FYI, Authy was bought and is now owned by Twilio
FYI, Authy was bought and is now owned by Twilio
Authy gets recommended often here but got turned off of them because they require a phone number to set up the app on iOS. There's no phone number requirement for TOTP implementations so I eventually found Duo Mobile. This was before they got bought by Cisco.
iOS TOTP apps all suck, it's amazingly bad. I installed like ~15 different ones. After the fifth try, I just had to know if it was just my poor initial selection or a general problem.
Each and every iOS TOTP app has at least one crucial problem - requiring a subscription, mandatory sync to a proprietary cloud, having no export-import, not having a watch companion, being from an unknown/generic developer, no support for longer TOTP codes (worse, some display it truncated!) or they're simply very buggy.
I settled on Step Two because it was like all the others, but not an eyesore...
Is there a standard app developers can use to securely sync/backup to for self-hosters? Is there a 'nice' UX/flow to connect apps to s3-style storage (enabling folks to use AWS/DO/Backblaze/whatever?) or would that be too raw?
One would have to set a password that they then store in a password manager, that is then accessed using the same 2FA protected by the password. Plus a mandatory PIN, with the same caveats. Cyclical or duplicate authentication is simply not good design.
Great!
(Side note: Authy backups are encrypted client-side with the user's backup password. They're not unprotected on a third-party server; Authy has no ability to decrypt them. https://authy.com/blog/how-the-authy-two-factor-backups-work...)
Had to manually contact them to resolve and then close the account because FUCK THAT, and fuck SendGrid too, which did the exact same thing after Twilio acquired them.
Sorry, I don't buy for a second that that was an accident or negligence. I'm sick of watching people play ball with companies that pull such moves. (Edit: you want to KYC me to prevent abuse? Fine. Don't make my startup insecure to achieve it.)
Authy is just not a good suggestion here when there are standard, non-needlessly-tied-to-sms options.
Also to be totally honest, each device should have their own TOTP key and while backups are fine*, key sharing isn't.
of course, they're not open source, so I'm not really going to bat for them here, but am I missing something?
https://authy.com/blog/how-the-authy-two-factor-backups-work...
https://www.ghacks.net/2022/08/10/twilio-the-company-behind-...
etc.