If you use Google 2fa authentication app you probably should turn OFF the sync to cloud option
Retool blames breach on Google Authenticator MFA cloud sync feature
Software company Retool says the accounts of 27 cloud customers were compromised following a targeted and multi-stage social engineering attack.
if you wanna ditch google authenticator app
try Aegis
open source app
https://github.com/beemdevelopment/Aegis
/nosanitize
https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis
@ecksmc so FIDO: what devices are en vogue? Titan/yubikey/nitro/?
@b4cks4w i don't use any of them
have read about them though YubiKey seems to be popular and would probably be the one i got/get if/when i switch
@ecksmc
I use Aegis and recommend it also.
For iOS users, I like RavioOTP.
@voltronic @ecksmc
FWIW Aegis is on Fdroid as well
Aegis Authenticator (Free, secure and open source 2FA app to manage tokens for your online services)
https://f-droid.org/packages/com.beemdevelopment.aegis/
yeah it was you i got the heads-up from :)
sidenote:
you should enable google prompt
When you sign in to your Google Account via a new device you get a full screen alert notification on your main device(smartphone), you can tap that notification on your phone to confirm it's you or deny which will stop the sign in attempt - Google prompts give you info about the device, location, and time of the sign-in attempt.
enable it via your google account security 2fa
having google prompts enabled still allows you to to use 2fa app