Authy is joining Twilio
authy.com
authy.com
I switched to Authy when Google Auth 'forgot' all my tokens in one of its updates (which ended up being restored later), and Authy has worked flawlessly since then.
I'm guessing it was money+stock, probably a bit over 10M, given that authy just raised 3M in September (total of almost 4M)
again, just a guess out of thin air.
This is not in the spirit of 2FA.
I also understand why some people don't like clouds backups. The good news is that backups are off by default and optional. If you don't need them, you can keep them disabled.
https://twitter.com/authy/status/498244613766139904
@benmcginnes Yes we are RFC 6238 TOTP compatible.
Same algorithm as GAuth but 7 digits, 256 bit keys and 10 seconds window.
So why do you still need my phone number? There's no network connection or SMS required to generate those TOTP codes. I'm not buying the story that you need to text me or call me unless you're storing the seed/token centrally and sending it to users upon request which I strongly disagree with. That should only be stored on the user's device.If they don't have a phone number they can't do all that transparently, which is bad when you are aiming your service at a broad audience.
I'm not really interested in defending it, I probably don't like the idea of depending on a third party any more than feld does, I was just pointing out that there are simpler explanations for what they are doing than I'm not buying the story that you need to text me or call me unless you're storing the seed/token centrally and sending it to users upon request which I strongly disagree with.
Another one is that if they actually implemented TOTP like that their business would take a lot of damage when it was revealed publicly (because what's the point of paying for a broken implementation?).
This stuff is no more complicated than storing password hashes. Having a nice client app is good, but Google Authenticator is good enough. So instead of using authy and relying on a third party, why not get something like [4] and be done with it?
[1] https://github.com/nathforge/pyotp
[2] https://github.com/mdp/rotp
A couple of months ago I managed to break the screen of my tablet with 20-30 services I use 2FA (Google Authenticator). I had to spend about 50 bucks just to get a new screen and repair it.
For some of these services I had the token saved on my keepass, but I always felt a little dirty doing that. If there was a way to keep backups of Google Authenticator data, I'd take it in a heartbeat.
You could also add a U2F token and store that away.
I think Google's (or Microsoft's because I think they use a similar SMS-based 2FA) method could be easily manipulated by intelligence agencies for example with access to the carriers' networks. The Google Authenticator app is now completely useless for Gmail as well, since they made it to fallback to SMS-based 2FA if you forgot your password (ugh - why Google? WHY?!).
I am not very familiar with Authy, but I have built pin-code 2FA solutions using Twilio. Based on your comments, I am not sure the point of Authy if it is easy to build 2FA except TOTP using yesterday's Twilio.
If you're questioning yourself whether authy is trustworthy because they require you to provide a phone number for a 2FA-TOTP-Method that does technically not require it at all(!) and thus could pose a potential security degredation, check the FAQ about account recovery/passwords here: https://support.authy.com/hc/en-us/articles/115001950787-Bac...
Quote: * The Backups password is never sent nor stored in our servers for your security * Like the Backups password, the App Protection PIN (and optional biometric data) is never stored in our servers * Like the Backups password and App Protection PIN, the Master Password is never stored in our servers
the question still is if you trust those promises - but as authy is backed by twilio (thus lots of 2FA-SMS are already processed by them) the chances are good those guys know what they do and do it responsibly
Perhaps I should have read the instructions more carefully, perhaps I am an idiot. But I thought the purpose of an app linked to my cell phone number is that these codes would port automatically.
As a result, I will never use Authy again.
SMS validation seems to work fine, which is good business for Twilio. Not sure I understand the acquisition, unless Authy has some good math in their code generation process.
The ones that use their backend infrastructure are tied to your phone number, and are ported automatically.
Ones that you import from other TOTP-based systems via a QR code (like Google Authenticator) are private to your device by default. But if you really want, you can turn on the optional "backup" feature in settings, which will upload them to your Authy account and automatically port them between phones.
Sure, it requires an extra step... but to be fair, normal behavior for TOTP codes is to keep them 100% local to the device. I'd argue this is a reasonable default, given that security is involved. TOTP services almost always require a backup method (SMS or scratch codes) in case you switch phones, anyway.
Authy is one of the worst-designed iOS applications I have ever used. It has been this way for a very long time. They are actively hostile to people who try to criticize their poor design choices. I would not classify it as "dedicated to excellence."
CloudFlare forces me to keep it installed, so I have to interact with it on occasion. If you have more than about 3 services set up, you have to first scroll to expand the scrolling list of icons, then scroll multiple times to find and read the 10pt font name of a service, etc. It's awful. Compare it to Google Authenticator, which has a nice, big scrolling list of numbers and names. The one advantage Authy has is encrypted backup, which I like, and service lock-in, which annoys me.
Perhaps there's hope in somebody else taking over. Please, Twilio: prioritize _usability_.
FWIW, I have 4 services set up on it.
It's awful with dozens. I, for example, have four client AWS accounts, each with the AWS icon, that are rather difficult to distinguish between. The earlier iOS app (with a left-hand side drawer and larger text) was much better for me.
Current screenshot http://i.imgur.com/EzNc2g9.jpg
To be fair, Bluetooth pairing between iOS and OS X hasn't been the most pleasant experience in general.
--
Authy is a fine app, but the main selling point to me has basically always been the typical "anything but Google's half-abandoned BS".
I would not trust such liars with credentials to my most important services.
* TOTP
* Yubikey
* SMS
If you want to partner with someone and ram unnecessary apps down our throats, optionally add the following: * Authy
* RSA
* etc
I have places where I want 2FA but I will not install the Authy app, so I go without. Sorry. Let me use TOTP or my Yubikey.This is a pretty good example of not doing something because it represents a minority and would make onboarding more difficult for their actual value-add.
This seems awfully like "If you're going to offer 2FA, at least offer all the tools I like, before you offer any tools that I don't like".
It's also worth noting that Authy's app supports TOTP, last I looked.
(But I will use my Yubikey for U2F)
I also refuse to install Authy. I really, really do not like their creeping, creepy intrusiveness and the profiling it enables. I get the feeling that people don't actually understand Authy beyond "Hey, it backs up my secrets to the cloud. Cool!"
I recently had to renew my Google Authenticator tokens and I was tempted by Authy but the setup/onboarding sent me away screaming. Then I remembered the NEO can handle this (well except for Amazon tokens). Can't wait for U2F NFC to be standardized.
Give an option for those who deeply care about their security. If you're going to grab the industry by the balls and capture the attention of major industry players at least stick to your core values and offer an advanced/expert option for those of us who want to stay out of your system but still use 2FA.