Google Authenticator’s new syncing feature raises security concerns (2024)

A new Google Authenticator sync-to-cloud feature for its two-step verification app is coming under fire by privacy advocates who claim communication between endpoint and cloud is unencrypted and can be snooped on by adversaries.

The sync feature was added by Google to help users back up their two-factor authentication code sequences to the cloud allowing them to save time and restore authentications on multiple devices just by adding a new instance of the app on devices logged into a specific Google Account.

Researchers at Mysk analyzed network traffic of the updated Google Authenticator app and said “it turns out the traffic is not end-to-end encrypted.”

“Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices. TL;DR: Don't turn it on,” Mysk explained in tweet earlier this week. "Although syncing 2FA secrets across devices is convenient, it comes at the expense of your privacy."

Researchers said the lack of encryption opens users up to data leakage and a possible Google account takeover. A successful attack gives a malicious actor access to the two-factor-authentication's QR code used to generate a one-time code, allowing the bad actor to generate the same one-time code.

"Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access to your Google Account, all of your 2FA secrets would be compromised," Mysk wrote.

Paul Ducklin at Sophos’ Naked Security blog noted, anyone with a search warrant for your Google data can access authenticator sensitive data.

The Mysk researchers recommend privacy conscious users to turn off the new syncing feature in Google Authenticator.

A tweet from Google’s Christiaan Brand, product manager: identity and security, acknowledges the the privacy concerns and stated Google plans to roll out end-to-end encryption for Google Authenticator “down the line.”

“[Google] believes that our current product strikes the right balance for most users and provides significant benefits over offline use,” he wrote.

Google Authenticator’s new syncing feature raises security concerns (2024)
Top Articles
Ethereum Short Selling Guide - How to Short ETH on Binance | Coin Guru
Europejski Ranking Innowacyjności 2023
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 6161

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.