Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can’t speak to eSIM problems, but I’ve moved as much to synced passkeys as possible, and the last of my 2FA/MFA in Bitwarden will be migrated as those sites support passkeys.

As long as the data on my device is synced to iCloud storage or backups, that meets my needs. If the UX around an app is not great when switching phones or requires some esoteric incantations, I just won’t use it.



> As long as the data on my device is synced to iCloud storage

But is it though? That’s the major catch. Something as important as Google Authenticator is not backed up, so you must enable sync to your account to ensure you don’t lose it (which wasn’t a thing at all until recently)


Google Authenticator can sync to your account, now, meaning codes will be available from any new device.

https://security.googleblog.com/2023/04/google-authenticator...


That’s what I said, and I think it’s opt-in. GA is just one of many who silently opt out of iCloud.

> you must enable sync to your account


I don’t use nor recommend Google Authenticator. If you want a secure 2FA/MFA, use a hardware token or a passkey. TOTPs without a backup or sync is pain waiting to happen.

Of course, syncing TOTPs comes with its own threat model. Something to keep in mind.


Sometimes you don’t have a choice. Sometimes even if have that set up, the service will still send an SMS.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: