31 comments

[ 1.6 ms ] story [ 80.8 ms ] thread
> Twilio, Authy’s parent company, is also moving Authy’s customer support hub to the help center on Twilio’s website after January 15th, 2024.

> Twilio says it made the decision to sunset its desktop app to “streamline our focus and provide more value on existing product solutions for which we see increasing demand.” The company laid off 5 percent of workers in December 2023, and it just announced on Monday that it has replaced its CEO.

Ironically, I was planning to move from Google Authenticator to Authy precisely because Authy had a desktop app. Oh well, that's one less thing for me to do, and one less user for Authy!
Google Authenticator is just a TOTP client. You can just copy the token to any app. I'd personally recommend KeePassXC.
The start token, yes. If you don't capture the start token then I don't believe there's a way to extract it from GA.
WTF? Does it cost more money somehow to serve the desktop app than the mobile app?

Not looking forward to having to type codes vs copy-paste..

I know on iOS you can copy-paste between the iPhone and your MacBook. I recall there being various clipboard syncing options on other platforms.
So what’s the alternative option here for a mobile and desktop 2fa?
Some password managers allow you to do 2FA autofill, I’ve been moving mine into 1password, but when it doesn’t autofill it isn’t as fast to go pull it up manually as it was with authy, still worth it overall, though
Ive been using the 2FA in bitwarden and it rocks.
On Windows, you can use a variety of Android 2FA apps. With a bit of messing around, you may even be able to get the Authy Android app working. On other platforms, there's a variety of open source and not-so-open source TOTP apps you can use instead.

Authy does have some proprietary stuff (partnership with companies for auth push notifications, for example; I've seen this on Twitch) but most companies just use the TOTP/HOTP functionality that's available in all manner of apps.

Android: Aegis or ente

iOS: ente

PC: 1Password, Bitwarden, KeePass

(comment deleted)
Seems like requiring second factor to be on a different device would actually enhance security a bit... No?
I saw an infra guy using 2fa with the desktop app and had the same reaction. Like wait, why is that a thing...
Perhaps, but I don't think it should be a strict requirement. A locked-down, encrypted laptop with all of its keys stored securely in a TPM will do just fine when all you want to prevent is hackers from another country using credential stuffing to log into your online environment. It mostly depends on what kind of threads you're trying to defend against.

Then again, with passkeys and Windows Hello/TouchID becoming more and more usable in real life, I think the Authy app has better replacements available that are built right into the operating systems already.

The real kicker is Authy's sync feature; you're basically locking your 2FA behind a password and a phone number. It's another thing attackers need to hack, but it's inherently weaker for protecting access than the "hardware you need to destroy to get the secrets" types of second factors.

The second factor is not meant for securing you against a compromised system and if you really think about it you already lost mostly when your system is compromised (stealing sessions credentials etc). The second factor usage is to secure that you are really you and securing a service against external unknown logins.

The attack vector is the following: Somehow a hacker gets your username and maybe a password you use often or using an brute force attack on an internet service. The second factor basically asking: Is that really you? When the second factor is on the same device (which you own) then that's also a valid way to say "yes, it's really me".

Also think about it: When you login on a phone browser or phone app both things are on the same device. Same logic.

The iOS app runs ok on Apple Silicon Mac. In fact I prefer its UI to the desktop app I was using before it was retired
I didn't know you could run iOS apps on Apple silicon Macs. I will look into this now!
The desktop app is also buggy and slow, while the iOS version runs perfectly on Mac.
Darn. Use it on the regular for daily desktop ops.

What I don't understand is the need for a mobile device handy to access stuff on desktop. I mean I understand how that increases security but why isn't access to the app, which is basically locked behind the OS login/authentication a pretty good setup. Because a hacker already having access to the laptop invalidates it? In a stolen/compromised desktop scenario I can still access my 2fa synced on mobile and lock them out no?

Tried the desktop app a few years ago. Decided that turning 2FA into 1FA wasn't a good idea.

If I decided that it was worth the risk, then I'd probably use 1Password's 2FA integration instead.

CRAP.

Is there _anything_ else available that can run on multiple platforms including desktop, and sync your stuff between them?

I really want to have access to the codes on my desktop AND I _need_ multi-device syncing -- I am absolutely unwilling to be in a state where losing a device loses me access to everything (unless I have all my "backup codes" which i definitely will never).

Any suggestions?

I think Bitwarden might be your best bet.
Thank you i'll check it out. It's free?

If I wanted to pay, looks like 1password also does it. (Or if I already had 1password which I should prob have anyway).

I'm of the opinion that Authy should be sunset in favor of TOTP. It's required use in Twitch is deeply problematic. There's just no space for this sort of solution with TOTP authenticators being far more ubiquitous, and open.
I thought Authy was a TOTP authenticator? I thought I was using it as an "Authenticator App" in places that require a TOTP authenticator, and can use any TOTP authenticator implementation, and Authy is the one I was using.

But this stuff confuses me, I am not shocked if i'm wrong. Can you explain where I'm going wrong, or provide a link to help me understand it?

I don't use Twitch; it sounds like maybe Twitch doesn't let you use any TOTP authenticator, but _requires_ you to use Authy? (weird!) But maybe Authy is still a TOTP authenticator?

Authy supports TOTP, but it also provides it's own proprietary secret TOTP alternative, and that's what Twitch uses unless something has changed. You cannot use anything other than Authy for Twitch.
A shame. It already saved my a* once when my phone died and I could still login normally to all my sites.