse HDE OTP, its a better looking app anyway.
- drivebyacct2 13y agoHow did 3 minutes of dogfooding not catch this?
- deleted 13y ago[deleted]
- PLejeck 13y agoI actually just switched to Duo Mobile earlier today because of iOS 7 issues with Authenticator; this just cements my decision to switch. Edit: oddly iOS 7 hasn't autoinstalled this yet.
- elithrar 13y ago> I actually just switched to Duo Mobile earlier today because of iOS 7 issues with Authenticator; this just cements my decision to switch. I moved all my non-critical stuff over (to test it out), saw the Google Authenticator update, and then had to go and reconfigure those accounts anyway. I highly recommend making sure your backup phone number is updated and verified and/or you have backup codes prepped.
- PLejeck 13y agoLuckily I was still logged into all my accounts (my Dropbox account suddenly dropped from Google's app like a week ago) Duo seems to be quite nice, I doubt I'll end up using the backup codes. Incidentally, GitHub has it right - "download a text file of your backup codes" is much easier than "print this page nad hope you don't lose it"; I find find(1) outpaces my frantic drawer-emptying.
- bdcravens 13y agooddly iOS 7 hasn't autoinstalled this yet. That is odd - it installed several hours ago for me.
- clarkm 13y agoFor those looking for Google Authenticator alternatives, I recommend either Duo Mobile from Duo Security or Authy. I ditched Google Authenticator a while ago and haven't missed it one bit -- having a single app manage my two-factor tokens / keys is much more convenient.
- nwh 13y agoEdited: Authy requires a mobile number and a remote server to store your tokens though.
- PLejeck 13y agoThis is not at all true. Both are generating your tokens clientside with no internet connection. Try disabling internet access, it should work. As for the mobile number, I didn't have to type that into Duo Mobile when I installed?
- nwh 13y agoYou certainly do for Authy, I was apparently wrong about Duo. http://i.imgur.com/dY1zWUe.png http://i.imgur.com/dY1zWUe.png
- beedogs 13y agoSeriously. What's the difference between this and just setting up a webcam pointed at all your SecurID tokens?
- elithrar 13y ago> Both require your mobile number and for a remote service to store all of your tokens though.. Duo does not, for the record. Download and go.
- nwh 13y agoI seem to have recalled that one wrong then, or they've changed their service since I last saw it.
- calvin 13y agoIf you offer two-factor authentication for your website, be prepared for a surge in support requests today. When I talked to one of my providers on the phone, they stated they are already getting a surge in calls because of this app update.
- dknecht 13y agoThe Authy app is great and supports Google, Dropbox, CloudFlare, Amazon…
- orand 13y agoIf they had released this two weeks later, iOS 7's auto-update feature would have bricked everyone's accounts. Google Auth 2.0 redefines two-factor auth: something you know + something you DON'T have. Their entire purpose in life is this second part and they completely and absolutely botched it. I can't believe this passed testing at both Google and Apple. There wasn't even a warning in the release notes.
- bobbles 13y ago>There wasn't even a warning in the release notes Do you think they would have released it if they knew about it?
- orand 13y agoProbably not, but I use several apps that put a big "BACK UP YOUR APP DATA BEFORE UPGRADING" in their upgrade release notes. I'm just shocked they didn't know about it because the upgrade process wasn't even in their test plan.
- natch 13y agoThis isn't addressing the (obviously rhetorical) question of whether they knew in advance, but now that they do know, fwiw: They have the ability to yank the updated version any time, 24/7, at a moment's notice, until a fix is available. They also have the ability to update the release notes after the fact.
- thrownawaaay 13y agoThey have the ability to yank the updated version any time, 24/7, at a moment's notice, until a fix is available. Not when iTunes Connect is down for maintenance, they don't. Worst possible timing.
- derefr 13y agoI think Google's thinking on this is that 2FA tokens are definitely "one of those things you don't want stored in an subpoenable manner by your Cloud provider." If your 2FA token is synced to iCloud, for example, then it's no longer something you have--it's something else you know (your iCloud username+password.) "Something you Have"-type tokens provide security basically because they're immune to rubber-hose cryptanalysis: if you really just don't have the key to a safe, nothing an attacker does can make you give it to them. As such, tokens are also the factor that protect you from contempt-of-court charges if you're compelled to provide it. (Though they can then ask you "who does have a key?"; if this is an accomplice, it's best if they live in a separate country, and hopefully one which doesn't like the US very much.)
