Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think you’re being a little paranoid:

https://support.authy.com/hc/en-us/articles/360036077534-Aut...

“How do you derive encryption keys from a Backup Password?

We use the National Institute of Standards and Technology (NIST) recommended algorithm PBKDF2.”



Oh no that's fine, I just didn't like the initial seeds for a new 2fa enrollment being magically transferred to the authy app without my control/intervention. See https://authy.com/guides/twilio/ and note that it's not the usual "scan the qr code". The seed is transmitted straight to authy, which, safe or not, takes away control from me to add that same seed elsewhere.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: