4 ms·
Sorry, couldn't resist. Shameful self-promotion, but this is why companies shouldn't implement their own two-factor authentication. Getting everything right is
by danielpal 12y ago
Sorry, couldn't resist. Shameful self-promotion, but this is why companies shouldn't implement their own two-factor authentication. Getting everything right is hard and chances are that you aren't reading or informed of the latest attacks.
At Authy we are obsessed with Two-Factor Authentication and spend a huge amount of time looking at whats happening in the ecosystem, which new attacks do we need to be aware of etc. It might look easy to build a quick two-factor authentication system, but history will repeat itself, and like passwords we'll see lots of bad and insecure implementations because its harder than what people think.
- primitivesuave 12y agoAuthy is an awesome piece of technology, I definitely think some day it will be the standard.
- enscr 12y agoYou should add a line in your response saying that 'Authy isn't vulnerable to the voicemail attack'. Good job for being dedicated to the service.
- deleted 12y ago[deleted]
- enscr 12y agoAssuming you aren't compromising someone's account that was left logged-in or a stolen phone: Note down all information about the account creation, frequent contacts, services used .. basically all dashboard data and then contact Google. If you have a secondary recovery address, that's even better.
- deleted 12y ago[deleted]
- zobzu 12y agoso you're saying authy is better than google, etc and will never suffer from any security issue?
- vertex-four 12y agoThe point is that the company is dedicated to it, and they can't slip up or they outright lose customers, so they're more likely to pay attention to risks and the state of the art in multi-factor authentication.
- Revisor 12y agoPlease add public pricing to your website.
- deleted 12y ago[deleted]
- macspoofing 12y agoI appreciate startup self-promotion as much as the next guy buuuuuut are you saying multi-hundred billion dollar internet companies shouldn't implement their own 2f auth? they should instead trust the security of their hundreds of millions user to you? Really?
- MichaelApproved 12y agoI think Authy is saying that even multi-hundred billion dollar internet companies get it wrong, that's how hard it could be to properly build 2-factor. Don't try it yourself, use us.
- macspoofing 12y ago> Don't try it yourself, use us. I get it, what I'm saying is, if you're a multi-billion dollar internet company whose business it is to manage hundred of millions of users, you should keep security in-house, and get it right instead of outsourcing it to a start-up.
- danudey 12y agoI think specifically what they're saying is 'If even Google can get it wrong, then you should seriously reconsider implementing it yourself if you need it. That said, we know a lot more about it than most people and you can trust us more than you can trust something you build yourself.'