- pshc 13y agoThanks for the heads-up all! Looking forward to actually being able to distinguish Authenticator accounts on iOS 7.
- chime 13y agoEvery time I upgraded to a new iOS 7 beta, it wiped my Google Authenticator account tokens. It wasn't a big deal with Google or Dropbox because both allow me to move. But I can't log in to my CampBX account anymore. I tried Authy today after another comment here on HN and it's been working so far.
- PLejeck 13y agoI'm just gonna point out that the previous update was somewhere around 2 years ago, and it's just now getting retina, so we should be glad there's even this much.
- bruceboughton 13y agoYeah, now I can view my missing one time codes in retina, edge to edge quality. Yay!
- bruceboughton 13y agoFuck you, Google. Fuck you.
- victorlin 13y agoShit, I am fucked by Google as well ... :(
- noveltyaccount 13y agoWhen I add sites to Authenticator, I take a screenshot of the QR code and tuck it away in an encrypted document (OneNote for the record, which uses uses AES to encrypt).
- skeletonjelly 13y agoHave you tested this? Are the barcodes not time pertinent?
- markwakeford 13y agootpauth://totp/johndoe@google.com?secret=SECRETKEY1234567
- markbao 13y ago(I've studied two-factor authentication using HOTP and TOTP, and built a node.js implementation of it.) The QR codes simply divulge a URI with the secret key for generating tokens. They look like: otpauth://totp/[keyname]?secret=[secretkey] The secret key is used in the app in conjunction with a moving factor (usually 30-second intervals of time) to generate a numerical hash of sorts for that interval of time, which is then truncated to 6 characters. The QR code itself doesn't have any sort of time limit on them; they only serve to transmit the secret key.
- noveltyaccount 13y agoThis. I scanned one QR code with a regular QR code reader and came to the same conclusion... I haven't actually tested it though. :-/
- markwakeford 13y agofine, outdo me haha. Saving the Key is useful with AWS MFA because if some reason you loose your MFA Virtual Key (app updates and you loose the key) you have to contact AWS to have it reset, Can't just do it yourself.
- skeletonjelly 13y ago
- castis 13y agoMan, someone is going to have a really really bad day tomorrow.
- bound008 13y agoThis was a perfectly functional app except that it didn't look like google+. I would recommend switching to authy (YC) bc their Bluetooth 4.0 LE implementation is awesome: https://www.authy.com/thefuture#pairing https://www.authy.com/thefuture#pairing
- guiambros 13y agoAuthy (YC W12, [1]) is a nice replacement for the GA app. Besides being more stable, it has also the "benefit" of allowing you to back up your keys, and recover in the case of a lost phone or deleted app. Thankfully, backing up is entirely optional, and turned off by default. While they claim backups are encrypted with PBKDF2 [3], I still would never ever use something that sends my tokens to a remote server, as it'd defeat the purpose of 2FA in the first place. Still, I can see the use for casual users that care enough to have 2FA, but not that much to worry about tokens being stolen and decrypted from Authy.. Past discussions on HN here [2], [3], [4]. [1] https://www.authy.com/thefuture https://www.authy.com/thefuture [2] https://news.ycombinator.com/item?id=6133648 https://news.ycombinator.com/item?id=6133648 [3] https://news.ycombinator.com/item?id=4916983 https://news.ycombinator.com/item?id=4916983 [4] https://news.ycombinator.com/item?id=4330050 https://news.ycombinator.com/item?id=4330050
- cdman 13y agoYou had me until "backups are encrypted with PBKDF2". PBKDF2 is not encryption, it is a Key Derivation Function (it says so right in the name - KDF). Given that one of the developers is claiming that they are "encrypting" using PBKDF2 (which is in the same category as claiming that they are encrypting using MD5!), dissuades me from ever using it or recommending it.
- kibibu 13y agoI may be totally wrong, but isn't PBKDF2 useful exactly as a way to generate an encryption key from a password?
- mahyarm 13y agoThis is why you keep backups of your TOTP authenticator keys. I was really put off by 2 factor until I figured a way to do a backup. Authenticator URLS look like this: otpauth://totp/KeyNameHere?secret=SECRECTKEYSTRINGHERE You can save it in some passworded zip archive somewhere or print it out. If you print them I suggest printing them with QR codes to aid in recovery speed. You can easily generate QR codes by putting the text URLs into a QR code generator. If you just have a QR code, use a general QR code scanning app to extract the string. Also the new google authenticator version has a %100 repo crash bug when you scan two QR codes in a row on iOS 7 phones.
