Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Google Authenticator is a separate app that you need to download from Google Play. Native android solution is Google Password app which is pre-installed (at least on Pixel) and its functionality is extremely rudimentary even compared to Apple Passwords. No TOTP support there.

I think that Google does not care about security for their users, because their passwords app is clearly some intern work, not something really well thought. They just slapped it to mark a checkbox in their "Chrome password autofill" TODO list and moved on to a more pressing issues like implementing user tracking and extracting more ads revenue. Apple had similar issues for years, but I think that their recent releases significantly improved.



Until recently, Google Authenticator codes could not be backed up or transferred to a new phone. When I replaced my Android device, I had to re-register every TOTP code that I had in Google Authenticator. This led me to Authy, and later on to Yubikey since the code is removed from my phone completely.


I'm pretty sure you could always manually export a QR code for every one of your secret keys.


This was around 2016 and that was not an option at the time.

edit: the app used to be open source: https://github.com/google/google-authenticator-android/

"By design, there are no account backups in any of the apps."


My bad, that's too far in the past. I've changed Android phones several times between 2017 and 2020, and I remember using the QR codes exports.


It's not ideal but there's been some progress.

I'm not sure we can blame Google for not pushing their Authenticator more, most services have been dead set on SMS and are now slowly moving to Passkeys, probably for the best.


Passkeys are going to make these problems much worse.

What do you do if google/ms/apple won’t let you log in, or you lose a device, or you lose your phone?

If the answer is “there’s an account recovery path involving a password”, then just accept passwords!

If the answer is “recover the passkey provider account”, then that forces everyone to have a single password / security question / whatever that grants access to all their accounts.


I don't want Google to push their Authenticator, I want Google to retire their Authenticator, implement TOTP codes in their Passwords app (it's very trivial to implement) and implement passkeys on Google Chrome Linux (now those are not trivial, but if they push passkeys so hard, they could at least implement them). I also want to be able to store any items in Google Passwords manager, like ssh username/password, my bank cards, software serial codes and other sensitive information (again trivial to implement, just provide me multiline textedit with notes). I also want password generator in their app. I also want to configure multiple domains for entry, like microsoft.com + live.com. Are those big requests? I don't think so.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: