What happens behind each code and password.
Four things 2FA Live does, and exactly what leaves your iPhone when it does them. Boxes outlined in blue happen on your device. Dashed boxes are other services.
A code is made from a shared key and the current time.
When you turn on two-factor sign-in, the website shows a QR code that contains a secret setup key. 2FA Live saves that key. From then on, your iPhone and the website each work out the same 6-digit code from the key and the clock, with no connection between them.
- Setup keySaved once from the QR code, kept in the iOS Keychain
- Current timeCounted in 30-second steps
- HMACKey and time step mixed with SHA-1, SHA-256 or SHA-512
- Code
482 913for the next 30 seconds
- Same setup keyStored with your account
- Same timeSame 30-second step
- Same HMACSame calculation
- Codes matchYou are signed in
- This standard is called TOTP (RFC 6238). Any authenticator app that follows it gives the same code for the same key.
- Codes need no internet connection, which is why they work in flight mode.
- Because the clock matters, keep your iPhone's time set automatically. You can check your setup on the test page.
iCloud stores only data it cannot read.
iCloud Sync is off until you turn it on. When it is on, each item is locked on your iPhone before upload, and unlocked again only on your other devices.
- Your itemA code, password, card, note or Wi-Fi network
- EncryptAES-256-GCM with a key made on your iPhone
- Your private iCloudHolds only scrambled data
- Your iPadGets the key from iCloud Keychain and decrypts
- The key travels only through iCloud Keychain, which Apple encrypts end to end between your own devices.
- We run no server and have no access to your iCloud. Apple sees only encrypted records.
- On a new device, wait a few minutes for iCloud Keychain to deliver the key before items unlock.
- Encrypted backups work the same way, except the key comes from a password you choose.
The breach check never sends your password.
2FA Live checks passwords against the Have I Been Pwned list of hundreds of millions of passwords exposed in data breaches. It uses a method called k-anonymity, so the service never learns which password you checked.
- Your passwordStays on your iPhone
- Hash itSHA-1 gives 40 characters, like
5BAA6…68FD8 - Send 5 charactersOnly
5BAA6goes to Have I Been Pwned - Get a list backSeveral hundred hash endings that start the same way
- Compare on deviceFound or not found, decided on your iPhone
- Hundreds of different passwords share every 5-character start, so the request reveals nothing useful.
- The app also asks the service to pad its replies, so even the reply size gives nothing away.
- The check for weak, reused and old passwords runs entirely on your iPhone and sends nothing.
A passkey's private half never leaves this iPhone.
A passkey replaces a password with a pair of keys. The website keeps the public key. 2FA Live creates the private key inside your iPhone's Secure Enclave, a separate chip that will use the key but never hand it out.
- Website asksSends a one-time challenge
- You approveWith Face ID or Touch ID
- Secure Enclave signsUses the private key without revealing it
- Website checksVerifies the signature with the public key
- There is nothing to phish or leak: the website never stores a secret that could sign you in.
- Passkeys in 2FA Live are not synced or backed up, because the private key cannot leave the chip. Keep a second sign-in method for each account in case you lose or replace this iPhone.