Hacker News new | past | comments | ask | show | jobs | submit login

Your third point is not actually true.

Well, it is true, but there are a lot of other apps which don’t transfer to new phones. Google’s Authenticator app is such an example.

From what I understand: anything using the Secure Enclave as primary storage cannot be transferred.




Google Authenticator can transfer details to a different phone these days.

You get a notification at the top of the App for a few days to alert you to the transfer.


For those confused, like me, it seems that Google has finally updated their Authenticator app on iOS.

https://apps.apple.com/us/app/google-authenticator/id3884976...

I, like others, stopped using this app because it had dangerous bugs (app could delete the wrong token) and several limitations.


Maybe it's a poor example then, I wasn't aware of that.

Mobile BankID (Scandinavian Identity Service), my British Banking app and Okta verify definitely can't transfer to a new phone. I know because I checked recently.

My overall point is: they're not alone, this is a common issue for Apps.


Mobile BankID is running in the sim card, and transfers fine to new phones. Except the ones with embedded sims, i guess :/


My (Swedish) BankID definitely doesn't run from the sim card. :S I've had 4 phones in Sweden and I had to enroll it as a new device each time in Nordea.


This must be very recent - I changed my phone around June and this was not an option. So I moved all my accounts to Authy, and moved that instead, which brought everything to the new phone flawlessly.


The consumer "workaround" mentioned uses some sort of iCloud "Secure Enclave" Backup file of some sort and will restore data on a new phone if you use the "Recovery" option, which does transfer regular boring TOTP and the primary "consumer" MSA account and the recovery locks/bricks the same data on the previous phone in the process.

The additional issue mentioned is that while it works great for the MSA account and any boring TOTP you have setup it doesn't work at all for other Azure AD accounts of seemingly any stripe (Corporate Microsoft 365 accounts, B2B, B2C), which is surprising given it is Microsoft's Authenticator and they highly recommend using it, but it fails for Corporate MFA transfers. It just gives an error icon and not very useful error message.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: