TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Raivo OTP just deleted all tokens after update and is now asking for money

102 点作者 parody57712 个月前

23 条评论

kiririn12 个月前
This seems like a case where Tim Apple needs to step in. &#x27;Mobime&#x27; should be banned from the app store and Raivo reverted to a known good version. They have literally shipped ransomware<p>Otherwise what point is there in the apple walled garden and trying so hard to avoid sideloading (aka installing)?
评论 #40525106 未加载
评论 #40533626 未加载
thisisabore12 个月前
Updated URL, after Mobime disabled issues entirely on the repo: <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20240531085449&#x2F;https:&#x2F;&#x2F;github.com&#x2F;raivo-otp&#x2F;ios-application&#x2F;issues&#x2F;328" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20240531085449&#x2F;https:&#x2F;&#x2F;github.co...</a><p>See also this conversation, where Mobime request respect and to &quot;acknowledge the efforts being made to resolve the situation&quot; while blurting out things like &quot;We could have easily suspended the entire repository, but we have chosen to keep it open to reassure you that we are taking all necessary steps to resolve this&quot;. Classy.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;raivo-otp&#x2F;ios-application&#x2F;discussions&#x2F;369">https:&#x2F;&#x2F;github.com&#x2F;raivo-otp&#x2F;ios-application&#x2F;discussions&#x2F;369</a>
评论 #40541210 未加载
prirai12 个月前
Related discussion: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40521655">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40521655</a><p>The App Store should pitch in and do something for this.
marcinzm12 个月前
Whenever an app like this is sold to some unknown company there&#x27;s people who say to give the new owners a chance. This is proof of why that&#x27;s inherently the wrong approach. Migrate the second you can.
marton_s11 个月前
I am one of the victims. Only noticed something is wrong today, Raivo on my iPhone got renamed to Raivo Debug and repeatedly crashed on start.<p>I&#x27;ve updated the app - what could go wrong - and it seems like I am one of the unlucky ones that got their 2FA codes wiped forever.<p>There was no option shown for recovery that others mentioned here, and they did not ask for money either.<p>Now I am going through the pain of recovering each one of my dozens of accounts one-by one and moving 2FA codes to 1Password (and 1Passwords own 2FA to Google Authenticator on my iPhone). Quite ironically, I&#x27;ve switched to Raivo in an attempt to use fewer Google products.<p>I would like to report this to Apple (although they did review and approve all revisions - sounds like very little fu*ks they give), but not sure how. The report categories are &quot;Request a refund, Report a quality issue, Report a scam or fraud, Report offensive abusive content, Report illegal content&quot;. I&#x27;ve tried &quot;Report a quality issue&quot; (closest to my situation) but then I get &quot;Reporting not available&quot;.
lxgr12 个月前
Wow, that&#x27;s horrible. I hope it&#x27;s something reversible involving the ownership change (the app seems to have been acquired – maybe a new team identifier is preventing access to old keychain groups or something).
modeless12 个月前
So it&#x27;s &quot;open source&quot; but that doesn&#x27;t really help people because Apple&#x27;s policies don&#x27;t let you sideload a new version yourself, is that right?
scoopr12 个月前
Raivo is the Finnish word for “rage”. Seems fitting.
NylaTheWolf12 个月前
I went on today to realize that the app is acting like this is my first time setting it up and started asking me to pay a subscription. Thank god I exported my data weeks before...I don&#x27;t even want to imagine what other people are going through right now. I&#x27;m so angry and betrayed.
12345hn678912 个月前
This is oddly similar to the insomnia http client moving to a paid model only. Always turn off auto updates!
weikju12 个月前
Glad I switched to Ente with (local no cloud)months ago AND that I have a backup of all my codes as well.
评论 #40535471 未加载
评论 #40524249 未加载
评论 #40527013 未加载
评论 #40524038 未加载
mpeyton12 个月前
I was able to restore my entries after clicking the “Restore” button, and choosing iCloud. However, the export feature is now paywalled.<p>This is hostageware, plain and simple.<p>I even had a todo to move away from it after I heard it had been acquired… guess it’s my fault for getting busy and not getting around to it.<p>One of my rules is to only use software where you can export your data easily. I guess I need to add another rule where I only use software where I control when it updates. That might be impossible with Apple devices though…
评论 #40525072 未加载
评论 #40525140 未加载
parody57712 个月前
I think this was little fucked up of Tijme Gommers at Northwave Cyber Security <a href="https:&#x2F;&#x2F;northwave-cybersecurity.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;northwave-cybersecurity.com&#x2F;</a> original author of this app i assume.<p>Things I get and appreciate:<p>- Before selling, great software, nicely working UI etc.<p>- Taking the risk to create this software.<p>- Wanted get some money out of the project.<p>Things that I don&#x27;t get:<p>- Working for a Cyber security company and selling your &quot;open source&quot; project to some fishy company without really informing the users with big banners (or changing name of the app. e.g. Raivo OTP Mobime)<p>- Knowing fully the risks and importance of this kind of app.<p>- Not speaking out when shit hit the fan. (or helping)<p>There is no accountability here, only the social goodwill has been broken.<p>Lessons:<p>- Don&#x27;t use automatic updates.<p>- All software is shit.<p>- Backup before updates.<p>- Trust nothing and assume it&#x27;s going to break at some point.<p>- Go to the forest and never come back.
评论 #40552469 未加载
trulyrandom12 个月前
Repeat after me: I will never, ever, use proprietary software for important data again.
评论 #40605086 未加载
评论 #40532070 未加载
km6GEwiQqsyEKQH12 个月前
