Email or username:

Password:

Forgot your password?
Mysk🇨🇦🇩🇪

Google Authenticator still syncs two-factor authentication secrets without E2EE. If you enable cloud syncing, this means:

1️⃣ Google can read the secrets and generate one-time passwords for your accounts
2️⃣ Google knows the services you use
3️⃣ #Google knows your usernames
4️⃣ Given a court order, Google is obliged to hand over this data to law enforcement

#Privacy #privacymatters #CyberSecurity #infosec
defcon.social/@mysk/1102623132

24 comments
Christoph Schmees

@mysk
I for one would NEVER use #Google Auth. I would NEVER use Google for anything relevant for #security or #privacy. I would NEVER use Google at all. I refuse to correspond to gmail. And so forth.

dbread

@PC_Fluesterer @mysk I'm with you here. I tried to explain this to our HR department that there exist people who want to and can live without #Google. Got weird responses.

Christoph Schmees

@dbread @mysk Could you cite the best of them? Many thanks! 😀

Emil Borch 🏳️‍🌈

@mysk Ahoj!
Do you have any suggestions for good and privacy friendly 2fa-apps? I really would like to switch/go away from google authenticator :D

Mysk🇨🇦🇩🇪

@schnaff

Check out Raivo and 2FAS, but watch this for a more informed decision:

youtu.be/JHIAIzOPz3I

Emil Borch 🏳️‍🌈

@mysk Thank you very much! :D
Any direct recommodations for 2fa-apps on f-droid? (maybe I should watch the video first xD )

Emil Borch 🏳️‍🌈

@mysk Again: Thank you very much! You helped me a lot!

I am gonna watch the video later this day!

Have a nice day! :blobcatcoffee:

shadowwwind

@mysk @schnaff aegies is great and easily allows you to import directly from Google authenticator.

Stu

@shadowwwind @mysk @schnaff I just tried to import from Google Authenticator to Aegis and it said root access was needed. I started going through the motions anyway, but it warned me Authenticator now encrypts local storage, so it may not be accessible.

I cancelled, and will continue manually moving stuff over, which I was already in the middle of doing.

shadowwwind

@tehstu @mysk @schnaff you can just scan the export qr codes from Google authenticator with Aegis

Christian Aubry 🇺🇦

@mysk @schnaff
What about an open source solution with a minimal yearly fee and zero knowledge security for both passwords and 2FA? Then I suggest Bitwarden but you can also protect your Bitwarden and other critical accounts with third parties such as 2FAS or Authy. Check this (and their homepage too): bitwarden.com/help/bitwarden-f

Hans Hammer

@schnaff @mysk FreeOPT (local) or Bitwarden (cloud, can be self-hosted)

jamespthomas

@mysk is that how i got blocked out of my gmail account?password not working for weeks

Emil Jacobs - Collectifission

@mysk Any alternatives you recommend? Alternatives that do sync E2EE?

Bennett

@collectifission @mysk

Any password manager worth it's salt has this capability

Emil Jacobs - Collectifission

@mysk To answer my own question: looked into BitWarden's capabilities and they seem to be a great alternative for Google Authenticator.

DELETED

@mysk

Thanks for raising awareness!

Curious if you or others know of worthwhile options for iOS?

3⭐️ rating for FreeOTP on iOS, no import or export support.

Leaves me debating upgrading to paid BitWarden.

Thx for any input!

Molytov

@mysk Aegis and Ente Auth are the only two TOTP apps I'm comfortable vouching for. Have used both and they're good and actually safe to use.

你的雷电型阿喵

@mysk how about Microsoft authenticator? I'm using it

Go Up