Google Authenticator still syncs two-factor authentication secrets without E2EE. If you enable cloud syncing, this means:
1️⃣ Google can read the secrets and generate one-time passwords for your accounts
2️⃣ Google knows the services you use
3️⃣ #Google knows your usernames
4️⃣ Given a court order, Google is obliged to hand over this data to law enforcement
#Privacy #privacymatters #CyberSecurity #infosec
https://defcon.social/@mysk/110262313275622023
@mysk
I for one would NEVER use #Google Auth. I would NEVER use Google for anything relevant for #security or #privacy. I would NEVER use Google at all. I refuse to correspond to gmail. And so forth.