Bitcoin Forum
May 13, 2024, 07:08:51 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3]  All
  Print  
Author Topic: 2FA - Important Precautions with Google Authenticator  (Read 1100 times)
dragonvslinux
Legendary
*
Offline Offline

Activity: 1666
Merit: 2204


Crypto Swap Exchange


View Profile
October 03, 2019, 05:47:56 PM
 #41

Quote
People need to stop trusting this spof centralized server backup bullshit business if they care about their op sec.

Ever wondered why banks use vaults and time-consuming multi-login procedures, why cold storage exists etc? For me it's the same principles that apply here. But again this is just me who likes to secure my personal data with banking level security, as I do with cryptoassets. I don't feel the values are so different to me at least.

You were saying that centralized services were insecure, now "banking level security" is the best standard?
"Banking level security" is a cloud. There is no cold storage. (maybe in a few banks, but not most of them)

You just need an email and password and that is it. Sometimes a SMS or something like that through mobile, which is far less secure than 2FA or cold storage.

I mean banking in the conceptual sense, "to bank something". In this sense a keybank, similar to a sperm bank or blood bank (ignoring the securities or said examples as unrelated). Nothing to do with financial institutions known confusingly and generically as "banks". Banking your data and private information as you would bank your bitcoin: securely and through ownership. Some call it self-banking, but it's still banking. Apologies for the confusion through use of words.

Quote from: "To bank something" from a dictionary
A bank of something, such as blood or human organs for medical use, is a place that stores these things for later use.

Source: https://dictionary.cambridge.org/dictionary/english/bank#cald4-1-5

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
1715627331
Hero Member
*
Offline Offline

Posts: 1715627331

View Profile Personal Message (Offline)

Ignore
1715627331
Reply with quote  #2

1715627331
Report to moderator
If you want to be a moderator, report many posts with accuracy. You will be noticed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715627331
Hero Member
*
Offline Offline

Posts: 1715627331

View Profile Personal Message (Offline)

Ignore
1715627331
Reply with quote  #2

1715627331
Report to moderator
1715627331
Hero Member
*
Offline Offline

Posts: 1715627331

View Profile Personal Message (Offline)

Ignore
1715627331
Reply with quote  #2

1715627331
Report to moderator
1715627331
Hero Member
*
Offline Offline

Posts: 1715627331

View Profile Personal Message (Offline)

Ignore
1715627331
Reply with quote  #2

1715627331
Report to moderator
royalfestus
Hero Member
*****
Offline Offline

Activity: 2408
Merit: 516


View Profile
May 16, 2023, 08:39:51 PM
 #42

Quote from: Google Authenticator Security Risk
Google Authenticator's cloud sync feature is not end-to-end encrypted, and poses a high security risk if you use it.

🔑 Google Authenticator stores your private keys used to generate one-time codes every 30 seconds, and is used for two-factor authentication.

☁️ When the cloud sync feature is turned on, Google backs up your private keys without encrypting them behind an additional passphrase.

💥 This means that a malicious attack on your Google account will not only leave your passwords vulnerable, but your private key too.

💻 This allows hackers to log in to all your accounts with two-factor verification.
https://www.pcworld.com/article/1800132/google-authenticator-finally-got-cloud-backups-for-2fa-secrets-but-you-should-hold-off.html
🔒 Strongly recommend turning off the cloud sync feature.

1) On your device, open the Google Authenticator app.
2) Tap your profile photo.
3) Hit Use without an account.
4) Tap Continue.

I am unable to comprehend the suggestion to disable the cloud synchronization functionality.
bitmover (OP)
Legendary
*
Online Online

Activity: 2296
Merit: 5942


bitcoindata.science


View Profile WWW
May 16, 2023, 09:00:24 PM
 #43

Quote from: Google Authenticator Security Risk
Google Authenticator's cloud sync feature is not end-to-end encrypted, and poses a high security risk if you use it.

🔑 Google Authenticator stores your private keys used to generate one-time codes every 30 seconds, and is used for two-factor authentication.

☁️ When the cloud sync feature is turned on, Google backs up your private keys without encrypting them behind an additional passphrase.

💥 This means that a malicious attack on your Google account will not only leave your passwords vulnerable, but your private key too.

💻 This allows hackers to log in to all your accounts with two-factor verification.
https://www.pcworld.com/article/1800132/google-authenticator-finally-got-cloud-backups-for-2fa-secrets-but-you-should-hold-off.html
🔒 Strongly recommend turning off the cloud sync feature.

1) On your device, open the Google Authenticator app.
2) Tap your profile photo.
3) Hit Use without an account.
4) Tap Continue.

I am unable to comprehend the suggestion to disable the cloud synchronization functionality.

Google authenticator now has a cloud sync feature.
Many people are telling it is not safe, including binance.

My suggestion is that you move your keys to another authenticator,  such as aegis

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Velemir Sava
Member
**
Offline Offline

Activity: 231
Merit: 28

Enterapp


View Profile
May 30, 2023, 03:51:27 AM
 #44

That's right, the authenticator code works when logging into a platform and when processing withdrawal transactions from main account to the platform we are going to, be it an investment or trading account. and if it's gone like the case you said there must be a way out, namely confirmation on the relevant platform and directed to their technical team and just follow it to reset again. But if you are proficient, it is normal and back it up. so just re-enter the 2fa code.

▀███████▄            enterapp.io       |       CRYPTO WEB3 NEOBANK            ▄███████▀
                            PRE-SALE IS LIVE                           
▀█▄ ▀█▄ ▀█▄        D E C E N T R A L I Z E D   B A N K I N G        ▄█▀ ▄█▀ ▄█▀
Pages: « 1 2 [3]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!