Google Authenticator to get E2EE following complaints it is now less secure


It appears the new 2FA account cloud-syncing feature in Google Authenticator isn’t end-to-end encrypted, but this feature will be coming at a later date.
Google recently updated its authenticator app to allow users to back up their saved accounts that require a Time-based One Time Passcode (TOTP) to authenticate their login, meaning that they can now easily transfer them to a new device.
However, security researchers Mysk sent out a tweet (opens in new tab) advising against turning on this functionality, as it isn’t end-to-end encrypted, meaning that Google or a third-party if the tech giant is breached, could see your codes.
Convenience trade-off
End-to-end encryption is a security and privacy enhancing feature that obfuscates sensitive content so that it can only be decoded with a key, such as a password. For instance, it is the cornerstone of popular messaging app such as WhatsApp, ensuring that content can only ever be seen by the sender and receiver – not even WhatsApp itself can take a peek.
Christiaan Brand, Product Manager for identity and Security, defended (opens in new tab) the omission by saying that the tech giant’s “goal is to offer features that protect users, BUT are useful and convenient.”
He added that “We encrypt data in transit, and at rest, across our products, including in Google Authenticator. E2EE… provides extra protections, but at the cost of enabling users to get locked out of their own data without recovery.”
However, he also said that E2EE will be coming to various Google products, including now the authenticator, sometime “down the line”. He noted too that the app can still be used offline without having to sync 2FA accounts to their Google Account.
If you are using the Google Authenticator, then you may be using it conjunction with the Google Password Manager. While it isn’t our choice as the best password manager, it does allow for on-device encryption, which means that your own device stores the key internally to unlock access to your vault. Also, Google says that this key is used to “lock your passwords before they’re saved to Google Password Manager”, which means that, like end-to-end encryption, your passwords cannot be seen Google or anyone else but you.
Google does caution, though, that this means that “if you lose the key, you could lose your passwords too.” But this on-device decryption could be part of the push from Google and other big tech firms to ditch passwords altogether in favor of passkeys, which they want to be future of credential security.
It appears the new 2FA account cloud-syncing feature in Google Authenticator isn’t end-to-end encrypted, but this feature will be coming at a later date. Google recently updated its authenticator app to allow users to back up their saved accounts that require a Time-based One Time Passcode (TOTP) to authenticate their…
Recent Posts
- Like the Crucial T705 but more affordable? Micron 4600 PCIe Gen5 SSD comes painfully close to its award-winning sibling
- Vizio Elevate SE 5.1.2 Soundbar Review: Cheap Thrills
- Our favorite apps for listening to music
- Leaked hands-on Samsung Galaxy S25 Edge video hints at its design and specs – and then disappears
- Nvidia confirms ‘rare issue’ with some RTX 5090 and RTX 5070 Ti GPUs – here’s how to check if you’re affected and to get a replacement
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010