Edit: If you already have two phones due to your work life separation, then 2FA isn't really causing you to get a second phone is it?
https://www.twilio.com/legal/privacy/authy
The only privacy friendly method is no 2FA, just long secure passwords. Which is why 2FA is pushed so hard ...
This is absolutely ridiculous and so clearly false I can't help but wonder if it's intentional misinformation.
There are numerous open source TOTP authenticators for both the desktop and mobile that require absolutely no data to be stored in the cloud or shared with third parties.
I myself use KeepassXC and Keepass2Android.
If I was really paranoid I'd keep the TOTP database on a separate device but, frankly, I don't anticipate being the target of a motivated attacker so that's more than I feel is necessary given the threat models I'm concerned about, those being untargeted hacks (service breaches, driveby attacks, etc) and social engineering.
If you don't want to use Authy then use something else that doesn't backup the 2FA codes for you. But don't say 2FA is inherently a privacy concern. It isn't.
The whole work/personal line is blurring more and more and our devices and thought patterns have not kept up with this. You could probably write one of those 'Things programmers assume about online identity' articles by now.
If you have a Google account for work you also have a work issued computer at minimum, so install a TOTP authenticator there.
If you also have a work issued phone it's a total non-issue as you can use that for 2FA.
If you access your work Google account from a personal device in circumstances where you don't have access to work equipment, then install an authenticator there.
I have a Google account for work. I don't have a work issued computer.
I think you're assuming too much about how other people might work.
I agree there are enough options that it shouldn't really be a big problem, but it's not surprising that not everyone are aware of the options.
Which must mean you're using personal equipment and you're not doing what the previous person was talking about, which was:
> It is very common to arrange your life so that you are able to 'hand in' all work devices and walk away.
Context matters. I was arguing a specific point based on a scenario the previous individual was posing. That scenario apparently doesn't apply to you, in which case, go argue with that person, because it wasn't my claim.
Now, if we want to talk about your specific circumstance, if you're using personal equipment to access a work account, stick a TOTP authenticator on your personal device.
I honestly don't understand what's confusing about this.
> I honestly don't understand what's confusing about this.
I didn't argue it was confusing. I argued against your assumption. And there's no need to use that tone - it comes across as aggressive and condescending. EDIT: I note this is not your only comment in this thread that comes across this way. Looking at your comment history suggests you're just direct, so I'll assume you don't mean anything by it, but it rarely goes over well here.
In my current position I can be called up for an emergency at any time. I'm not going to cart my desktop or laptop around on my day off, but carrying a phone for use with any reasonably secure machine I can find is a good solution.
People with responsibility for operations systems will find themselves in this kind of situation somewhat regularly. These are also the people most likely to seperate work and personal devices due to usage policies or risk profiles.