Hacker News new | past | comments | ask | show | jobs | submit login

I use Authy and it does this too. I like that I can get the code on my phone or tablet. I also keep paper copies of the original QR codes in a safe place.





The trick with Authy is to disable multi-device access unless you're in the process of adding another device, so hackers and scammers can't add their own devices to your account without your aid. If you leave the setting enabled, someone may get your TOTP secrets from Authy before you can stop them.

If there is a trick to doing something securely, then that is already an automatic fail.

No. That's not "the trick". As soon as it's in the cloud, it's over, it's gone, you've lost the game.

I've been using Authy for around ten years now, so I lost the game a decade ago and the consequences have been nothing and the benefits have been something. Not a bad loss IMHO.

Good for you. Just wait and see...

You can just decode the QR code and use whatever secret is in there to generate the OTP codes. TOTP isn't that complicated, it's really just a second password that the system generates.

While true, I haven't yet seen an authenticator app that let's you just dump the topt code yet...

1Password can show the whole URI with the seed, and I have used it in the past to tediously restore seeds to my other 2FA apps.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: