The apps are actually more secure.
The apps are actually more secure.
> But 2FA via SMS is ubiquitous because of its ease of use. “Not everyone is running around with a smartphone. Some people still have dumb phones,” says Android security researcher Jon Sawyer. “If Google cut off 2FA via SMS, then everybody with a dumb phone would have no two-factor at all. So what’s worse — no two-factor or two-factor that is getting hacked?”
The thing is, SMS is worse than a reasonably good password. So it's a bit annoying that Google strongly encourages me to register my phone number with my gmail account for recovery.
And many services, including Google, make it difficult or impossible to enable TOTP without first registering a phone number. They really really push the SMS route. Brings up the average security level for the average person, I'm sure. Very annoying for me.
So (for me) it's a real PITA when places require a mobile phone number and there's no way to skip it. Obviously, can't use those services.
Does anyone know if Google Authenticator would run on a wifi iPad? As a potential workaround for the "no mobile network" situation.
That being said, it hadn't clicked that a non mobile (eg laptop/desktop) version of it could exist.
The wikipedia page for it says it's strictly mobile only[1], as does the Google install info page[2].
[1]: https://en.wikipedia.org/wiki/Google_Authenticator
[2]: https://support.google.com/accounts/answer/1066447
Oh well.
Apparently I had disabled my device's (the one with the authenticator app) "automatically set time from NTP" feature. Over time this resulted in my device's clock drifting X seconds away from the providers' clock(s), which in turn resulted in my occasionally using codes that were already X seconds expired.
A reasonably trustworthy APK download can be found on f-droid: https://f-droid.org/repository/browse/?fdfilter=freeotp&fdid...