Loss of popular 2FA tool puts security-minded GrapheneOS in a paradox - eviltoast

Losing access to Authy leads to another reckoning with Google’s security model.

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    37
    ·
    edit-2
    5 months ago

    This really isn’t about Authy specifically.

    It’s about a possible trend of Apps refusing to run without Play Protect (which GOS can’t provide) since it’s not a signed Google OS.

    It’s a worrisome trend, but I don’t think it will kill GOS because plenty of apps want to run on Chinese phones which cannot have Play Protect.

    Play Integrity, formerly SafetyNet Attestation, essentially allows apps to verify whether an Android device has provided permissions beyond Google’s intended models or has been rooted. Root access is not appealing to the makers of some apps involving banking, payments, competitive games, and copyrighted media.]

    The last paragraph of the article has a bad link, going to reddit and not the GOS page they said they would link… it should be https://grapheneos.org/articles/attestation-compatibility-guide


    The more I think about this, the more upset I become, this is removing user agency. Requiring verified hardware and software environments to run code has benefits, especially around security, but if someone wants to do banking from their VM they should be able to. The hardware should only empower user agency, never remove it.

  • 0oWow@lemmy.world
    link
    fedilink
    English
    arrow-up
    32
    ·
    5 months ago

    Um, if you’re security minded, you’re already staying far away from Authy, so I’m not really sure what the article’s focus is.

    That said, I’m using 2fa all day long on Grapheneos. No issue. And prior to Grapheneos, I ran rooted and had been using Authy with no issue, so this kind of sounds like an advertisement piece for Authy.

    • Eager Eagle@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      edit-2
      5 months ago

      Built-in synchronization of codes and ability to revoke devices.

      You’d need to set up e.g. Syncthing to have at least the sync part with Aegis, but the vendor lock-in of Authy is really not worth it.

      • 4am@lemm.ee
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        2
        ·
        5 months ago

        Bitwarden has a free 2FA app, and 2FA is integrated into autofill with the premium version of the password manager (which is $12/year) and is fully open source and even self-host able.

        Why go through all the trouble of KeePassX and SyncThing when it’s literally LastPass without downsides

        • Eager Eagle@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          5 months ago

          Aegis and syncthing*

          In my case it is because I don’t like the idea of having 2fa in the password manager. It partially defeats the purpose of 2fa.

  • Eager Eagle@lemmy.world
    link
    fedilink
    English
    arrow-up
    25
    ·
    edit-2
    5 months ago

    I don’t know why the article chooses Authy to showcase the issue, when it’s an app that is trivially replaced by alternatives (if one is patient enough to migrate). Finance and streaming apps are hardly equivalent on the other hand.

    “We don’t want to punish users of alternative OSes, but there’s really no other option at the moment,” Wilden added before his blunt conclusion. “Play Integrity has absolutely no way to guess whether a given custom OS completely subverts the Android security model.”

    We know what this is about, and it’s not about security. It’s about only allowing apps that make shareholders happy.

    • jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      5 months ago

      Thank you for sharing the Doctorow talk, its really good

      muted something he said… I wonder what it was

  • AmbiguousProps@lemmy.today
    link
    fedilink
    English
    arrow-up
    23
    ·
    5 months ago

    I’m not sure why the author thinks that Authy is the only option? I’ve never used it on my phone running Graphene.

    • AbidanYre@lemmy.world
      link
      fedilink
      English
      arrow-up
      24
      arrow-down
      1
      ·
      edit-2
      5 months ago

      Authy isn’t even the best option. Especially if you’re the kind of person who is going to run GrapheneOS.

      • anarchrist@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        1
        ·
        5 months ago

        It’s me. My bad. I was running Calyx OS and using authy and also just realized I’m in this boat after switching to Graphene so I finally sacked up and started using Aegis backed up to my nextcloud. I’ll be better.

      • sic_semper_tyrannis@lemmy.today
        link
        fedilink
        English
        arrow-up
        2
        ·
        5 months ago

        In that case those people probably wouldn’t be on Graphene anyways. If they’re open minded enough to try Graphene they’re probably open to trying new apps such as Aegis.

  • JoeKrogan@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    edit-2
    5 months ago

    FreeOTP+ is offline and in fdroid and let’s you export the entries you have saved. No third party needed. Just back it up as a habit every time you add a new entry. Store the backup encrypted with gpg or veracrypt or whatever

    • Saik0@lemmy.saik0.com
      link
      fedilink
      English
      arrow-up
      8
      ·
      5 months ago

      Even to get the fancy always online shit, run your own vaultwarden setup and use bitwarden.

  • Kairos@lemmy.today
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    1
    ·
    edit-2
    5 months ago

    page on their site

    links to reddit

    And Authy is runbby twillio which is owned by Facebook. Don’t give corporations control over this shit. They’ll take it away whenever they want.

  • terminhell@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    5 months ago

    Dang. Really hope this gets sorted soonish. In the market for something new and planned on going GOS or lineage.