Some Authy 2FA accounts were compromised in Twilio data breach
engadget.com
engadget.com
Instructions:
https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
Aegis-specific export:
https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
Probably not worth buying it just for that feature, but I'm a happy user.
There’s also OTP Auth, which is a freemium app with all the basic needs covered in the free option, including an Apple Watch app/Watch Face complication.
But now I am wondering if I should be re-seeding across all my TOTP-enabled accounts in case we continue to be drip-fed new information about how much worse this breach is getting.
I've triggered the deletion process for my Authy account - the claim is that all my info will be deleted after 30 days.
Aegis has a nice clean encrypted import/export JSON format.
There is an ipad app, which I installed on my M2 macbook air, so I can access it on my laptop as well. I also downloaded a version onto my old iphone 6 I keep in a drawer under my bed, just as a backup in case something gets stolen. And I have an ipad mini that I use on a daily nightly basis for reading and browsing. In addition to a ~5 year old windows desktop and a windows laptop form ~2015.
I've been resistant to using apps that only exist in the apple ecosystem, because I generally have only used windows laptops and android phones. But now I use an iphone, I have an m2 macbook air, and quite honestly the quality just blows everything on the windows / android side out of the water. I finally just admitted to myself that there is probably never going to be a scenario where if my phone breaks, I would go out and buy an android phone. It won't happen. The sheer connivence of just getting a new replacement phone, logging in, and having all your settings and files and (2FA codes! - encrypted in icloud!) automatically download is understated.
The price of an old iphone 6 or 6s is ~25-40 dollars on ebay. The price of a yubikey is 50 or 60 bucks.
App Store Link: https://apps.apple.com/us/app/raivo-otp/id1459042137
On Android I would recommend Aegis.
Playstore: https://play.google.com/store/apps/details?id=com.beemdevelo...
F-Droid: https://f-droid.org/en/packages/com.beemdevelopment.aegis/
I tried an 8 digit long key. 9 char long string. 9 char + 3 spaces. 9 char + 3 hyphens.
It just keeps rejecting them saying weak passwords without telling me what does it need.
I finally set a long randomly generated password and it was accepted. I like to remember passwords of my password manager and TOTP tool. It I knew the requirement I would have set something longer but memorable.
Isn’t there s desktop tool at all?
There is no way to recover your backup easily...
https://raivo-otp.com/faq/#how-do-i-restore-from-a-zip-archi...
... and it is a 2 year old issue...
I will say that what surprised me about the exported backup encrypted zip file - it did not work the way I expected. I thought it was going to be some .txt file with a bunch of numbers and things I would have to input into a new 2fa app manually - but no, it's legitimately a a very nice html document that has every 2fa account laid out neatly with a QR code, section by section. When transferring these codes to my old iphone 6 (before I turned on icloud sync), I just held my phone up to my laptop screen and moved it inch by inch every 1 second (tapping accept in between) to scan and add 20+ codes with the camera. It took me 5 minutes to add them initially as I doubled checked the veracity of the 2fa codes generated... but truthfully you could probably add 20+ accounts in under a minute. If not quicker.
I don't consider the lack of an automated way to import the manual backups a bad thing. The encrypted icloud sync works remarkably well. The exported zip backup would, in in the worse case scenario, be where I lost my iphone 12, I lost my macbook air, someone stole my ipad mini, and in the same day, someone broke into my house, went under my bed, and additionally stole the beat up looking iphone 6 in the back of the drawer. But again, since the codes are backed up encrypted in iCloud, just because my devices are stolen doesn't mean I lost access to them. I could also drive 30 minutes downtown, walk into an apple store, buy an iphone on the spot, download raivo from the app store and have it automatically sync my codes from iCloud, and have access to my 2fa codes, all within an hour. Or I could go to craigslist and find someone selling an old ipad, iphone, or whatever and buy it off them for 50 bucks and have access to my codes. My wife also has an old iphone 7 that is laying unused on the bookshelf in our living room, which I could also just log in and access my codes as well.
Basically, what I'm saying, is that as long as an encrypted copy of my 2fa codes exist in icloud, I can log into any idevice and have access to my 2fa codes. The chance of me having to manually use my encrypted .zip backup is virtually nil. The only scenario I can envision is if someone stole every device I own, burned my house down, sim swapped my phone and stole my cell phone number, burned down the local google data center (likely centers) where my iCloud user data is stored on Google Cloud, and also bought every iphone, ipad, macbook, and apple device in a 100 mile radius, including used models, and including breaking into and robbing every apple store in the vicinity so I couldn't procure a new idevice. That is legitimately the only scenario I can foresee in where I would lose access to my 2fa codes.