- veidr 13y agoWhat does it mean that it 'loses all accounts'? I use two factor auth but not this app, so I am not sure why people are going to have such a bad day...
- kibibu 13y agoYou add your Google (and potentially other) accounts in the app - then you need to open the app to log in to your account. The app is "forgetting" and no longer displaying the accounts you add, such that you open Authenticator and it's empty. You can no longer log in to your Google account without one of the 10 printed one-time access codes you made when you first set it up.
- elithrar 13y ago> You can no longer log in to your Google account without one of the 10 printed one-time access codes you made when you first set it up. * or a backup phone number that's been verified (i.e. send a verification code and confirmed).
- Tichy 13y agoHm, the point of authenticator is to not use the phone, because phjone numbers may be more vulnerable. wasn't there a case of social hacking where the telco forwarded to hacker's phone?
- tjbiddle 13y agoJust in time for Github to add 2FA.
- bluesmoon 13y agoChris Messina has a solution: https://twitter.com/chrismessina/status/375118991280205824 https://twitter.com/chrismessina/status/375118991280205824
- evilduck 13y agoThat's only good for Google accounts. Dropbox and others aren't reset as easily.
- seanieb 13y agoDropbox has the option to add a backup SMS phone number in addition to offline TOTP code. Here are some other steps you can follow if your Google Auth app got wiped: - https://www.dropbox.com/help/364/ https://www.dropbox.com/help/364/
- superuser2 13y agoDropbox gave you a code when you turned on 2FA and told you to keep it safe. You can also recover your Dropbox account from any connected computer. It'll log you in on the web console without a password or 2FA.
- drewschrauf 13y agoI used my Pebble watch for TFA. You have to compile the app yourself but it's pretty easy. https://github.com/aaronpk/pebble-authenticator https://github.com/aaronpk/pebble-authenticator
- thrownawaaay 13y agoWhat an absolutely awesome time for iTunes Connect to be down for maintenance.
- CamperBob2 13y agoAlmost as if Apple is twisting the knife.
- devx 13y agoThis is the sort of "nightmare scenario" I'm afraid of, and why I'm still not using 2FA. I'd rather risk having only a weaker password, than risking losing my accounts for good. You can't get back into your accounts if something like this happens, right?
- lalc 13y agoTo get back into your account you're provided backup codes that you're supposed to store somewhere safe. Otherwise, if your phone were stolen you'd be out of luck, yes.
- arjie 13y agoI was about to respond "Haha, no big deal, I use my Google Voice number". The flaw in this was readily apparent.
- icecreampain 13y agoI cannot fathom why people still rely on Google for their core business needs. At my last place of work I built an SMS system to be used as the second factor in the intranet login. I _could_ have used a 3rd party 2FA, but the most _logical_ reason to have our own system was ... well.. we didn't want to rely on anyone except ourselves. Didn't take me long and the most difficult part was finding enough USB-connected phones to be used as SMS senders. Guess what? The system still works today, why Google is broken.
- enscr 13y agoOur company started writing their own verilog & soon we'll have chips for our custom designed smartphones. Yay ! Till then, we are stuck with silly can phones :(
- mavhc 13y agoYou have your own mobile network? Sweet. I just use this open source thing that doesn't rely on anyone else
- crumblan 13y ago> didn't want to rely on anyone except ourselves. And the remarkably secure telecom system, of course. Google's style of 2FA is IMO technologically superior in that there is no communication after the initial seed. It also appears to be somewhat standardized -- see others posting about Authy. You could have your own handwritten program running the algorithm if you wanted to be independent. The real screw up on Google's part is not instructing users to have an encrypted backup of their 2FA data.
- jordanthoms 13y agoWell, they do instruct people to print backup codes.
- ibejoeb 13y agoTo disable auto-update on recent Android: Play Store -> Search "Authenticator" -> Select "Google Authenticator" -> Press "Menu" -> Deselect "Auto-update"
- jordanthoms 13y agoI don't think this is happening on Android, seems to be an issue with an iOS update.
- jared314 13y agoI think this is a good reminder to use the auto-update feature wisely, on all platforms.
- darklajid 13y agoNot an iPhone user, but I wonder if you could access the key data manually and restore it afterwards? On Android that's possible (if you have root....) by accessing the key database (sqlite in that case). I did that to duplicate the keys from my handset to my tablet.
- rem1313 13y agoYes, if you have synced with iTunes before the update. If that's the case you have to delete the updated app from the phone, connect phone to iTunes (do not sync or transfer purchases) and copy over the old app from iTunes to phone and it will restore the old version + app data.
