Hi Everyone Very important update.
Authy the most commonly used Google Authenticator alternative was also affected by the issue.
Their response - SECURITY NOTICE: AUTHY RESPONSE TO CLOUDFLARE CLOUDBLEED INCIDENT • Authy
Long story short you need to add all your accounts stored in Authy once again.
Why because its based on Time-based One Time Password(TOTP) type 2FA.
The tokens may have been compromised. I got the response re-confirmed from Authy Support.
For more details on how TOTP works read these blogs
Why You Should Never Use Google Authenticator Again
Cloudbleed Security Measures on TREZOR
wow interesting.
maybe now I understand why nowdays people don't trust 2FA sms anymore and want those usb authenticators
that article would deserve a another thread
thank you for sharing