The Google Cloud Sync feature that could make you vulnerable (2024)

Multi-factor authentication (MFA), also known as 2-Step Verification, is a layered approach to securing your accounts. It combines two or more ‘authenticators’ like biometrics (e.g. your fingerprint), physical tokens and one-time passcodes to verify your identity.

Popular authenticator applications now include Google Authenticator and Microsoft Authenticator as they generate one-time passcodes.

What's the problem

One of the biggest challenges with adopting MFA via authenticator applications is the risk of losing the device that stores the app and authenticator codes for your important accounts like banking, email and social media accounts.

Losing the one-time passcodes, and therefore access to your accounts, could begin a long, time consuming recovery process.

To combat this issue, it’s possible to sync the codes to the cloud, and across devices. Then, if the device is lost, you can log in to your account (e.g. Google or Outlook) on a new device and retrieve your MFA codes.

What's the security concern?

Unlike other authenticator apps, Google Authenticator doesn’t use end-to-end encryption for codes uploaded to their cloud servers, making them susceptible to hackers during the sync. This also means that If an attacker gains access to your Gmail account, they could access all the one-time passcodes linked with your account at the same time.

This was what happened at Retool, a software development company.

The Retool story

Retool blamed a $15 million crypto currency hack on the Google Authenticator Cloud Sync feature.

The attack started when several Retool employees received targeted texts, claiming that a member of their IT team was dealing with an account issue that would prevent healthcare coverage [1].

An employee clicked the link in the text message and provided login details, including a MFA code. Shortly after, the employee was contacted by the attacker who was impersonating IT Support. They then handed over another MFA code which let the attacker login into the employee account and register their personal device to produce their own MFA codes.

The use of Google Authenticators Cloud Sync feature played a key role in this breach, as the attacker could access all MFA codes saved to the employee Google account, including several company accounts.

Convenience versus risk

Although syncing MFA codes across devices is convenient, it carries significant security risk if your account is compromised.

If you’re syncing high risk accounts (like business accounts or those with client information), I recommend switching this feature off so it can’t sync to the cloud and only allow authenticator apps to store secrets locally.

If you’re worried about device loss, you can generate and safely store or print one-time backup codes for your most valuable accounts.

It’s worth noting that there’s no way for an administrator to centrally disable Google’s Cloud Sync. If you are relying on Google Authenticator in your business, you’ll need to ask employees to switch off Cloud Sync themselves on their own devices.

How to turn off Cloud Sync:

Just follow these simple steps:

  1. Open Google Authenticator
  2. Select your picture
  3. Select "Use without an Account" from menu [2].

You’ll know the app has been switched off when you see a line through the cloud symbol.

Turn on multi-factor authentication (MFA) for your Parmenion Account today

We offer MFA for our platform and it only takes two minutes to set up through our secure Parmenion App. All you have to do is:

  1. Download the Parmenion mobile app
  2. Login to your Parmenion account via the Parmenion mobile app (this will automatically link your device to your account)
  3. Next time you login to your account via the browser, you'll be asked to authenticate using your mobile device.

[1] https://retool.com/blog/mfa-isnt-mfa/

[2] https://support.google.com/accounts/thread/216566901/how-to-turn-off-google-authenticator-cloud-sync-feature

The Google Cloud Sync feature that could make you vulnerable (2024)
Top Articles
कहां से आया था बैंक खोलने का आइडिया, भारत का ये पहला बैंक... फिर लग गया ताला
How Long Should a Workout Last?
Katie Pavlich Bikini Photos
Gamevault Agent
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Free Atm For Emerald Card Near Me
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
Things To Do In Atlanta Tomorrow Night
Non Sequitur
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Walgreens Alma School And Dynamite
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Bedbathandbeyond Flemington Nj
Free Carnival-themed Google Slides & PowerPoint templates
Otter Bustr
Selly Medaline
Latest Posts
Article information

Author: Aracelis Kilback

Last Updated:

Views: 5733

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Aracelis Kilback

Birthday: 1994-11-22

Address: Apt. 895 30151 Green Plain, Lake Mariela, RI 98141

Phone: +5992291857476

Job: Legal Officer

Hobby: LARPing, role-playing games, Slacklining, Reading, Inline skating, Brazilian jiu-jitsu, Dance

Introduction: My name is Aracelis Kilback, I am a nice, gentle, agreeable, joyous, attractive, combative, gifted person who loves writing and wants to share my knowledge and understanding with you.