Apple devices are ubiquitous in the US. I still have a windows laptop and desktop that I had considered as my "main" computers for the longest time. I had a real come to jesus moment several months ago when I realized my way of thinking was a bit outdated. I had thought that in order to reduce the attack surface, I would need to manually backup all my codes, print them out, make several copies so I wouldn't lose one of them, and use my 2fa codes only on one device. But truthfully - there is another way of ensuring ubiquitous access to my 2fa codes, and it didn't involve much more effort on my part.
What you are asking for is the manual backup you create to automatically restore.
All the other 2FA apps out there that I've looked at are lacking in some way or another. Ideally, I'd like as a basis: iOS and MacOS app (not electron) support, easy import/export, no requirement for a phone number, some sort of encrypted 'cloud' backup, open source, decent UX.
I'm half tempted to just import into Bitwarden (which I happily pay for) and call it a day, but I'd like to keep my password manager separate from my 2fa... just seems awkward to combine them.
I haven't found anything better. Some people aren't happy with them for reasons like their subscription model and their move to Electron for some formerly-native clients.
> I'm half tempted to just import into Bitwarden and call it a day, but I'd like to keep my password manager separate from my 2fa... just seems awkward to combine them.
FWIW, In practice I find that this is natural and super-convenient.
maybe one day one of these: https://www.crowdsupply.com/sutajio-kosagi/precursor
This doesn't affect any of the MFA secrets you manually added to Authy, and these days many of the integrated services will let you additionally add standard TOTP mfa to your account ( unfortunately Twitch still requires you to set up an Authy account first, though )
It will also automatically put the 2FA code into your clipboard after you autofill your password.
Clarification edit: they offer a 2FA token app which you unlock with your hardware key, which is separate and can be used in conjunction with hardware token authentication with any service that offers it.
Note that their cheaper blue or newer biometric keys don't support all the same things their mainline black ones do, but should work just fine.
No affiliation, just happy with their products and had a really awesome (business) customer support experience where they replaced several broken (through my own fault) keys for free.
Edit: some reading: https://en.m.wikipedia.org/wiki/Universal_2nd_Factor I have the advantages and disadvantages section a read and I believe I got it right. The one major disadvantage I’ve read about is that there is no backup. At a place I worked, we registered two keys and kept one as a backup. It seemed to work okay.
Also this: https://www.yubico.com/blog/otp-vs-u2f-strong-to-stronger/
On OTP:
> The remaining issues, however, are phishing and man-in-the-middle attacks, the most infamous assaults that defeat OTP technology. The theory is quite simple: the hacker sets up a fake website designed to trick visitors into submitting their credentials. When a user falls into the trap and enters his information (user name, password, and even his one-time password), it is immediately intercepted by the hacker and used to access the victim’s account.
Later, on FIDO U2F:
> Real-time challenge-response schemes like U2F address OTP vulnerabilities such as phishing and various forms of man-in-the-middle attacks. As the legitimate server is issuing the challenge, if a rogue site or middle-man manipulates the flow, the server will detect an abnormality in the response and deny the transaction.
For some historical reason, at my previous job the SendGrid account was connected to my phone number. When I quit, I migrated Authy, which was required to log into SendGrid, to another employee.
Now, months later, I find that Twitch has migrated its 2FA to Authy, and I am unable to get the codes anymore so I'm locked out. I'm pretty sure my codes are now being sent to this other employee, and neither Twitch nor Authy's support are keen to help.
I don't know if I should blame Twitch or Twilio but fuck this shit and I will not give either any more or business.
I use Bitwarden for password management and 2FA now. I recommend them instead.
Thanks.
The reminder you are talking about is when you are already using Authy to re-enter your backup password so that you dont forget it. That is the prompt you can dismiss, not the once needed to setup Authy on new machine.
Wouldn’t you mind stating what license this is released under.
Somehow I suddenly trust bima a whole lot.
There are many other apps that provide syncing (the accounts and seeds) across devices without needing a phone number and SMS OTP authentication. There your threats are primarily your phone and what service is used for the sync.
That said, using it is a choice that compromises the underlying principle of 2FA, which is verifying something "you have" in addition to something "you know" (your login credentials). This is a choice that should more clearly be explained to users, in that expanding the pool of things "you have" and allowing that pool to be expanded using nothing but SMS auth significantly increases the possibility of nullifying 2FA security entirely.
I say this as the author of a password-store extension that stores and syncs TOTP and HOTP keys. I understand that users can choose to defeat 2FA entirely by storing keys alongside their passwords without a second factor needed to decrypt those keys. But users can also choose to keep the store decryption keys on a hardware token such as a Yubikey, which effectively replaces OTP 2FA with hardware token-based 2FA, with the possibility to restore from a backed-up PGP private key.
Obviously that option is complicated, which is why I admire the sync solutions implemented by Keybase and Signal like you describe.
I don’t think they compromised the encrypted / non-Authy-issued codes.
At this point I also won’t consider anything but U2F secure 2FA.
proprietary auth - not even once