- 3dinger 13y agodidn't work for me - app was restored but not data
- kalmi10 13y agoRestoring from an iTunes backup should restore both the old version and the app data.
- tlrobinson 13y agoRelated: will iOS 7 let you turn off the auto-update feature?
- JoshGlazebrook 13y agoThankfully yes it does.
- deleted 13y ago[deleted]
- imkevinxu 13y agoQuick solution for Google 2-step auth (do it QUICK so you don't lose access to your Gmail) 1) Go to this page https://accounts.google.com/b/0/SmsAuthSettings https://accounts.google.com/b/0/SmsAuthSettings 2) Click "Move to a different phone" 3) Re-setup your Google Authenticator Note: the 10 printed one-time access codes and all the application-specific passwords will still work after this "reset". But you still need to reset your other accounts that use the Google Authenticator
- bdcravens 13y agoI use Google Authenticator on the 2 AWS accounts I manage. Fortunately, at least on the first, the master account didn't have 2FA on it, so took about 60 seconds to reset it. (remove device, then readd) However, most wouldn't have the master account (the entire purpose of IAM). I suspect that Google may have an update that restores accounts. I know when I've restored my phone, losing all apps, when I reinstalled an app months later, the settings were still there. Obviously the settings are stored in a file somewhere, so my hope is that this is how Authenticator works, and this buggy release just failed to properly open that file. Of course, not everyone can wait and have to reset like I did.
- 0x0 13y agoHappened to me as well, fortunately I disabled 2FA on my Dropbox account before the upgrade, thanks to this warning!
- victorlin 13y agoDamn it... This is stupid, I just upgraded too.
- gmac 13y agoToo late for me, but a pleasingly fast and pro-active response from AWS (which rather shows Google up) just received by email: "If you are an AWS customer who uses Google Authenticator for iOS as a multi-factor authentication device to secure your AWS account via AWS MFA (http://aws.amazon.com/mfa/ http://aws.amazon.com/mfa/), please read on. We are writing to inform you that Google has recently released an update to the Google Authenticator App in the iOS Store. We've received reports indicating this update is inadvertently deleting all MFA tokens from the smartphone; this could prevent you from authenticating to your AWS account. At this point, it is our recommendation that you do not update your Google Authenticator App if you're using an iOS Device. If you have already updated your Google Authenticator app and are no longer able to login successfully you can request assistance from our AWS Customer Service team at: https://portal.aws.amazon.com/gp/aws/html-forms-controller/contactus/aws-token-support https://portal.aws.amazon.com/gp/aws/html-forms-controller/c... We have posted this as an announcement to our AWS Developer Forums at https://forums.aws.amazon.com/ann.jspa?annID=2091 https://forums.aws.amazon.com/ann.jspa?annID=2091 and will be posting updates if new information becomes available."
- Continuous 13y agoI scan the 2D barcode on two apps Google Authenticator and Authy. I also set up SMS Backup and it works well for Gmail/Hotmail accounts.
- SilliMon 13y agoJust because something is in the cloud doesn't mean you don't need backups. Backup your entire Google account. Here's a tool to do it: http://www.syncdocs.com/ http://www.syncdocs.com/ Print out the 10 password recovery codes Google offers. Here's how to do it: https://support.google.com/accounts/answer/180744?hl=en https://support.google.com/accounts/answer/180744?hl=en Having a backup and extra security is essential for everything stored in the cloud.
- sjg 13y agoWhat's even worse is with a certain iOS update that may or may not be launching in the next few weeks will make this advice impossible. 3 words for you - Auto updating apps
- jbrooksuk 13y agoI'm just glad it works full screen on the iPhone 5.
- arange 13y agothis is especially bad for mtgox as it does not have backup codes or cellphone backup.
- web007 13y agoUnrelated to this particular snafu but still potentially problematic: if you have your Authenticator account named by its default name (foo@example.com) and you add another account with the same key, it will be blindly overwritten. I found this out the hard way after scanning my Meraki 2FA QR code that was tied to the same email that already had Google 2FA. ProTip: rename your auth entry to something like "Gmail foo@example" to avoid this problem, whether malicious or accidental.
- andreif 13y agoSome guys really needed retina support. Now you got it.
- robin_reala 13y agoThe broken update has now been pulled.