I recently got an apple phone never before having owned one. I was dismayed about the options for 2fa apps, that there seemed to not be any foss ones. I installed Raivo since it was at least source-available and had export features. But you just can&#x27;t trust anything from the app store since anything can be uploaded there and you can&#x27;t roll back. Luckily, I had put off migrating the tokens and looks like I will be carrying two phones for a while more.
评论 #40538696 未加载
dimask12 个月前
It was a disaster waiting to happen. I had entirely disabled automatic updates for my iphone apps specifically this kind of risk with this specific app. An OTP app is sold to some totally shady guy, what can go wrong. Though tbh I must say I did not expect extortion but rather I was more afraid of malware that would just steal the TOTPs and sell them in the dark web.
评论 #40552488 未加载
InfiniteVortex12 个月前
I was one of the users who also participated in the discussions, while also participating in inquiries to discover who MobiMe actually is. I think we affected users figured it out, and the person behind MobiMe is the same person listed as the Key Principal for MobiMe&#x27;s profile on Dun&amp;Bradstreet [3]. There&#x27;s also other corroborating evidence, while circumstantial and coincidental, that was noteworthy and generated a further sense of suspicion. He would delete every post containing BENABID&#x27;s full name, and then lock the discussion or delete the discussion entirely. (Don&#x27;t worry, his name is in public records for the company, it was never private information)<p>Throughout the entire ordeal, from the beginning of responding to users, to the very end, he continued to lie, attempted to deceive, and assumed that we, the damaged users, were fools. I really don&#x27;t know what he was thinking. Or if he was partially using an LLM to generate responses. If you look at the series of events, from the App Store log of Raivo, to his enumeration of the problematic events in question &amp; their causes, which changed multiple times throughout the timeframe of his responses, you would come to the conclusion that he was not acting in good faith at all (which I presumed was happening from the beginning). Any reasonable and impartial observer would come to the same conclusion. Some users lost their 2fa codes, and were locked out of accessing some of their most sensitive and valuable data. Yes, there is an element of personal responsibility (having backups codes, etc), but the actions committed by MobiMe were and are against not only the App Store TOS, but are also morally wrong (as if he cares about that), and perhaps legally wrong (civilly wrong or even maybe criminally wrong if there is more we don&#x27;t know). IANAL -- we all know that practically no legal action, civil or especially criminal will ever come of this. I&#x27;m almost certain he is living in an unfriendly jurisdiction that does not enforce cybercrime laws.<p>Ultimately in the end, like I mentioned above, he eventually deleted all discussions (after previously deleting all issues), then closed all PRs, blocked many users from interacting with the repository, and prohibited anyone from forking the repository and creating a PR. He also reseted&#x2F;removed all poor reviews of Raivo on the App Store. Basically he did everything he said he wouldn&#x27;t do. Then again, I&#x27;d be surprised if he actually kept his word.<p>Hopefully if enough people report Raivo OTP to Apple, the new&#x2F;current dev in control of the project (MobiMe aka Soufiane BENABID), he won&#x27;t be able to intentionally lock out users from their 2fa tokens, because he wouldn&#x27;t have an Apple Developer account. He currently operates 2: the first is MobiMe, which operates Raivo and some other apps, and the second is Soufiane Benabid, which operates some apps that are very similar to the apps under MobiMe. Basically the theme with him is that he tries to squeeze as much money out of the user as possible. He controls a few domains under his belt too (literally just ~4 IIRC).<p>In sum, he sucks &amp; the (impulsive?) decision to sell Raivo (which was never open source to begin with, despite marketed that way) to a super shady company without a proper transition, coupled with said shady company proceeding to turn the app into ransomware-lite is just an unfortunate and regrettable series of events.<p>If you want to read the lore regarding this entire incident (you&#x27;ve already read enough of this comment), here you go [0][1][2][3].<p>[0]: <a href="https:&#x2F;&#x2F;archive.ph&#x2F;fGnO3" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;fGnO3</a><p>[1]: <a href="https:&#x2F;&#x2F;archive.ph&#x2F;m8xk6" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;m8xk6</a><p>[2]: <a href="https:&#x2F;&#x2F;archive.ph&#x2F;X8shn" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;X8shn</a><p>[3]: <a href="https:&#x2F;&#x2F;archive.ph&#x2F;094wM" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;094wM</a>
评论 #40542599 未加载
cyanwave12 个月前
I reported it to the App Store and all users should. This was a train wreck random attempt
justinclift12 个月前
Wow, there are a lot of unhappy (now ex-)users filing issues in that repo. :( :( :(
评论 #40523988 未加载
评论 #40524203 未加载
soygem12 个月前
get filtered by trusting a third party with your passwords
anton00112 个月前
This is ridiculous. I&#x27;m just thankful for the fact that I added all the OTP secrets in BitWarden if I ever where to upgrade to Premium. Today I did that...
mistrial912 个月前
but their site says &quot;This website is a labor of love by Raivo&#x27;s community on Github.&quot;<p>certainly repeating &quot;love&quot; and &quot;community&quot; while getting donated graphic design is all the proof anyone needs &lt;&#x2F;s&gt;
评论 #40523914 未加载
userbinator12 个月前
How much more insanity can we manage to wrap around hash(key + timestamp)?<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=33245042">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=33245042</a>
评论 #40523810 未加载