Answer the question
In order to leave comments, you need to log in
Is Google Authenticator the safest?
Is signing in with Google Authenticator the safest way?
For example, compared with SMS authentication.
Thanks to.
Answer the question
In order to leave comments, you need to log in
Most - no.
More secure than SMS authentication - rather yes, because. an attack on the interception of SMS is easier (cheaper) to organize than on Google services (at the moment).
If you mean any services (not google). The presence of one or another method of two-factor authentication in itself does not automatically make it more secure. It is necessary to consider the threat model.
For example, where there is 2FA there automatically if bypassing 2FA through the same email, question answer, call to the admin - reset my 2FA, for some reason do not log in ...
Ok, Let's compare SMS and T-OTP. (Google Auth) :
- SMS can be considered more secure since the OTP secret key is stored only on the server. Attack simulation includes: 1) Find out the mobile phone number and the first factor of authentication, 2) fake SIM card or intercept SMS. But if the attacker is an insider with connections to Telecom, it's already hot)). Therefore, the main thing here is to choose an operator that is weakly susceptible to SMS attacks, or choose Email delivery as an alternative.
- In the case of Google Auth, the secret key can be stored in the user's Mail, in the same SMS, somewhere else they haven't followed it, because in order to set up Google Auth, you need to enter this Key on your phone or scan QRcod, which is even more dangerous. And it is already possible to simulate more "cheaper" attacks. Therefore, the main thing in Google Auth is to set up the employee's phone in the Admin's office.
Yes and no.
In the case of Gauth, a couple of dumb links leave the chain - a cellular operator and sms services, but there is no difference as such.
The advantage of Gauth is that you are not tied to the stability of SMS gateways.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question