Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Scotty_Trees

macrumors newbie
Feb 28, 2023
14
16
Been using Authy for years but I’ve always been suss on the requirement for a phone number, especially as Twilio’s entire business model is SMS.

You should not have to, nor expect to, disclose your phone number in order to use a TOTP generator. My data has already been leaked so many times, so I migrated to 2FAS about a month ago in anticipation of an event like this. Sadly my data was leaked because Authy takes 30 days to delete an account 🙃

Do not use Authy.
you should've been like me and been using 2FAS Auth for the last 2 years, so this never would've happened! Also every account I use has a different password, no two are the same thanks to password managers like bitwarden baby yeah!!!
 

Premium1

macrumors 68000
Jan 26, 2013
1,526
1,903
Things like this happen all the time. Most of the time we never are even informed, even when they get way more than our phone numbers. It is near unavoidable in today's world.
It's plenty avoidable if these companies would take security of user data seriously, but they know nothing more than a slap on the wrist happens so they cheap out.
 
  • Like
Reactions: Jackbequickly

CalMin

Contributor
Nov 8, 2007
1,765
3,329
I was a big fan of Authy until they killed off the desktop version which was a major inconvenience to me. I've since switched over to the Step Two app https://steptwo.app/

It does pretty much the same thing but it's better integrated with Safari, and it uses iCloud to sync vs. some third-party. And it's free up to 10 accounts.

So long Authy!
 

redheeler

macrumors G3
Oct 17, 2014
8,514
9,016
Colorado, USA
Been using Authy for years but I’ve always been suss on the requirement for a phone number, especially as Twilio’s entire business model is SMS.

You should not have to, nor expect to, disclose your phone number in order to use a TOTP generator. My data has already been leaked so many times, so I migrated to 2FAS about a month ago in anticipation of an event like this. Sadly my data was leaked because Authy takes 30 days to delete an account 🙃

Do not use Authy.
Thanks, I’ll be switching away from Authy (have a few accounts on there for 2FA).
 

canadianpj

macrumors 6502a
Jun 27, 2008
509
422
I was a big fan of Authy until they killed off the desktop version which was a major inconvenience to me. I've since switched over to the Step Two app https://steptwo.app/

It does pretty much the same thing but it's better integrated with Safari, and it uses iCloud to sync vs. some third-party. And it's free up to 10 accounts.

So long Authy!

You could have installed the iPad version if you have an M series machine. Took me 15 seconds and I had my desktop application back again, not that using my phone was a burden mind you.

Curious, what did you and the people who ditched it switch to? Not that I plan to move.
 
  • Like
Reactions: jdogg836 and CalMin

jumpcutking

macrumors 6502
Nov 6, 2020
307
227
I don't see them as related. The desktop app was probably killed for lack of usage. (Unfortunate.)
I don’t discount this as a possibility but with universal apps from Apple - it shouldn’t be a problem for the Mac ecosystem.
 

eltoslightfoot

macrumors 68020
Feb 25, 2011
2,417
2,915
I switched to another app and deleted my account with them. I switched to 2FAS and they don't need an account at all--they use your icloud drive to store the data--which is only known to you.
 

nylon

macrumors 65816
Oct 26, 2004
1,398
1,035
This really sucks! I've been an Authy user ever since I set up my first 2FA. I intentionally kept my 2FA's separate from my passwords app.

Is there a way to easily migrate or do you have to go through and setup 2FA again for all accounts?

Any recommendations on alternatives?
 
  • Like
Reactions: Surfer13134

CarAnalogy

macrumors 601
Jun 9, 2021
4,511
8,277
Been using Authy for years but I’ve always been suss on the requirement for a phone number, especially as Twilio’s entire business model is SMS.

You should not have to, nor expect to, disclose your phone number in order to use a TOTP generator. My data has already been leaked so many times, so I migrated to 2FAS about a month ago in anticipation of an event like this. Sadly my data was leaked because Authy takes 30 days to delete an account 🙃

Do not use Authy.

I really regret ever using it, but early on it was one of the only options for two factor. And they didn’t used to be so bad, it was only after the acquisition. As usual.
 

fromgophonetoiphone

macrumors regular
Dec 6, 2017
199
294
My problem with Authy is their native tokens are based solely on SMS authentication.

Many people think Authy protects tokens behind a client side password but this applies to Google Authenticator TOTP Tokens backed up only. When you setup a new Authy install on a new device, you will see after completing SMS authentication, your Authy native tokens are unlocked.

The Google TOTP tokens are not unlocked until you type in a further password. This is a huge risk to Authy tokens which is why services like Coinbase already shifted away from Authy and require the standard RFC 6238 token.
 

SunMac

macrumors member
Jul 19, 2018
76
74
My problem with Authy is their native tokens are based solely on SMS authentication.

