Google Authenticator to get end-to-end encryption ‘down the line’

On Wednesday, April 26th, we shared how Google’s Authenticator application was discovered to not offer end-to-end encryption (E2EE). Earlier this week, Google announced that users would now be able to sync Authenticator to a Google account and use it across multiple devices.

However, when security researchers and app developers for the software company Mysk dug deeper into the change, they noticed that the underlying data wasn’t end-to-end encrypted. This opened up the possibility for Google getting a glimpse at users’ apps and data for the purpose of targeted ads.

Now, Google product manager Christiaan Brand has responded to criticism from security researchers. He said, “we have plans to offer E2EE for Google Authenticator down the line.”

With the Authenticator app synced to Google Accounts, users can easily sign into their accounts on new devices. Although this feature is a welcome addition, it raises security concerns, as hackers who breach a user’s Google account could gain access to numerous other accounts through the Authenticator app. If the new update featured E2EE, hackers and third parties, including Google, would not be able to see this sensitive information.

Brand added that while E2EE is a powerful feature, it comes at a cost. Google encrypts “data in transit, and at rest, across our products, including in Google Authenticator,” adding E2EE would come at the “cost of enabling users to get locked out of their own data without recovery.”

It is currently unknown when Google will offer E2EE for the Authenticator app.

Image credit: Shutterstock

Source: @christiaanbrand Via: The Verge

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TheDailyCheck is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected] The content will be deleted within 24 hours.