Let us review the threat: MiTM - SS7 attack to retrieve the SMS for Authy. If that scenario happens, the attacker will have a grasp over your encrypted tokens meaning that the attacker needs the password (or a flaw in the encryption algorithm, which is less likely since they use industry-standard algorithms) in order to decrypt them. In such a case, the password complexity will determine how ...

Understanding the Context

Authy also displays the remaining time before a token times out so that you can see if it is about to expire. I also take a screenshot of every QR code so that I can register it again with a new device or a new MFA app. It’s time to update your iPhone or Android app after Authy admitted attackers have stolen up to 33 million users’ phone numbers. Authy, the app used by many people for two-factor authentication (2FA), ...

Key Insights

My understanding is that if you use Authy, without backups/multi-device options, none of your account keys are stored on their servers. It all resides on your single device. Ie, even if Authy se... Authy: Does multi-device mode imply that all keys are stored on their ... Secondly, the Authy OTP seeds between each of these devices ARE DIFFERENT.

Final Thoughts

Here is a side-by-side image of the Authy Desktop app and the Authy iPhone app. Notice the values are different! Google Authenticator seeds which are stored in Authy will be the same as they have only a single seed value which needs to be stored and shared. I have enabled Authy backups on my phone, and set the password. Then I installed the Chrome app on my PC, after I input backup password, the screen shows "Re-encrypting accounts". When this process Why is the use of Authy TFA more secure than just having a long password?

Presumably the user will record his Authy code right along side his normal password. No, the user should not do this. The user should record the code in a different system, or a system where it's not easily retrievable, but will provide codes, e.g. the Authy app.