Website Security & Threat Management
Choosing a Two-Factor Authentication System

Choosing a Two-Factor Authentication System

11/28/2012 · Matthew Prince

What this post added

This post details Cloudflare's exploration and adoption of two-factor authentication (2FA) to enhance account security. It highlights the decision to implement Time-based One-time Password (TOTP) based solutions, specifically favoring Authy over alternatives like SMS or Google Authenticator due to security concerns (e.g., carrier network insecurity, Google's past flaws, inability to revoke tokens, sync issues, and cumbersome phone upgrades). The post emphasizes Authy's superior implementation, including better token revocation, clock synchronization, seamless phone upgrades, and stronger cryptographic standards, ultimately leading to the rollout of 2FA as a feature for all customers.

Read the original post ↗