(no title)
dvdhsu | 2 years ago
I do agree that we should start using hardware keys (which we started last week).
The goal of this blog post was to make clear to others that Google Authenticator (through the default onboarding flow) syncs MFA codes to the cloud. This is unexpected (hence the title, "When MFA isn't MFA"), and something we think more people should be aware of.
hn_throwaway_99|2 years ago
FWIW, nearly every TOTP authenticator app I'm aware of supports some type of seed backup (e.g. Authy has a separate "backup password"). I actually like Google's solution here as long as the Workspace accounts are protected with a hardware key.
The only real lesson here is that you should have been using hardware keys.
darkerside|2 years ago
Changing things to make it less offensive to someone who was offended really waters down your position.
deepspace|2 years ago
hn_throwaway_99|2 years ago