The major pro is their seed length, which is significantly longer than Google Authenticator. The major con is you have to trust that they are using a secure system.
[1]https://news.ycombinator.com/item?id=4916983
The major pro is their seed length, which is significantly longer than Google Authenticator. The major con is you have to trust that they are using a secure system.
[1]https://news.ycombinator.com/item?id=4916983
From my discussion with the founder on that HackerNews thread yesterday (and his other comments on the thread), it seemed clear that they didn't have a good enough understanding of the space - both the technical security requirements and the existing solutions. If you're not clear on what problem you're trying to solve, I doubt that you understand the domain well enough to solve it properly - at least when it comes to security.
Security is one field where 80% of the way isn't "good enough" - in fact, 80% may be worse than nothing at all.
First, he was way off the mark on a number of unrelated elements, not just the key-strengthening algorithm.
While it's good that he owned up to his mistake, it's clear from his wording that he was shaky on the actual principles of security and encryption, not just
My standards for a security-sensitive product are far higher than for anything else. Any person in any position of authority should have a very clear understanding of the security fundamentals being used. The last thing I want in a 2FA application is for an overeager PM to make a decision that inadvertently compromises the security of the product, in a well-meaning attempt to improve the UI, branding, monetization, etc.
Product design and technical implementations do not happen in separate silos. And I want the security products that I use to inspire a much higher level of trust than some generic tool.
Given the security setting, I am comfortable with the tradeoff. I do not think brute-force attacks represent a significant risk, especially compared to other attack vectors.
That may change over time. Fortunately, it's straightforward to increase the default key size.
I think people are confusing the Authy Google Authenticator Support with the Authy product.
We do not sell Google Authenticator or aim to be a replacement for it. We simply added the possibility to add Google Authenticator tokens into the Authy App - mostly since our existing clients wanted this -.
Our Service, it's usage etc are completely separate.. If you are not using Authy you can simply use Google Authenticator App.
The only thing in common is we both use RFC 6238 which is an open standard for Time based OTP's.