TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Authy: One token to rule them all

55 pointsby dcuover 12 years ago

14 comments

spindritfover 12 years ago
I may be dense but if you back up the tokens and protect that online backup with a password, don't you eliminate the second factor?<p>Now the attacker just needs to get two passwords (to the backup at Authy and to whatever account) so it's reduced to just something you (may) know.
评论 #4917189 未加载
mannkindover 12 years ago
Looks like the someone from Authy is reading this thread so here goes...<p>Feedback:<p>* Registration is a bit complex; all texts to my phone (with the exception of the registration code) are completely useless as the <i>real</i> info is sent to my email address<p>* Why is my backup encryption key in plain text? A dual-password field with sameness-checks would be better.<p>* Restoring from backup is... painful.<p>- I cannot just reregister my phone, I have to go through a reset process online. Ok, fine. I got texts to my phone instantly but the reset email took almost 15 minutes to reach me.<p>- The app crashes tapping any "GA" item other than the first one.<p>- I have to type in my encryption key for each "GA" item and the app crashes each and every time.<p>- The <i>first</i> time I tried to restore authy, after typing in my encryption key to recover the first "GA" item, the app crashed and wouldn't let me recover any of the other items... I had to do the whole process all over again.<p>* Aside from the above, the app <i>looks and works</i> so much better than Google Authenticator on my iPhone (5). Especially considering I'll be able to recover my tokens when switching phones -- Google Authenticator completely screws this up (broken phone? Get a replacement phone from Apple? Upgrade? All your tokens in Google Authenticator are lost, even if you recover from backup).
评论 #4917453 未加载
评论 #4918643 未加载
评论 #4917457 未加载
bcambelover 12 years ago
You better replace your development error pages with proper 404 Take a look at <a href="http://blog.authy.com/feed" rel="nofollow">http://blog.authy.com/feed</a>
评论 #4917371 未加载
SCdFover 12 years ago
This is interesting, I've never considered using an alternative app for google 2fa tokens.. mostly because the app Just Works. It's literally one tap and it shows the token I need to type into the website, I'm not sure how it could get any simpler.<p>Since the authy guys seem to be around, if the only 2fa I have is on my Google accounts, what is the advantage of using Authy over the standard Google Authenticator app (on Android, fwiw)?
scottmp10over 12 years ago
Is this "condoned" by Google or does Authy just emulate the algorithm that Google uses? If they are just implementing their own version, then what secret info do they need for the algorithm?
评论 #4917133 未加载
评论 #4917141 未加载
asfdfdasfafdsssover 12 years ago
There is only one semi-reliable auth method: deep body scan + DNA + mitochondrial RNA + retina scan fuzzy match. Passwords and 2 factor auth suck. And so will embedded/mark IDs, which I will never, ever use.<p>This is a good idea- everyone worth their salt wants a third-party single auth service, perhaps one that we pay an annual fee for, however this ain't it yet. You should not piggyback. Don't.
seanponeilover 12 years ago
Looks like the back button is broken on the Android app. I can't hit the back button and leave the app from the registration Activity.
kmfrkover 12 years ago
I don't know if likening yourselves to Sauron will assuage our caution to adopt your tool. :)
nbashawover 12 years ago
Just FYI, the images look terribly stretched on my iPhone
评论 #4917304 未加载
TylerEover 12 years ago
&#60;Insert XKCD cartoon about new standards here&#62;
评论 #4917241 未加载
freshhawkover 12 years ago
Seems like a complicated way to turn two factor off while leaking information to yet another 3rd party.
cynixover 12 years ago
Now if it can import all my RSA key fobs...
martincedover 12 years ago
What could possibly go wrong when using a device that is connected to the Internet as a 2nd form factor?<p>That's not just a criticism of this app: all the apps that advertize a device that is connected to the Internet as a "2nd form factor" is using deception to lure people in.<p>There's no way this is "Two-Factor" in the same way that a physical RSA token is "Two-Factor".
评论 #4917792 未加载
评论 #4918785 未加载
asveikauover 12 years ago
Can someone put a moratorium on startup names that end in "-y" or "-ly"? After a few of these it gets irritating. Maybe the next one will be called "obnoxiously".
评论 #4917293 未加载
评论 #4917396 未加载