Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cloudflare should probably deprecate their Authy provider, considering they support other more secure MFA options (hardware and virtual WebAuthN). I believe Wise (ex TransferWise) and Plastiq also use Authy natively for SMS OTP server side, but provide no mechanism to disable SMS 2FA (boo).

https://authy.com/guides/cloudflare/



There's no "Use Authy" option any more in Cloudflare. It just says:

    Mobile App Authentication
    Secure your account with TOTP two-factor authentication.
And clicking the button gives you a generic QR code to use with app of your choice.


Thank you for correcting me, Cloudflare was presented as an Authy token that would be destroyed when I deleted my Authy account and some of the docs I found led me to believe this was still actively in use. I retract the Cloudflare part of my above comment.


No need to apologize. We did use Authy for a long time but allowed more general TOTP solutions from 2017 and have really pushed hard for people to use hardware keys.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: