evariste.gal🌈is Profile picture
🏳️‍🌈🦄 don't drink and root 🦄🏳️‍🌈 @Pitch Security. Formerly @smallpdf @arduino.
Feb 20, 2023 5 tweets 2 min read
🧵 mmm this thread is quite a nightmare from a security perspective, so, if you are moving to an authenticator app, here are my 2 cents:
1. Google Authenticator is fine if you know how TOTPs (usually) work. You can always save the 2FA seed in a safe place, have more phones 1/n or exports seeds via QR code. Google Authenticator doesn't offer the best UX for beginners, but it is easy, and it is secure (no cloud, no 2FA notifications, no SMS for recovering, etc);
2. Use a cloud-based TOTP service (e.g. Authy), they offer a better UX, 2/