- acheron 13y agoI saw Google Authenticator had an update this morning and thought "haha, wouldn't it be awful if it deleted the accounts when I updated!" Well, I guess I'm the goat [1]. I was still signed into Google so that was easy enough to generate a new key, but I believe I'm going to have to use my backup number to get into Dropbox. [1] http://en.wikipedia.org/wiki/Duck!_Rabbit,_Duck%21 http://en.wikipedia.org/wiki/Duck!_Rabbit,_Duck%21
- div 13y agoiOS7 beta automatically updated my Google Authenticator. The 'updated app' indicator is taunting me.
- namaserajesh 13y agoThanks for letting us know.
- gfodor 13y agoI'm not seeing the update in the App Store, nor the app itself. Must be pulled.
- DigitalSea 13y agoDo Google even test the stuff they put out? This is a pretty severe mistake to make for a company as big as Google. Do they not have teams dedicated to testing this stuff? The small design studio I work at does a better job QA'ing their websites than Google does QA'ing major product upgrades... Disgraceful.
- swalkergibson 13y agoDon't be ridiculous. Of course they QA their projects. Shit happens. This issue is of a serious enough nature affecting enough people that there will almost certainly be a proper route back.
- olive_ 13y agolesson learned : do not upgrade anything unless you read some feedback about it.
- hrjet 13y agoWhat I worry about is a hacker feigning to be another user and claiming that they can't access their google account anymore because of a botched update. I guess Google support might get too many reset requests to show due diligence in verifying authenticity of the requests.
- Achshar 13y agoDoes this affect android? my phone is off and I am not turning it on until I can somehow disable auto update from the play store from web.
- corresation 13y agoSomewhat related, but when I setup two factor authentication I securely saved the initial TOTP tokens (using barcode scanner to extract it) for exactly this sort of situation (well in my case it was that I switched smartphones enough that having it tied to one was nonsensical).
- nl 13y agoA while ago the Android version was replaced by a new app (instead of just an upgrade), allegedly because the team LOST THE SIGNING KEY FOR THE ORIGINAL APP[1]. If there is one team you'd expect not to lose a signing key I would have thought it would be that one! Everyone makes mistakes, but it's pretty scary to hear this happening too. [1] http://www.androidpolice.com/2012/03/22/psa-googles-authenticator-updated-to-v2-except-its-a-brand-new-app-and-you-need-to-install-it-to-get-future-updates-old-one-is-dead/ http://www.androidpolice.com/2012/03/22/psa-googles-authenti...
- markstanislav 13y agoDon't forget that Duo Security's mobile application supports Google Authenticator (and any other TOTP-enabled service). It also has already been working on iOS 7 for weeks.
- cheald 13y agoAside from the screwup here, this is a good chance to check backup mechanisms for your various 2FA accounts. If your phone is broken or stolen, do you have a recovery plan? I keep backup codes for each of my 2FA services in a Truecrypt container, which is mirrored on Dropbox. Additionally, I keep a copy printed out and kept in a fire safe. Phone backups for personal accounts have my wife's phone on record, and I try to keep printed copies of the QR codes I used to set up the account. About a year ago, my phone was shattered while on the road, and while I was able to regain access to those accounts due to existing login sessions on my home computer, I'd have been sunk without them. Make sure you have a plan for what you do if your phone authenticator becomes unavailable.
- MiguelHudnandez 13y agoShit. I am running the iOS 7 beta with automatic app updates, and I already have the new app. I am considering wiping my phone and restoring it from a previous backup with the old copy of the app. Edit: I was still logged in from my browser, and was able to activate the new version without entering a code from the deceased version of the app. From this, it seems theft of your cookies could let an attacker completely take over your account and two-factor device if they know your account password and you have chosen to trust the victim computer.
- dunham 13y agoIf you have a password on your backups, the codes are in your backed-up keychain. (Google Authenticator doesn't mark its keychain entries as "keep on device".) You'll need to patch iphone-dataprotection to handle a the iOS7 keychain format (I added a patch to the bug tracking database.)
- cominatchu 13y agoI recommend using the Authy app instead, it's much better
- mcleod 13y agoIs anyone else just happy that the assets will finally be high-res? :P
- gbraad 13y agoLuckily got a AWS reminder. And a shameless plug... my own 2FA app on http://gauth.apps.gbraad.nl http://gauth.apps.gbraad.nl can be used everywhere you have a webbrowser, offline when your browser supports it and updates without problems when a new version is available. Besides, no updates were needed in months due to good QA. ;-)
- nick_urban 13y agoThis is the most pressing and actionable information I have ever gleaned from a news site. Thank you!