My personal favorite service is Authy, now part of Twilio.
My personal favorite service is Authy, now part of Twilio.
My understanding is that Sendgrid isn't too keen on dongles.
I prefer a stand alone app or device for that. Why would Authy demand that I give them a phone number and an email address if not for monetizing (as in selling to anyone) my personal information?
Google and Github both require the use of app specific passwords if you have 2FA on. Which means that accessing anything that uses the API is no longer a matter of username+password+token, it means username+password+log into site+generate huge and ridiculous password that is only shown once+save that into the app.
It's a pain in the ass. Massively.
Compared to someone gaining access to your Gmail (and the rest of your Google platform services) account or Github access? Hardly.
I agree its not perfect, but its relatively painless for the benefit obtained.
There's no reason I can't generate my own app passwords, nor is there a reason to prevent me from accessing my own passwords later.
The only flaw here is when you aren't able to label your prior passwords and are only given the option to nuke them all. That ticks me off more than anything. I've got 2fa enabled most places that allow it now, and use Authy too. The only times it's been a real pita is when I've had to setup email on a new phone with a generated passphrase (I'm trying to stop using the "password"). Other than that has been one day where I forgot my phone at home and didn't go back to get it after I was in my car...
Certain classes of non-shared-secret hardware token are waaaaaaaaay better. Just less convenient. You should look into DoD CAC, for example. Google Authenticator is nice but will never protect Secret information. I know this sounds way out of startup league, but it shouldn't; we should instead study what we can learn from such things instead of blanket advice like yours.
Reiterating: none = bad, TOTP = better, strong tokens/biometric/etc = best.
Which of the solutions you mention works even if an attacker has actual physical access to the two-factor device?
Android specific?
TOTP protects against the most common threats, and is trivial to implement compared to other solutions you refer to.
Most of your complaints about TOTP security don't make sense under its threat model. Yes, if your phone is rooted, the TOTP secrets can be stolen. The point is that it's unlikely that both your phone and your laptop/point of access device both get compromised.
The reason people use authy and the like is because they make it simple to recover if you lose access to your device (lost, stolen, broken). My work around this is to take a screen cap of the QR codes and encrypt them with gpg. You could also save them inside a password manager (especially for less technical people).