In the ever-changing world of technology and retai...
Google's Authenticator App Is Not End-to-End Encrypted, Putting Users at Risk for Security
April 27, 2023 By Monica Green
(Image Credit Google)
Google’s New Two-Factor Authentication Isn’t End-to-End Encrypted, Tests Show (Image credit- Yahoo News)
Image credit- Cyclonis[/caption]
Additionally, the experts mentioned that the app's traffic is not end-to-end encrypted. The screenshots, which were provided by Mysk, demonstrate that Google is very likely aware of your private information if it is kept on its servers.
If you are concerned that the Google Authenticator is not end-to-end encrypted, you can remove the connection between your Google account and the device to resolve the problem.
Mysk added that even while using several devices is thought to be advantageous, using the 2FA approach exposes the user's privacy. As a result, the business no longer advises customers to sync their accounts with the app.
This week, Google Authenticator tokens might now be saved on the cloud, according to a report from Mashable, giving customers more options for where to keep them as long as the Google Account is connected.
The dominant search engine claimed that this update fixed a long-standing issue with one-time codes that had been annoying users. The feature is optional, of course, and you have every choice to save it locally if you so choose.
[caption id="" align="aligncenter" width="1440"]
Image credit- Yanko Design[/caption]
While synching 2FA secrets is incredibly useful, Mysk researchers discovered that once the Google Servers are attacked, they would leak.
What's worse, the threat actor might be aware of the other details linked to your account, such as the account name and the app that's attached to it.
It's quite dangerous, especially for an activist or content creator who often manages numerous Twitter accounts with an alias.
According to Tommy Mysk, you shouldn't be concerned solely about hackers because Google employees may have unauthorized access to your data.
Tommy continues, "Missing the encryption on an authenticator tool is not a good thing." Additionally, this implies that Google will have more influence over the targeted advertisements it chooses to display to a specific audience.
Google is anticipated to treat 2FA secrets the same as passwords, according to Mysk. In other words, everything involving sensitive data should be handled with the utmost secrecy and care.
Leave a Reply
Apple's iOS 18: A Leap into the AI Era
March 12, 2024
Google's Regular Pixel 8 Won't Get Gemini Nano AI
March 12, 2024
MacBook Air M3 Makes Amends for M2's Storage Blunder
March 11, 2024
Samsung Unveils the Galaxy M15 5G
March 11, 2024
Elon Musk's xAI to Open-Source Chatbot Grok
March 11, 2024
Contra: Operation Galuga - A Modern Run-and-Gun Classic
March 11, 2024
Musk Confirms X's TV App Arrives This Week
March 11, 2024
RELATED NEWS
2
3
4
5
6
7
8
9
10