Authenticator app advertising on App Store sends QR codes to developer
twitter.com
twitter.com
On a related note: security experts of HN which (if any) TOTP authenticator apps would you use/recommend? I currently use duo authenticator except for one thing which bafflingly will only work with google authenticator and not duo (don't ask me why) or things like steam or lastpass which have their own homebaked authentication app. Any reason to use something different?
oathtool -b --totp <otp secret>
The app is also handy for bootstrapping OTP, because some implementations only give you the QR-code, not the secret or URI, and then you have to do the dance with decoding the QR-code before adding it.
Something like: when you enroll your primary, it automatically tells the site about your secondary key. The secondary is protected by a PIN and has equivalent validity as the primary and if it's ever used, the site notifies you. If your primary is lost or stolen, you can use your secondary with the help of your "password" manager to automatically revoke the old primary on all accounts. When you buy a new secondary, the same protocol can be used to inform sites to trust it, after which you put in back in storage.
Your phone will never be a proper secure computer.