3 ms·
What exactly is wrong with Authy that makes it completely unacceptable for you to use? Let's turn this device into a secure token Enter your Authy cellphon
by jomar 12y ago
What exactly is wrong with Authy that makes it completely unacceptable for you to use?
Let's turn this device into a secure token
Enter your Authy cellphone
__+code__ __Authy cellphone number__
They're my private tokens. I don't want to set up an account with Authy Inc and I certainly don't want my tokens in your cloud. Sure maybe it'd be nice to sync across my devices, but not if it looks like it means doing so via somebody else's servers!
- viraptor 12y agoYou realise that you encrypt the tokens you send and you can't restore them without that password, right? And that backups are opt-in only and you can leave that option disabled? Do you not trust them to actually encrypt the data before backup? Or is there another issue?
- nknighthb 12y agoAuthy necessarily has the keys on its servers in cleartext. When you integrate them into your application, you send the code the user inputs to Authy's servers for verification. Authy is a third-party authentication provider, it is not simply a synchronization service.
- jomar 12y agoNo, I don't realise any of that, because Let's turn this device into a secure token is the sum total of the information you get when you fire up the Authy app. No links to any explanations of why they want you to have an account, and I didn't care enough to go looking further myself. But the real issue for me is: given a choice between (1) having my private tokens physically only on my own devices; (2) having an account and apparently some form of my tokens at a third party in another country susceptible to bulk espionage and subpoenas... why on earth would I choose (2) in today's climate? Or in summary: I guess I don't trust them to actually encrypt anything in the face of legal threats.