Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> 1. Authy tokens automatically sync even if you lose, change or upgrade phone.

So the tokens are stored on Authy's servers? Doesn't that defeat the purpose of two-factor? How do I (or an attacker) recover my tokens if I loose my phone?



You're correct - there are serious security concerns with Authy's product, which were pointed out on an earlier HN thread: https://news.ycombinator.com/item?id=4916983

Personally, I'd be concerned with trusting my credentials with any company unless all members of the leadership team (yes, including "nontech" people) are incredibly familiar with basic security terminology and practices.

(Note that the founder is unclear when PBKDF2 and AES are being used in the product, which is concerning, because they have very different use cases and should be hard to confuse).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: