Authy got hacked, and 33 million user phone numbers were stolen - eviltoast
  • TheEighthDoctor@lemmy.world
    link
    fedilink
    English
    arrow-up
    50
    arrow-down
    7
    ·
    6 months ago

    I started using Authy instead of GA because every time I changed the ROM on my phone I would lose all codes, because I would forget every time.

    • Lem453@lemmy.ca
      link
      fedilink
      English
      arrow-up
      48
      ·
      6 months ago

      Use aegis, export the keys and then reimport them every time you switch. Trusting your second factor to a cloud is a disaster waiting to happen.

      If you want to get fancy setup your own cloud server (nextcloud, Seafile, owncloud etc) and set the backup folder for aegis to the self hosted cloud for easy restore every time you switch ROMs.

      • ruse8145@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        Simpler approach: auto export from aegis when an update occurs, syncthing or similar to your home PC. I have it synced across several computer in different locations and aegis is good enough to make unique filenames, combine with syncthing file history and I’m good for like 2 years of backups.

    • dev_null@lemmy.ml
      link
      fedilink
      English
      arrow-up
      13
      ·
      6 months ago

      GA now backups your codes in your Google account, so this doesn’t happen anymore.

      • ruse8145@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 months ago

        They had an obvious solution which is export to an encrypted text files and went with the option that lowers your security

        • dev_null@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 months ago

          Google usually goes with the lowest common denominator solution. There is a staggering amount of people who don’t know what is a file, let alone that phones have any.

    • laurelraven@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 months ago

      I’ve started putting mine into my Bitwarden vault as well as Google auth, mainly because I’m a bit paranoid I’ll wind up locked out of something by trusting a second factor too much

      • Coreidan@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        6 months ago

        With password recovery you shouldn’t be getting locked out of anything. I don’t see this being a risk.