Authy > Microsoft Authenticator

Sometime earlier this year the internet picked up Twilio's announcement about discontinuing the Authy desktop app. That move honestly surprised me quite a bit. I wasn't sure why they were doing it, or what would happen to the mobile app. I took a deep breath and started planning a migration. You never know when they might decide to kill the mobile app too.

I knew from the start this would be a marathon, not a sprint. Start with the most important accounts, then carefully work through the rest. It took over three hours of focused work. Luckily I never locked myself out. But I did run into some fascinating approaches along the way.

  • "Just go ahead and set up your second factor, no need to verify the tokens are generating correctly. We'll just trust it." Already reported that one — blind faith, you know how that goes.
  • Some services don't ask for any password at all — literally anything — to disable 2FA.
  • In one case I removed 2FA and all my Security Keys and app passwords vanished along with it. That's a proper face-palm moment.
  • The final gem: removing 2FA only to discover that to use any app I now have to download that company's own application. How many of those apps would I end up with? 50?! Right then.

As a bonus I set up Passkeys wherever possible. Who wants to be dealing with passwords all the time.

Other Related Posts:

Google Authenticator vs. Authy

The pros and cons — why I switched from one app to the other.

Having a backup is always an advantage. But what do you do with two-factor authentication? Yes, most sensible services will offer you backup codes (usually 10). But what if that option isn't available? Will you back up the whole app...

16th Sep 2018