Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

People recommend Authy. As far as I can tell they rely on cloud sync/backup like any other app in that space.

Isn’t google authenticator not using this on purpose? Central account and sync is googles thing and yet they deem it too insecure. Completely understandable

So how can using a central service that adds yet another attack vector be of value?

What I would love to have is a paper export. Every time you add a new account to google authenticator you can print it as QR code for later reimport.

Yes many services already provide this for you via recovery codes but having it on a per service basis directly from authenticator is probably much easier to use and not less secure

Any reason this wouldn’t work?



I can't see any, based on my slightly more than superficial dive into this area when working on my own two-factor application.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: