What IT Teams should do about security concerns around the new Google Authenticator sync feature (2024)

Recent news of security concerns around a new feature in Google Authenticator may have IT teams wondering if they need to adjust any reliance on the app for authentication within their networks or apps their organizations use.

Launched in 2010, the Google Authenticator mobile app provided a more secure 2FA option to SMS one-time codes. The enhanced security came from how it worked – the app’s codes were generated on the user’s phone and never traveled through insecure networks.

The new feature allows users to sync 2FA codes across devices through the cloud – something users have wanted for a long time. It eliminates the need to reset each code with a lost or stolen device as well as streamlining access to 2FA codes on a new phone.

However, Mysk researchers reported on Twitter that the sync is not encrypted:

“We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. Why is this bad? Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access to your Google Account, all of your 2FA secrets would be compromised.”

Of course, this seems to contrary to the initial security offered by the app when it launched – that it provided an alternative to codes traveling through insecure networks.

SC Magazine summed up the concerns around the new secret sync feature for Google Authenticator:

“Researchers said the lack of encryption opens users up to data leakage and a possible Google account takeover. A successful attack gives a malicious actor access to the two-factor-authentication’s QR code used to generate a one-time code, allowing the bad actor to generate the same one-time code.”

The app is a very popular 2FA method, with over 100 million downloads on the Google Play store. However, this isn’t the first time security issues have been reported for Google Authenticator.

In 2020, an Android malware strain was reported as extracting and stealing one-time passcodes generated through Google Authenticator.

The app has also been previously flagged for lacking a passcode or biometric lock on the app itself, increasing the danger a lost device poses to an organization. This danger is of course increased for organizations who make use of BYOD where IT teams cannot wipe end user devices.

What Concerned IT Teams Can Do About Google Authenticator

The reality of this new feature from Google Authenticator is that the end user would have to turn this capability on so the immediate risk posed to an organization whose users are authenticating with the app is low.

However, concerned IT teams can still take action:

  • Advise end users of this new feature and recommend they do not turn it on until Google offers end to end encryption for it.
  • Make use of a flexible MFA platform where you can adjust how much weight a single factor of concern has in the user authentication process (like the platform that powers Specops uReset for Active Directory password resets – customers can see how to adjust their policies for situations like these in this post).
  • Don’t neglect the password. Google Authenticator is often the second factor. The risk any security concerns around the app pose only arise if the attacker gets by the first wall of defense – the password. When it comes to protecting your organization’s AD passwords against this risk, make use of solutions like Specops Password Policy which can improve password security and protect against the use of over 4 billion unique compromised passwords.

The other thing to remember is that no single MFA factor is bulletproof. Each has their own potential vulnerabilities and security risks. The pragmatic IT team knows this and makes choices that balance these risks against end user requirements. Taking this approach with protecting MFA as well as passwords themselves helps mitigate against any single issue.

Questions about how to handle the risk of any one factor in your environment? Our team would love to help – contact us.

(Last updated on May 5, 2023)

Back to Blog

    What IT Teams should do about security concerns around the new Google Authenticator sync feature (2024)
    Top Articles
    What Rights Come With Your NFT
    Trader Joe’s takes heat over alleged 'Racist' labels for ethnic products: TikToker sparks heated debate
    Katie Pavlich Bikini Photos
    Gamevault Agent
    Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
    Free Atm For Emerald Card Near Me
    Craigslist Mexico Cancun
    Hendersonville (Tennessee) – Travel guide at Wikivoyage
    Doby's Funeral Home Obituaries
    Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
    Select Truck Greensboro
    How To Cut Eelgrass Grounded
    Pac Man Deviantart
    Alexander Funeral Home Gallatin Obituaries
    Craigslist In Flagstaff
    Shasta County Most Wanted 2022
    Energy Healing Conference Utah
    Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
    Aaa Saugus Ma Appointment
    Geometry Review Quiz 5 Answer Key
    Walgreens Alma School And Dynamite
    Bible Gateway passage: Revelation 3 - New Living Translation
    Yisd Home Access Center
    Home
    Shadbase Get Out Of Jail
    Gina Wilson Angle Addition Postulate
    Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
    Walmart Pharmacy Near Me Open
    Dmv In Anoka
    A Christmas Horse - Alison Senxation
    Ou Football Brainiacs
    Access a Shared Resource | Computing for Arts + Sciences
    Pixel Combat Unblocked
    Umn Biology
    Cvs Sport Physicals
    Mercedes W204 Belt Diagram
    Rogold Extension
    'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
    Teenbeautyfitness
    Weekly Math Review Q4 3
    Facebook Marketplace Marrero La
    Nobodyhome.tv Reddit
    Topos De Bolos Engraçados
    Gregory (Five Nights at Freddy's)
    Grand Valley State University Library Hours
    Holzer Athena Portal
    Hampton In And Suites Near Me
    Stoughton Commuter Rail Schedule
    Bedbathandbeyond Flemington Nj
    Free Carnival-themed Google Slides & PowerPoint templates
    Otter Bustr
    Selly Medaline
    Latest Posts
    Article information

    Author: Melvina Ondricka

    Last Updated:

    Views: 6281

    Rating: 4.8 / 5 (68 voted)

    Reviews: 83% of readers found this page helpful

    Author information

    Name: Melvina Ondricka

    Birthday: 2000-12-23

    Address: Suite 382 139 Shaniqua Locks, Paulaborough, UT 90498

    Phone: +636383657021

    Job: Dynamic Government Specialist

    Hobby: Kite flying, Watching movies, Knitting, Model building, Reading, Wood carving, Paintball

    Introduction: My name is Melvina Ondricka, I am a helpful, fancy, friendly, innocent, outstanding, courageous, thoughtful person who loves writing and wants to share my knowledge and understanding with you.