Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Been using Authy for years but I’ve always been suss on the requirement for a phone number, especially as Twilio’s entire business model is SMS.

You should not have to, nor expect to, disclose your phone number in order to use a TOTP generator. My data has already been leaked so many times, so I migrated to 2FAS about a month ago in anticipation of an event like this. Sadly my data was leaked because Authy takes 30 days to delete an account 🙃

Do not use Authy.
you should've been like me and been using 2FAS Auth for the last 2 years, so this never would've happened! Also every account I use has a different password, no two are the same thanks to password managers like bitwarden baby yeah!!!
 
Things like this happen all the time. Most of the time we never are even informed, even when they get way more than our phone numbers. It is near unavoidable in today's world.
It's plenty avoidable if these companies would take security of user data seriously, but they know nothing more than a slap on the wrist happens so they cheap out.
 
  • Like
Reactions: Jackbequickly
I was a big fan of Authy until they killed off the desktop version which was a major inconvenience to me. I've since switched over to the Step Two app https://steptwo.app/

It does pretty much the same thing but it's better integrated with Safari, and it uses iCloud to sync vs. some third-party. And it's free up to 10 accounts.

So long Authy!
 
Been using Authy for years but I’ve always been suss on the requirement for a phone number, especially as Twilio’s entire business model is SMS.

You should not have to, nor expect to, disclose your phone number in order to use a TOTP generator. My data has already been leaked so many times, so I migrated to 2FAS about a month ago in anticipation of an event like this. Sadly my data was leaked because Authy takes 30 days to delete an account 🙃

Do not use Authy.
Thanks, I’ll be switching away from Authy (have a few accounts on there for 2FA).
 
I was a big fan of Authy until they killed off the desktop version which was a major inconvenience to me. I've since switched over to the Step Two app https://steptwo.app/

It does pretty much the same thing but it's better integrated with Safari, and it uses iCloud to sync vs. some third-party. And it's free up to 10 accounts.

So long Authy!

You could have installed the iPad version if you have an M series machine. Took me 15 seconds and I had my desktop application back again, not that using my phone was a burden mind you.

Curious, what did you and the people who ditched it switch to? Not that I plan to move.
 
  • Like
Reactions: jdogg836 and CalMin
I don't see them as related. The desktop app was probably killed for lack of usage. (Unfortunate.)
I don’t discount this as a possibility but with universal apps from Apple - it shouldn’t be a problem for the Mac ecosystem.
 
I switched to another app and deleted my account with them. I switched to 2FAS and they don't need an account at all--they use your icloud drive to store the data--which is only known to you.
 
This really sucks! I've been an Authy user ever since I set up my first 2FA. I intentionally kept my 2FA's separate from my passwords app.

Is there a way to easily migrate or do you have to go through and setup 2FA again for all accounts?

Any recommendations on alternatives?
 
  • Like
Reactions: Surfer13134
Been using Authy for years but I’ve always been suss on the requirement for a phone number, especially as Twilio’s entire business model is SMS.

You should not have to, nor expect to, disclose your phone number in order to use a TOTP generator. My data has already been leaked so many times, so I migrated to 2FAS about a month ago in anticipation of an event like this. Sadly my data was leaked because Authy takes 30 days to delete an account 🙃

Do not use Authy.

I really regret ever using it, but early on it was one of the only options for two factor. And they didn’t used to be so bad, it was only after the acquisition. As usual.
 
My problem with Authy is their native tokens are based solely on SMS authentication.

Many people think Authy protects tokens behind a client side password but this applies to Google Authenticator TOTP Tokens backed up only. When you setup a new Authy install on a new device, you will see after completing SMS authentication, your Authy native tokens are unlocked.

The Google TOTP tokens are not unlocked until you type in a further password. This is a huge risk to Authy tokens which is why services like Coinbase already shifted away from Authy and require the standard RFC 6238 token.
 
My problem with Authy is their native tokens are based solely on SMS authentication.

