The danger with Google’s new cloud backup for 2FA authenticator

Share This Post

Google’s new 2FA authenticator update could leave users vulnerable to single-point hacks and “SIM swapping” scams.

Google released an update for its popular authenticator app that stores a “one-time code” in cloud storage, allowing users who have lost the device with their authenticator on it to retain access to their two-factor authentication (2FA). 

In an April 24 blog post announcing the update, Google said the one-time codes will be stored in a user’s Google Account, claiming that users would be “better protected from lockout” and it would increase “convenience and security.”

In an April 26 Reddit post to the r/Cryptocurrency forum, Redditor u/pojut wrote that while the update does assist those who lose the device with their authenticator app on it, it also makes them more vulnerable to hackers.

By securing it in cloud storage associated with the user’s Google account, it means that anyone who can gain access to the user’s Google password would then subsequently obtain full access to their authenticator-linked apps.

The user suggested that a potential way around the SMS 2FA issue is to use an old phone that is exclusively used to house your authenticator app.

“I’d also strongly suggest that, if possible, you should have a separate device (perhaps an old phone or old tablet) whose sole purpose in life is to be used for your authentication app of choice. Keep nothing else on it, and use it for nothing else.”

Similarly, cybersecurity developers Mysk took to Twitter to warn of additional complications that come with Google’s cloud storage-based solution to 2FA.

This could prove to be a significant concern for users who use Google Authenticator for 2FA to log into their crypto exchange accounts and other finance-related services.

The most common 2FA hack is a type of identity fraud known as “SIM swapping” which is where scammers gain control of a phone number by tricking the telecommunications provider into linking the number to their own SIM card.

A recent example of this can be seen in a lawsuit filed against United States-based cryptocurrency exchange Coinbase, where a customer claimed to have lost “90% of his life savings” after falling victim to such an attack.

Notably, Coinbase itself encourages the use of authenticator apps for 2FA as opposed to SMS, describing SMS 2FA as the “least secure” form of authentication.

Related: OFAC sanctions OTC traders who converted crypto for North Korea’s Lazarus group

On Reddit, users discussed the lawsuit and even proposed that SMS 2FA be banned, although one Reddit user noted it currently stands as the only authentication option available for a number of fintech and cryptocurrency-related services:

“Unfortunately a lot of services I use don’t offer Authenticator 2FA yet. But I definitely think the SMS approach has proven to be unsafe and should be banned.”

Blockchain security firm CertiK has warned of the dangers of using SMS 2FA, with its security expert Jesse Leclere telling Cointelegraph that “SMS 2FA is better than nothing, but it is the most vulnerable form of 2FA currently in use.”

Magazine: 4 out of 10 NFT sales are fake: Learn to spot the signs of wash trading

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

DC Circuit Court Rules Kalshi’s US Election Bets Legal

This week, the US Court of Appeals for the District of Columbia Circuit has ruled in favor of the predictions market Kalshi, allowing the commodities exchange to offer event contracts based on the

Ethereum ICO Participant Offloads 6,000 ETH As Bearish Sentiment Intensifies

According to data from CoinMarketCap, the price of Ethereum slipped by 1023% over the last seven days in line with the general market negative movement This crypto market downturn has been attributed

Bitcoin Cash: Empowering Merchants and Boosting Adoption in Bitcoin Cash City

Bitcoin Cash (BCH) has emerged as a popular cryptocurrency, offering fast and low-cost transactions In the vibrant city of Townsville, Australia, BCH adoption has reached new heights, thanks to the

Bitcoin Bull Trend Still Persists Despite Pullback, Analyst Explains

An analyst has explained how the data of an on-chain indicator could suggest a bullish trend is still on for Bitcoin despite the latest pullback Bitcoin Coinbase Flow Pulse Is Still Signaling Bull

Bitcoin Futures Liquidation Forms Local Price Bottom — A Return To $65,000 Inevitable?

The price of Bitcoin hasn’t quite started the month as widely expected, falling to around the $60,000 mark on Thursday, October 3rd This bearish pressure is believed to have been triggered by

Sky Reports Over 1 Billion USDS Minted Since August Rebrand

It’s been approximately 38 days since Makerdao, the decentralized finance (defi) project, rebranded as Sky and launched both the USDS stablecoin and the SKY token During this time, more than a