But for the security-paranoid, I understand that letting a cloud service store your 2FA tokens is suspect, even if it's password-protected. Steve Gibson suggests the alternative: when the site generates the QR code, take a picture of it, print the picture out, keep it in your safety deposit box. When you change phones, pull the QR codes out and re-scan them.
I have been researching how to dump the database of google authenticator (currently over 20 entries, some non recoverable), but the solution involves rooting my android phone and accessing a protected sqlite file, with a propietary (and version dependent) schema. I am not going to do that.
Does authy have the same workflow a google authenticator? Can I add entries with QR code? With ID? Can I dump the database in plaintext? (the IDs) Can it generate QRs for scanning with other 2fa tools?
Edit: ah, it's an online service. That kills it for me.
Though I've recently switched over to simply putting all the 2FA secrets in my keepass database, that's good enough for me in terms of security.
Define "dump". GA won't challenge you to display the one-time TOTP code, no. It would be incumbent upon you to lock your device. But as far as dumping those codes out into a state such that a malicious actor could then take them and import them onto another device, no, that is not easily doable. As the distant parent noted, Google Authenticator stores the stuff in an encrypted sqlite database that is not extractable without root access. I don't think even run-of-the-mill adb debug commands can get it out.
Recently I had to send my phone away for repairs, and as instructed, they told me to reset the phone to factory defaults before mailing them the device.
I forgot about Google Authenticator during this process so ended up having to reset everything/go through recovery procedures across all my accounts.
With SMS it almost seems stateless, the only thing you need is access to a signal. That's the biggest advantage in my opinion, but given the risks I'd be open to ideas that are not just "download an app onto your phone"
It's a shame so many people have no clue you can (and should, imo!) backup your TOTP key.
[1]: just copy the string and store it however you want. [2]: as far as I'm aware. I'm not a security professional, of course.
"The Time-based One-Time Password algorithm (TOTP) is an algorithm that computes a one-time password from a shared secret key and the current time."
https://en.wikipedia.org/wiki/Time-based_One-time_Password_A...
I've only found the Protectimus Slim NFC [0], which would be my ideal solution except it only holds 1 key.
If it could save say, 100 keys (or even 50 maybe?), I would buy 3 or 4 in a heartbeat. It would be great to have stronger 2FA than SMS, but with the peace of mind of not having to worry about the phone.
I'm definitely not a hardware guy, but I can't believe such a solution doesn't exist yet. It doesn't seem like it would be hard to build, right? I mean, you just need a very simple processor, a real-time clock, a display and an NFC module for reprogramming (or maybe micro-usb?).
Does anyone know of any products like the Protectimus but supporting multiple keys?
Ideally I'd love to have a hardware token that I can use for TOTP authentication regardless of the computer I'm working with.
I'm not ignoring that at all. Google Authenticator is the only one I use, even with the described workflow.
I back the key up immediately, when they're asking you to save the TOTP. They usually (not always!) give you multiple methods to input the TOTP, such as scanning an image or typing in a string. That string can be backed up, and is what I usually use.
I never renew my TOTP, and all I use is Google Authenticator. Anytime I get a new phone (nearly every year, heh), I just add my TOTPs back.
This of course doesn't work for non-tech people, it's a bit too manual. I acknowledged that in my first post, though.
The problem is 2FA is used to protect my email!
I can keep my 2fa straight but I know she can’t. I’d bet there are similar people out there. The solution needs to be elegant enough to support all degrees of tech knowledge and even people who are forgetful, accident prone, etc.
http://about.att.com/story/att_sprint_tmobile_and_verizon_un...
So if that's more your cup of tea for security, then you'll be well covered.