Google Authenticator is a load of crap (2024)

I’ve never been a fan of 2fa, but once introduced to FIDO2 security keys, esp. together with passwordless login, I can’t look back.

A password is really secure until you use it. Once used, anyone or anything can have snooped it. Be it a keylogger, a screensharer, a bad web browser or just simply a fake website. Spilling the beans is easier than you think, and if you have a lot of money or other assets on the line, you really don’t want to rely solely on passwords.

Introducing multiple factors of authentication. It can be something you know, something you have, something you are. Google Authenticator takes the form of something you have — your mobile phone. Or, at least that is the story they go with. It’s not the case, really. Google Authenticator is at best another form of something you know — just like your password. It doesn’t truly bring another factor of authentication.

The problem lies in how Google Authenticator is set up. You go to some website, enable 2fa and are presented a QR-code to be scanned. The fundamental problem is that, the QR-code that is shown to you on screen, is the very private key of your Google Authenticator set up. If that QR-code is snatched, any person on earth can generate your one time passwords without you even knowing. It’s a fake sense of security you can’t trust.

All it takes is one bad web browser extension and you are f*cked. A web browser extension can steal both your passwords and your QR-codes, reducing your security to “complete garbage”. There is no way of knowing whether someone has snatched it or not. It’s no better than relying on the secrecy of your password itself. A set up process where the very private key is shown on screen is terrible and at best dumb luck.

This is the main difference with FIDO2 security keys. They are set up by having the USB-key present its public key to the website, while keeping its private key entirely secret on specialized hardware, never presented to anyone. When you log in, a one-way derivative of the public key and private key is sent to the website. The private key itself never leaves the device. This is fundamentally different from how Google Authenticator works.

With a FIDO2 security key you can be certain that no middle party knows the secret used to generate one time passwords. Heck, you can even set up a FIDO2 key on a compromised system and still be entirely sure of secrecy. In other words it’s a system you can actually trust, and that actually do fill the purpose of “something you have”, as the key cannot be (trivially) duplicated.

Further on, the ergonomics of passwordless is fantastic. You have some basic pin code on the device itself — not a complex long password, just some short digit sequence like 6778. Then you just touch the device and you are logged in. It beats Google Authenticator in every possible way. And you can have as many keys as you want, for back up in case of physical theft or for when you drop one of your keys in the toilet.

Google Authenticator is a load of crap (2024)

FAQs

What is the downside of using Google Authenticator? ›

Backup codes are sent online, which is often insecure. You and Provider share the same secret. If an attacker hacks into a company and gains access to both the password and the secrets database, he/she will be able to access every account completely unnoticed. The secret is displayed in plaintext or QR code.

Why is Google authentication failing? ›

This error occurs when third-party cookies and data storage aren't enabled in your browser. These options are required by the Google Sign-in library. For more information, see 3rd-party cookies and data storage.

Why won t Google Authenticator work? ›

Google Authenticator code may not work because the time isn't correctly synced on your Google Authenticator app. To set the correct time: On your Android device, go to the main menu of the Google Authenticator app.

Why does Google Authenticator keep saying wrong code? ›

The most common cause for Incorrect Code errors is that the time on your device is not synced correctly. To make sure that you have the correct time in your Google Authenticator app, follow the instructions for your operating system below.

What is the security flaw in Google Authenticator? ›

A Google Authenticator vulnerability that allowed the programme to keep sensitive user data in the cloud was recently brought to light by Retool. According to Snir Kodesh, Retool's head of engineering: The fact that Google Authenticator syncs to the cloud is a novel attack vector.

What is better than Google Authenticator? ›

Twilio Authy: Best for backups and multiple devices. Although it isn't as big or widely known as Google or Microsoft, Twilio's Authy app is one of the most impressive and feature-rich Google Authenticator alternatives.

Why does my authentication keep failing? ›

Signal interference from nearby electronic devices, neighboring networks, or other physical obstacles can cause slow or unstable connections, which could lead to network authentication issues. The easiest way to avoid signal interference is to reposition your Wi-Fi router.

What happens if I can't log into Google Authenticator? ›

If You're Not Logged In

If your email or phone number is linked to the accounts you've added to the Authenticator app, you should be able to use the site or app's account recovery method to get back in.

Why is Google Authenticator not secure? ›

The Google Authenticator 2FA app only secure if you enable Privacy Screen and build in a reliable backup. The most secure 2FA method uses a physical security key, but for a free option, authenticator apps are recommended over text message-based 2FA, which is vulnerable to SIM swap attacks.

Why has my authenticator stopped working? ›

If you're using mobile data, try switching to Wi-Fi and vice-versa. Make sure Airplane mode is off. Make sure you're using the latest version of Authenticator - Microsoft does not support any app versions more than 12 months old. Tap Settings and make sure App updates is turned on.

Why is my authenticator app not allowing me to enter the code? ›

Microsoft Authenticator App Issues: There could be a temporary issue with the Microsoft Authenticator app, or the app may not be configured correctly. Try uninstalling and reinstalling the app to see if this resolves the issue. Microsoft Account Issues: There could be a temporary issue with your Microsoft account.

What to do if you can t access your authenticator? ›

Google Authenticator apps are tied to a particular device and cannot be recovered remotely. But it is possible to recover Google Authenticator access to your account by logging in through a new phone or using the recovery codes provided when you first logged in.

Why does my Authenticator app keep saying wrong code? ›

The most common cause for "Incorrect Code" errors is that the time on your Google Authenticator app is not synced correctly. Follow the instructions to make sure that you have the correct time in your Google Authenticator app. For Android users: Go to the Main Menu on the Google Authenticator app.

Why is Google Authenticator always invalid? ›

Google Authenticator: Invalid tokens are caused by incorrect device clock settings. Your clock must show the correct local time, date, and time zone to work properly. Android and Windows phones have an option to correct for time errors inside the Authenticator app properties if you do not wish to sync your clock.

Why aren t my Google verification codes working? ›

My Google Authenticator codes don't work

It may be because the time isn't correctly synced on your Google Authenticator app. On the next screen, the app confirms the time has been synced. You should be able to sign in.

What are the disadvantages of authenticator app? ›

Access to your accounts can also be lost due to protection being too strong. Like if after you've prohibited getting into your accounts without a code from an app, you somehow lose the authenticator. In this case, you might permanently lose your accounts and information in them.

Can hackers get through Google Authenticator? ›

In fact, authenticator apps don't even need internet access to perform their main function. All that a hacker can theoretically get is the actual one-time code that the system generates for you to enter. And this code is valid for just half a minute or so.

Can Google Authenticator be trusted? ›

The Google Authenticator 2FA app only secure if you enable Privacy Screen and build in a reliable backup. The most secure 2FA method uses a physical security key, but for a free option, authenticator apps are recommended over text message-based 2FA, which is vulnerable to SIM swap attacks.

Is the authenticator app good or bad? ›

Authenticator app FAQs

An authenticator app helps you to improve your online security by adding two-factor logins to any accounts you connect to the authenticator. This makes it harder for hackers to access your accounts, so we highly recommend using an authenticator app and two-factor authentication.

Top Articles
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 6197

Rating: 4.6 / 5 (76 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.