SandbagTiara2816@lemmy.dbzer0.com to Technology@lemmy.worldEnglish · 6 months agoAuthy got hacked, and 33 million user phone numbers were stolenappleinsider.comexternal-linkmessage-square175fedilinkarrow-up1740arrow-down16cross-posted to: [email protected][email protected]
arrow-up1734arrow-down1external-linkAuthy got hacked, and 33 million user phone numbers were stolenappleinsider.comSandbagTiara2816@lemmy.dbzer0.com to Technology@lemmy.worldEnglish · 6 months agomessage-square175fedilinkcross-posted to: [email protected][email protected]
minus-squaremaryjayjay@lemmy.worldlinkfedilinkEnglisharrow-up11·edit-26 months agoYou can, though. But not through their app. Someone reverse engineered their protocol and wrote a program that connects like a new client, which you then approve, and it dumps all your random seeds into a text file. I then put them all into Keepass. Edit: Unfortunately, the author has deprecated the project as Authy has added some attestations to their API, seemingly for this exact issue. https://github.com/alexzorin/authy?tab=readme-ov-file
minus-squareTodd Bonzalez@lemm.eelinkfedilinkEnglisharrow-up10arrow-down1·edit-213 days agodeleted by creator
minus-square___@lemm.eelinkfedilinkEnglisharrow-up2·6 months agoRemind me to start a batch rekeying service.
minus-squareTodd Bonzalez@lemm.eelinkfedilinkEnglisharrow-up2arrow-down1·edit-213 days agodeleted by creator
minus-squarecan@sh.itjust.workslinkfedilinkEnglisharrow-up1·6 months agoIf there’s a benefit to such a tool would bad actors have already developed one?
minus-squaremaryjayjay@lemmy.worldlinkfedilinkEnglisharrow-up1·6 months agoThey got rid of the desktop app. Also, with shouldn’t have your seeds. They’re encrypted before they are transmitted to their servers and only decrypted on the device.
minus-squarealiceblossom@lemmy.worldlinkfedilinkEnglisharrow-up1·6 months agoDo you know what it’s called? I’d like to do this if possible.
minus-squareAngryCommieKender@lemmy.worldlinkfedilinkEnglisharrow-up2·6 months agoThey added a link, but the project has been deprecated
You can, though. But not through their app. Someone reverse engineered their protocol and wrote a program that connects like a new client, which you then approve, and it dumps all your random seeds into a text file. I then put them all into Keepass.
Edit: Unfortunately, the author has deprecated the project as Authy has added some attestations to their API, seemingly for this exact issue. https://github.com/alexzorin/authy?tab=readme-ov-file
deleted by creator
Remind me to start a batch rekeying service.
deleted by creator
If there’s a benefit to such a tool would bad actors have already developed one?
They got rid of the desktop app.
Also, with shouldn’t have your seeds. They’re encrypted before they are transmitted to their servers and only decrypted on the device.
Do you know what it’s called? I’d like to do this if possible.
They added a link, but the project has been deprecated