Many people think Authy protects tokens behind a client side password but this applies to Google Authenticator TOTP Tokens backed up only. When you setup a new Authy install on a new device, you will see after completing SMS authentication, your Authy native tokens are unlocked.

The Google TOTP tokens are not unlocked until you type in a further password. This is a huge risk to Authy tokens which is why services like Coinbase already shifted away from Authy and require the standard RFC 6238 token.
There only unlocked if you don't have a backup password added to your account. I just reinstalled authy today on a new device and even though I was able to log in and see what authenticator accounts I had, I was not able to use them until I entered my backup password which is different then the account password that is used to log in.
 

szw-mapple fan

macrumors 68040
Jul 28, 2012
3,560
4,450
Never even heard of Twilio, should we be concerned? :rolleyes:
It's a SMS service widely adopted for 2FA and other text messaging services. They list Lyft, Netflix, and Airbnb as their users, so you can imagine how many other large companies are using them. Chances are your number is among those 33 million.
 
  • Like
Reactions: JosephAW

npmacuser5

macrumors 68000
Apr 10, 2015
1,790
2,016
I wonder why these large databases allow large across accounts downloads and or copies. Seems it would be a rather easy fix, no copies over one. If internally a large move or copy needed, would require several layers of approval. Always bugged me how access allows unlimited activity.
 

CalMin

Contributor
Nov 8, 2007
1,765
3,329
You could have installed the iPad version if you have an M series machine. Took me 15 seconds and I had my desktop application back again, not that using my phone was a burden mind you.

Curious, what did you and the people who ditched it switch to? Not that I plan to move.

Thanks and yes. I do have the iPad version on my Mac - I just figured that it is a matter of time before they close this off.

I switched to Step Two (it was linked in my post above).

I hope Apple's new Passwords app will help with this too, but mainly so that my less techie family members can implement better security. Too many of them use the same weak password everywhere.
 

NoBoMac

Moderator
Staff member
Jul 1, 2014
6,010
4,625
so I migrated to 2FAS about a month ago

2FAS looks interesting,

Gave it a test spin the other day. Liked it but it currently does not encrypt the data file that is stored in iCloud. Supposedly will encrypt the file in the next major release.

 

djkilla

macrumors newbie
Dec 10, 2021
6
2
I also have been using Authy and have been doing some research on replacements. I'm down to 3 to choose from:

1) Ente Auth (Cross platform sync, end-to-end encrypted, desktop app)
- Recommended by Privacy Guides and Techlore
- Free
- Open source


2) OTP Auth (Cross platform sync, end-to-end encrypted, apple watch app)
- Recommended by Steve Gibson from GRC and Security Now podcast
- Free and one time payment $3.99 for Pro version
- Not open source


3) 2FAS (Cross platform sync, apple watch app, desktop app)
- Free
- Open source
** Could have better encryption
 

willzyx

macrumors regular
Dec 21, 2016
181
475
Got added to a random scam WhatsApp group on Wednesday. Maybe related to this hack?
This one isn't. Probably from previous phone number leaks from other companies. This is a very old scam. I've had these messages show up like 3 years ago.
 
  • Like
Reactions: DougieS

coolfactor

macrumors 604
Jul 29, 2002
7,267
10,074
Vancouver, BC
33 million numbers? I don't even know 33 people who use Authy. 🤯

...jokes aside, I really question the wisdom of using 2FA / security apps from companies that aren't well known. Something like Google Authenticator or Microsoft Authenticator would make more sense. A 2FA authenticator from.... Twilio...? Maybe not so much.

Gravitating towards well-known brands doesn't mean you're getting a better deal. Think: Chrome.

Twilio is a big well-known player, just not consumer-facing.
 
  • Like
Reactions: jagooch

coolfactor

macrumors 604
Jul 29, 2002
7,267
10,074
Vancouver, BC
With this and there desktop app dead, does this mean the service is dying? Should I move my codes? I’ve never seen an active service close a desktop app before like this. I suspect it was due to a script being able to export 2FA account data (Reddit post) and maybe it was turned off for security reasons BUT their documentation doesn’t mention anything other than - “End of Life” and here are alternative software options.

I've been moving to iCloud Passwords with Verification Codes. Works great, and automatically available on all devices once added to one. Slowly replacing Google Authenticator with this.

It can be a couple of extra steps to setup or get a code for some sites, but not a show-stopper, and better than grabbing the phone constantly. I'm much preferring iCloud Passwords due to the cross-device convenience.
 

Fowl

macrumors regular
Sep 28, 2018
132
139
I deleted the desktop Authy app when they said they'd stop supporting it, but didn't close the account. Should I install it on my phone just to close the account, then remove it?
 
Last edited:
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.