Google Authenticator App Gets Cloud Backup Feature for TOTP Codes

Google Authenticator

Search giant Google on Monday rolled out a major update to its 12-year-old Authenticator app for Android and iOS with an account sync option that lets users back up their one-time passwords (TOTP) in the cloud.

“This change means users are better protected from blocking and services can trust users to retain access, increasing both convenience and security,” said Google’s Christiaan Brand.

The update, which also brings a new icon to the Two-Factor Authenticator (2FA) app, finally aligns it with Apple’s iCloud Keychain and addresses a long-standing complaint that it’s tied to the device it’s on installed, making it a hassle when switching from one phone to another.

Even worse, as Google says, users who lose access to their devices completely “lost their ability to sign in to any service where they had set up 2FA using Authenticator.”

The cloud sync feature is optional, meaning users can choose to use the Authenticator app without linking it to a Google Account.

That said, it’s always worth considering the downsides associated with cloud backups, as a malicious actor with access to a Google account could use it to break into other online services.

The development comes days after Swiss privacy-focused company Proton, which surpassed 100 million active accounts last week, unveiled an end-to-end encrypted password management solution called Proton Pass.


The publicly auditable, open source tool, which makes use of the bcrypt password hash function and a hardened version of the Secure Remote Password (SRP) protocol for authentication, also includes 2FA integration.

