The optional 2FA used is Authy, you activate Authy with your phonenumber only once, after that you use Authy to login to your account. So 2FA is not done through SMS text messages for example, where hijacking could be a problem.
Good one with the list of hostnames, I will prepare one, for now you can take a look at this JSON file:
Authy is absolutely not acceptable for privacy applications like VPNs. Authy stores user information on third-party servers, when there are plenty of 2FA apps that work locally on the user's device.
The fact that Authy refused to delete user accounts (before they were acquired by Twilio), even when they promised to do so in their terms of service, is also very concerning:
Comments
The optional 2FA used is Authy, you activate Authy with your phonenumber only once, after that you use Authy to login to your account. So 2FA is not done through SMS text messages for example, where hijacking could be a problem.
Good one with the list of hostnames, I will prepare one, for now you can take a look at this JSON file:
https://vpnserver.wifimask.net/vpnservers.json
Authy is absolutely not acceptable for privacy applications like VPNs. Authy stores user information on third-party servers, when there are plenty of 2FA apps that work locally on the user's device.
The fact that Authy refused to delete user accounts (before they were acquired by Twilio), even when they promised to do so in their terms of service, is also very concerning:
https://news.ycombinator.com/item?id=9103606
https://web.archive.org/web/20141011062757/authy.com/terms
Yeah, this is really not a good thing on the Authy part. You should not need to activate it with a phone number.