What happens behind each code and password.

Four things 2FA Live does, and exactly what leaves your iPhone when it does them. Boxes outlined in blue happen on your device. Dashed boxes are other services.

A code is made from a shared key and the current time.

When you turn on two-factor sign-in, the website shows a QR code that contains a secret setup key. 2FA Live saves that key. From then on, your iPhone and the website each work out the same 6-digit code from the key and the clock, with no connection between them.

In 2FA Live, on your iPhone
  1. Setup keySaved once from the QR code, kept in the iOS Keychain
  2. Current timeCounted in 30-second steps
  3. HMACKey and time step mixed with SHA-1, SHA-256 or SHA-512
  4. Code482 913 for the next 30 seconds
On the website's server
  1. Same setup keyStored with your account
  2. Same timeSame 30-second step
  3. Same HMACSame calculation
  4. Codes matchYou are signed in

iCloud stores only data it cannot read.

iCloud Sync is off until you turn it on. When it is on, each item is locked on your iPhone before upload, and unlocked again only on your other devices.

  1. Your itemA code, password, card, note or Wi-Fi network
  2. EncryptAES-256-GCM with a key made on your iPhone
  3. Your private iCloudHolds only scrambled data
  4. Your iPadGets the key from iCloud Keychain and decrypts

The breach check never sends your password.

2FA Live checks passwords against the Have I Been Pwned list of hundreds of millions of passwords exposed in data breaches. It uses a method called k-anonymity, so the service never learns which password you checked.

  1. Your passwordStays on your iPhone
  2. Hash itSHA-1 gives 40 characters, like 5BAA6…68FD8
  3. Send 5 charactersOnly 5BAA6 goes to Have I Been Pwned
  4. Get a list backSeveral hundred hash endings that start the same way
  5. Compare on deviceFound or not found, decided on your iPhone

A passkey's private half never leaves this iPhone.

A passkey replaces a password with a pair of keys. The website keeps the public key. 2FA Live creates the private key inside your iPhone's Secure Enclave, a separate chip that will use the key but never hand it out.

  1. Website asksSends a one-time challenge
  2. You approveWith Face ID or Touch ID
  3. Secure Enclave signsUses the private key without revealing it
  4. Website checksVerifies the signature with the public key