[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Which is more secure for 2FA? SMS or Google Authenticator? I

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 17
Thread images: 2

File: 1490639662487.jpg (713KB, 1920x1080px) Image search: [Google]
1490639662487.jpg
713KB, 1920x1080px
Which is more secure for 2FA?
SMS or Google Authenticator?

I read that if someone compromises the server for the site you are authenticating, they can predict your Google Authenticator keys indefinitely, but some people believe that Google Authenticator is more secure because there have been instances of people socially engineering mobile providers to get a new SIM and "stealing" the target's phone number and account.

So which is it? Hijacking someone's phone to me sounds a lot more complicated, time-consuming, as less payoff than compromising a server and thus having all accounts, so which is better in actuality?
>>
Google authenticator. No one has ever had their account compromised while using it. SMS happened to a ton of big youtubers a while back.
>>
>>61330585
>>61330552
SMS only as secure as your carrier's ability to not change your SIM to any bloke that says that they're you.
Google Authenticator is much more secure.
>>
>>61330552
>>61330585
>>61330851
yeah go with google auth. I use it works great. i use duo to, not as great.
>>
>>61330552

How's that OpenVPN testing coming along?
>>
>>61330868
The biggest risk with any of these authentication apps is the possibility of malicious apps taking screenshots/screen recordings of your device.
I wish Google would push an update to Authenticator that disallows screenshots/recordings when in the app. An app that does it well is Telegram when using the end-to-end encrypted (shitty encryption anyway) secret chats.
>>
>>61330552
everytime ayumu gets posted i'm reminded how much i hatred and seething rage i have for wakaki
>>
I'd recommend Authy over Authenticator for it's backup and restricted multi-device features, as well as if you use any 2FAs that use authy (Cloudflare, Twitch, and Humble Bundle come to mind).
>>
>>61331065
>backing up 2FA keys to a server you don't own
>>
>>61331065
hate that they fucking make you use authy for those sites. fuck that shit.
>>
>>61331094
Does the server in your garage actually have better security?
>>
>>61331065
Using authy which could easily have access to your backup not using Superior AuthWard™ with its sleek ui, nice managable selection of codes and protection, and no bullshit backup.
Also I'm not a shill and no sheckles where given to me to say this.
>>
>>61331133
Considering my home server is not internet facing and doesn't have an attack surface for thousands or hundreds of thousands of people

yes, it does
>>
>>61330552
Jesus christ retard, stop using either of those. Use a standard oath application such as "Android Token" (available on fdroid). It's a technology standard for fucks sake.
>>
>>61331472
>oauth
fixed
>>
>>61330552
If they compromise the server it doesn't matter what you use. Are you fucking brain damaged?
>>
>>61331540
>oath
Wasn't broken in the first place.
https://en.wikipedia.org/wiki/Initiative_For_Open_Authentication
Also thanks >>61331472 anon, TIL.
Thread posts: 17
Thread images: 2


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.