If you use Google 2fa authentication app you probably should turn OFF the sync to cloud option

Retool blames breach on Google Authenticator MFA cloud sync feature

Software company Retool says the accounts of 27 cloud customers were compromised following a targeted and multi-stage social engineering attack.

bleepingcomputer.com/news/secu

if anyone gets access to your google account they can then instal the google 2fa app that will enable them to then get all your 2fa codes and see what accounts you have then start hacking your other accounts

switching cloud sync off means they can't as the 2fa codes are only on your device

begs the question though

why is a company using google authenticator app in the first place for employees

sidenote: google should add the feature "verify device" then when a new device adds google authenticator app the device the app was 1st installed on gets an alert to verify or not

sidenote:

you should enable google prompt

When you sign in to your Google Account via a new device you get a full screen alert notification on your main device(smartphone), you can tap that notification on your phone to confirm it's you or deny which will stop the sign in attempt - Google prompts give you info about the device, location, and time of the sign-in attempt.

enable it via your google account security 2fa

having google prompts enabled still allows you to to use 2fa app

@ecksmc
I use Aegis and recommend it also.

For iOS users, I like RavioOTP.

Follow

@voltronic @ecksmc
FWIW Aegis is on Fdroid as well
Aegis Authenticator (Free, secure and open source 2FA app to manage tokens for your online services)
f-droid.org/packages/com.beemd

Sign in to participate in the conversation

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.