5 ms·
Founder of @Authy here. Happy to answer any questions.
by danielpal 12y ago
Founder of @Authy here. Happy to answer any questions.
- whyleyc 12y agoWhat was the acquisition price ?
- feld 12y agoWhy does Authy require I provide my cell phone number and email address? Why do I have to have a user account? This is completely ridiculous. I do not need nor want cloud syncing or backup. You are making Authy a potential target for attacks by associating a user to cloud stored 2FA information. This is not in the spirit of 2FA.
- Icyerasor 7y agoAn in my opinion crucial information is missing in the discussion that unfolded here 4 years ago; still this discussions comes up as a top result when searching for "authy telephone number required" and that is why I want to add something for current and future references: The phone number is only needed to recover access to your encrypted data that is stored on authys servers. If you're questioning yourself whether authy is trustworthy because they require you to provide a phone number for a 2FA-TOTP-Method that does technically not require it at all(!) and thus could pose a potential security degredation, check the FAQ about account recovery/passwords here: https://support.authy.com/hc/en-us/articles/115001950787-Backups-password-Master-password-and-PIN-protection-with-Authy https://support.authy.com/hc/en-us/articles/115001950787-Bac... Quote: * The Backups password is never sent nor stored in our servers for your security * Like the Backups password, the App Protection PIN (and optional biometric data) is never stored in our servers * Like the Backups password and App Protection PIN, the Master Password is never stored in our servers the question still is if you trust those promises - but as authy is backed by twilio (thus lots of 2FA-SMS are already processed by them) the chances are good those guys know what they do and do it responsibly
- danielpal 12y agoHi, good question. The reason for the phone number is that we depend on your phone number as part of your identity. Almost all 2-FA systems today use the phone number as a way to send you the code via text/phone call. If you read my blog post: blog.authy.com/twilio you'll see we decided to build our infrastructure on top of the telecom infrastructure because it was ubiquitous. I also understand why some people don't like clouds backups. The good news is that backups are off by default and optional. If you don't need them, you can keep them disabled.
- feld 12y agoThis tweet indicates you're using TOTP, slightly modified from Google's implementation: https://twitter.com/authy/status/498244613766139904 https://twitter.com/authy/status/498244613766139904 @benmcginnes Yes we are RFC 6238 TOTP compatible. Same algorithm as GAuth but 7 digits, 256 bit keys and 10 seconds window. So why do you still need my phone number? There's no network connection or SMS required to generate those TOTP codes. I'm not buying the story that you need to text me or call me unless you're storing the seed/token centrally and sending it to users upon request which I strongly disagree with. That should only be stored on the user's device.
- maxerickson 12y agoAuthy exists to make 2 factor easier for people implementing it. Some users will want methods other than TOTP, so they support methods other than TOTP. If they don't have a phone number they can't do all that transparently, which is bad when you are aiming your service at a broad audience.
- mmebane 12y agoThen why not allow users to defer entering a phone number until they try to add a service that actually requires it?
- maxerickson 12y agoBecause doing a high enough level of identity verification at that point would be disruptive. I'm not really interested in defending it, I probably don't like the idea of depending on a third party any more than feld does, I was just pointing out that there are simpler explanations for what they are doing than I'm not buying the story that you need to text me or call me unless you're storing the seed/token centrally and sending it to users upon request which I strongly disagree with. Another one is that if they actually implemented TOTP like that their business would take a lot of damage when it was revealed publicly (because what's the point of paying for a broken implementation?).
- bdcravens 12y agoThe advantage is that if you lose/switch phones, you don't have to reset your 2FA. (a disadvantage, of course, if your account/device is compromised)
- an6n 12y agoWhat's your take on U2F?
- danielpal 12y agoHi An6n, Fido and U2F are really interesting to us - we are totally supportive of it and have some really great things planned around this area. Stay tuned!
- asyncwords 12y agoDo you have any plans for a Windows Phone app? The SMS backup works well, but an app would be ideal; it's one of the few things I'm still missing after switching from Android.
- danielpal 12y agoHi, very likely. We will be investing a lot more resources into Authy - Windows Phone App is very high at the top of things we are thinking of doing.
- feld 12y agoIt's just TOTP, so if they weren't creating a walled 2FA garden you could use any of the available TOTP apps on Windows Phone, but alas...
- sleepyhead 12y agoWhy do you refuse to delete accounts? It is my data and I want it to be removed. How can I feel safe about my data if I cannot remove it if I choose not to continue using your service.