If I wipe my phone, I have permanently lost all of my TOTP codes if I wasn't careful and backed them up manually before wiping...
TOTP is great for security conscious and technologically fluent folks... awful for your grandma.
It's sort of the same problem PGP suffered from. It's technically great, but cumbersome for non-technical people to use (particularly in a safe way), so people will avoid it.
2FA needs to be simple and easy to achieve mass adoption.
Making people install special apps for just one service, or find out one day they're permanently locked out of their facebook account (or far worse) is simply going to hurt adoption.
If your grandmother can't make it work on her own, then it's not good enough. I'm not advocating SMS is the best option for 2FA, I'm just pointing out the alternatives are currently not up to snuff.
All of my other apps automatically back themselves up, or Apple/Google backs things up for me. When I get a new phone or wipe my phone... after logging into all my account I fully expect my Authenticator app to show up on my home screen and have all my codes in there exactly as I left it before.
This is a huge pitfall for the unaware... you will lose all of your codes, and potentially access to whatever services or things they were protecting.
I consider Google Authenticator to be unacceptably bad.
We all agree SMS 2FA is not as secure as we'd like it to be... but no alternative exists. It's the classic sliding scale between usability and security. The most secure system is one you cannot use... and the most usable system is one with no security. We need something that is very usable, and still secure... perhaps a tall ask but that is indeed what we're after.
Until then... regular people will continue to use SMS for 2FA. We should be happy people are at least comfortable with SMS 2FA instead of not using 2FA at all.
> No, it's tied to the app because the initial secret is destroyed after you set it up. Every single Authenticator App I've used (which is not all of them admittedly), requires manual backups - typically in some printed form.
i scan the QR codes with a normal code reader, and then put the information into keepassxc. i can view the secret, generate codes, do whatever, and it's all with decent open source stuff and stored in a file i can back up.
I don't think that's a huge problem.
TOTP is not tied to any app. When you set it up, save the TOTP seed in a secure place that you control. There is no need to rely on any app, which would be too fragile to consider.
I upgraded to an iPhone 13 about 6 months ago and it was almost completely seamless to restore everything to it.
Probably a security policy thing more than a technology thing... but the result is the same. TOTP is dangerous for the wrong user.
TOTP at least is just a standard so you can either use a client that has backup options, write your own, or whatever. It's better.
Do not, ever, store the TOTP seed in your phone! At least not as the one and only location.
This isn't about an attacker getting access to your TOTP codes - it's about you losing access to them.
SMS, for all its security shortcomings, is at least something that the vast majority of people understand already.
But of course SMS suffers of the same problems as naive use of TOTP: Lose your phone, you're locked out of every account you have.
So in the worst case, TOTP is as bad as SMS. But, with some awareness/education TOTP is far superior if the user doesn't fall into the trap of attaching the TOTP seed to a phone.
i.e. for the aware user, TOTP is far better. For the naive user, TOTP is no worse than SMS. Thus, always favor TOTP.
Let's just hope they don't use _that_ for marketing purposes! ;)
However, if you use the "less secure" email MFA then steam places limits on your account that don't exist with the app MFA, like a forced delay on executing trades.
https://bitwarden.com/help/authenticator-keys/#steam-guard-t...
———————
On a recent find apparently Authy (the app not the sms fallback) has a weird, uh, “feature?”, where my 2fa, for example, for Sendgrid will unlock all of my Sendgrid accounts, which I personally find mildly concerning.
Ultimately with any service you’re only protected by your contract and the PR value of a breach of trust. Unless you’re using an open source app and rolling your own sync, an app where trust is paramount (1Password), or one where a misstep is a huge media hit (Apple), you’re at the mercy of that company.
Microsoft fwiw, probably uses location to spot fraud and is unlikely to breach user trust imo.