logoalt Hacker News

hocuspocusyesterday at 2:04 PM1 replyview on HN

> I'm surprised ios and android don't have native TOTP apps (afaik).

They do.

Google's Authenticator is as close as it gets to a native Android app, and your secret keys are sync'ed in Google's cloud for a while now (it's a shame they waited so long).

Apple's Keychain has supported TOTP for ages too.

That said OTPs over RCS instead of SMS are a major improvement if you don't mind your phone number being used as an identifier.


Replies

vbezhenaryesterday at 2:15 PM

Google Authenticator is a separate app that you need to download from Google Play. Native android solution is Google Password app which is pre-installed (at least on Pixel) and its functionality is extremely rudimentary even compared to Apple Passwords. No TOTP support there.

I think that Google does not care about security for their users, because their passwords app is clearly some intern work, not something really well thought. They just slapped it to mark a checkbox in their "Chrome password autofill" TODO list and moved on to a more pressing issues like implementing user tracking and extracting more ads revenue. Apple had similar issues for years, but I think that their recent releases significantly improved.

show 2 replies