Hacker News new | ask | show | jobs
by zecaurubu 1410 days ago
#2: I believe they encrypt the backed-up tokens locally with a user-provided password [1]. The same password must be used to restore the backup. A malicious agent that "clones" your simcard will be able to obtain only an encrypted copy of your token data. This seems secure enough for me, but maybe I'm missing something.

[1] https://authy.com/blog/how-the-authy-two-factor-backups-work...