The Risks of Google Authenticator's Account Syncing

1 min read
Source: The Register
The Risks of Google Authenticator's Account Syncing
Photo: The Register
TL;DR Summary

Google's updated Authenticator app adds Google account synchronization, but the sync process isn't end-to-end encrypted, potentially leaving the seed used to generate 2FA codes visible to Google when stored on its servers. Salesforce Community users are leaking private data due to misconfigured user permissions. A new Meltdown side-channel attack has been discovered that affects multiple generations of Intel CPUs and targets the EFLAGS register using a transient execution flaw to change context execution time.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

4 min

vs 5 min read

Condensed

92%

97274 words

Want the full story? Read the original article

Read on The Register