Vamos falar sobre Verificação de Duas Etapas?

Atualmente utilizo o #Authy da #Twillio faz um tempão (desde 2019 basicamente), já utilizei o Microsoft Authenticator e Google Auth, não gostei de nenhum dos dois. Mas o Google Auth tem pelo menos opção de importar e exportar tokens, o que não existe no Microsoft Authenticator e Authy.

I assume that #Twillio realise that the only reason I use #Authy is because it'll sync across my mobile and laptop.
By ditching the desktop app they make themselves irrelevent.
Also, with a product roadmap like "fuck it, give them a month", I'll also never use a Twillio product again. What a complete dick move

Well this is a really fucked up #Rug_Pull!

At the time, I searched and searched and could not find any #FOSS solutions to achieve what I figure most everyone who must use #MFA / #2FA needs, namely:

  • A Linux desktop version
  • An Android version (F-Droid or .APK - not from the Google playstore
  • A Windows desktop version

Does anyone have suggestions as to how to achieve this, so that it syncs between all of your devices?

There are plenty (even FOSS versions) out there, but none of them that I know of that sync between all of your devices. If you lose your phone... oh well! But with Twillio you could just install it on a new phone and it would sync over all of your accounts from one of your other devices, laptop, whatev. I know it's proprietary, and that's a bad thing, but like I said, I couldn't find a single FOSS solution that had this very basic functionality of syncing between all of your devices.

Do you know of an authenticator that syncs between all of your devices? Feel free to boost and ask around, people shouldn't have to carry a phone around with them everywhere, let alone use a phone for your multi-factor authentication when your working on your desktop, and using your desktop/laptop to authenticate/signon to your accounts. That's just ridiculous.

https://www.theverge.com/2024/1/8/24030477/authy-desktop-app-shutting-down

We only have 7 months to migrate to an alternative solution. The Desktop version goes EOL and then dark in August.

If you have any suggestions, please do let me know

#tallship #Twillio #authenticator

.

Neenster

@carnage4life it's fair to mention Miguel has a mastodon account: @miguelgrinberg, here's the post sharing the fact he's not at #twillio anymore:

https://mstdn.social/@miguelgrinberg/110566044757625214

Miguel Grinberg (@[email protected])

Goodbye, Twilio. https://blog.miguelgrinberg.com/post/goodbye-twilio

Mastodon 🐘
@konst the #AWS SES product is good enough. What I dislike is the AWS management portal. #Twillio has good a #API and less account management overhead.
Twilio breach let hackers gain access to Authy 2FA accounts

Twilio's investigation into the attack on August 4 reveals that hackers gained access to some Authy user accounts and registered unauthorized devices.

BleepingComputer

Incident Report: Employee and Customer Account Compromise - August 4, 2022

https://www.twilio.com/blog/august-2022-social-engineering-attack

#security #twillio

Incident Report: Employee and Customer Account Compromise - August 4, 2022

On August 4, 2022, Twilio identified accounts of employees who were compromised by a social engineering attack. The attacker then gained access to data for a limited number of customers.

Twilio Blog
Tonight I would like to finish sending a text message to my cellphone using #Twillio API and a script in #Guile
IoT Potty Training

If you have not had children, stop reading now, we implore you. Because before you’ve had kids, you can’t know how supremely important it is that they take care of going to the bathroom…

IoT Potty Training

If you have not had children, stop reading now, we implore you. Because before you’ve had kids, you can’t know how supremely important it is that they take care of going to the bathroom…