mysk ,
@mysk@mastodon.social avatar

Google Authenticator still syncs two-factor authentication secrets without E2EE. If you enable cloud syncing, this means:

1️⃣ Google can read the secrets and generate one-time passwords for your accounts
2️⃣ Google knows the services you use
3️⃣ knows your usernames
4️⃣ Given a court order, Google is obliged to hand over this data to law enforcement


https://defcon.social/@mysk/110262313275622023

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines