Post
Topic
Board Beginners & Help
Re: Security Alert: Update your Authy to the latest version
by
RickDeckard
on 09/07/2024, 11:00:22 UTC
So far I have never problem using Authy, so when I compared it with Google, Using Authy is simpler when we change cellphones, we can log in again using the same cellphone number and receive a code via SMS. I have experience lost the google 2fa code and can't login on 2fa. because of that, I prefer using authy for beginners who have weaknesses in storing data or code on paper.

From the very beginning I traded using Authy security. I think it's still safe and I feel comfortable with the automatic recovery feature and it can be used on multiple devices. I hope there are no other losses for me and other users later.

Then regarding the update problem, I checked in my application Authy that I have the latest version. I checked from the Play Store. Is this a little different from the one on the play store? Hopefully not. I see the details My update version is already in 25.11.
I had this discussion on the other thread that is addressing this breach more hands on, but I'll post the intervention here as well:
Bear in mind that this was not the first breach that Authy suffered. There have been a few already[1][2] and, to my books, more than 1 would be enough to convince me that they are not worth to have my data, let alone considering the type of service that they offer. Again, this is purely by personal opinion. The fact that you have to rely on a "non official" tool to export your 2FA codes[3][4] is just ridiculous and shows how deep they want you to be locked in to their app.
(...)

[1]https://www.twilio.com/en-us/blog/august-2022-social-engineering-attack
[2]https://www.engadget.com/twilio-authy-data-breach-202314313.html
[3]https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93
[4]https://help.ente.io/auth/migration-guides/authy/
If you know about all these breaches in the past and you make your risk assessment regarding Authy, then fine by me. I just don't like seeing users that do not have a full picture of the product that they are currently using.