Many people think Authy protects tokens behind a client side password but this applies to Google Authenticator TOTP Tokens backed up only. When you setup a new Authy install on a new device, you will see after completing SMS authentication, your Authy native tokens are unlocked.

The Google TOTP tokens are not unlocked until you type in a further password. This is a huge risk to Authy tokens which is why services like Coinbase already shifted away from Authy and require the standard RFC 6238 token.
There only unlocked if you don't have a backup password added to your account. I just reinstalled authy today on a new device and even though I was able to log in and see what authenticator accounts I had, I was not able to use them until I entered my backup password which is different then the account password that is used to log in.
 
Never even heard of Twilio, should we be concerned? :rolleyes:
It's a SMS service widely adopted for 2FA and other text messaging services. They list Lyft, Netflix, and Airbnb as their users, so you can imagine how many other large companies are using them. Chances are your number is among those 33 million.
 
  • Like
Reactions: JosephAW
I wonder why these large databases allow large across accounts downloads and or copies. Seems it would be a rather easy fix, no copies over one. If internally a large move or copy needed, would require several layers of approval. Always bugged me how access allows unlimited activity.
 
You could have installed the iPad version if you have an M series machine. Took me 15 seconds and I had my desktop application back again, not that using my phone was a burden mind you.

Curious, what did you and the people who ditched it switch to? Not that I plan to move.

Thanks and yes. I do have the iPad version on my Mac - I just figured that it is a matter of time before they close this off.

I switched to Step Two (it was linked in my post above).

I hope Apple's new Passwords app will help with this too, but mainly so that my less techie family members can implement better security. Too many of them use the same weak password everywhere.
 
so I migrated to 2FAS about a month ago

2FAS looks interesting,

Gave it a test spin the other day. Liked it but it currently does not encrypt the data file that is stored in iCloud. Supposedly will encrypt the file in the next major release.

 
I also have been using Authy and have been doing some research on replacements. I'm down to 3 to choose from:

1) Ente Auth (Cross platform sync, end-to-end encrypted, desktop app)
- Recommended by Privacy Guides and Techlore
- Free
- Open source


2) OTP Auth (Cross platform sync, end-to-end encrypted, apple watch app)
- Recommended by Steve Gibson from GRC and Security Now podcast
- Free and one time payment $3.99 for Pro version
- Not open source


3) 2FAS (Cross platform sync, apple watch app, desktop app)
- Free
- Open source
** Could have better encryption
 
Got added to a random scam WhatsApp group on Wednesday. Maybe related to this hack?
This one isn't. Probably from previous phone number leaks from other companies. This is a very old scam. I've had these messages show up like 3 years ago.
 
  • Like
Reactions: DougieS
33 million numbers? I don't even know 33 people who use Authy. 🤯

...jokes aside, I really question the wisdom of using 2FA / security apps from companies that aren't well known. Something like Google Authenticator or Microsoft Authenticator would make more sense. A 2FA authenticator from.... Twilio...? Maybe not so much.

Gravitating towards well-known brands doesn't mean you're getting a better deal. Think: Chrome.

Twilio is a big well-known player, just not consumer-facing.
 
  • Like
Reactions: jagooch
With this and there desktop app dead, does this mean the service is dying? Should I move my codes? I’ve never seen an active service close a desktop app before like this. I suspect it was due to a script being able to export 2FA account data (Reddit post) and maybe it was turned off for security reasons BUT their documentation doesn’t mention anything other than - “End of Life” and here are alternative software options.

I've been moving to iCloud Passwords with Verification Codes. Works great, and automatically available on all devices once added to one. Slowly replacing Google Authenticator with this.

It can be a couple of extra steps to setup or get a code for some sites, but not a show-stopper, and better than grabbing the phone constantly. I'm much preferring iCloud Passwords due to the cross-device convenience.
 
I deleted the desktop Authy app when they said they'd stop supporting it, but didn't close the account. Should I install it on my phone just to close the account, then remove it?
 
Last edited:
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.