Hacker News new | ask | show | jobs
by sillysaurus3 4447 days ago
Random question: Is Authenticator secure from Google themselves? I thought "yes," but after thinking a little more it seems like the answer is "maybe not."

What's to prevent an app like Authenticator from uploading its cryptographic seeds to Google's servers?

I was wondering why a company would invest resources into creating an app like Authenticator, which seems to have no obvious path toward monetization. But if the company who writes Authenticator can also spy on its users, then that might be the answer.

1 comments

It's not hard to decompile and verify Authenticator if you really need to.

IMHO the real problem is the actual OS :/