For those of you using two-step authentication for your Google account, a new update for the Google Authenticator app has just landed in the Android Market. Version 0.85 apparently fixes a few security bugs, and adds some UI improvements -- though we have to say, the app looks exactly the same to our untrained eyes.

Anyone with CyanogenMod 7.1 installed will want to stay clear of this Authenticator update, however, as users of the popular custom firmware are reporting that this new update force-closes at startup on their devices. Our own Chris Parsons has confirmed that the latest version doesn't work with CM 7.1 on his HTC Desire HD and Motorola Atrix, while the app is equally borked on Josh Munoz's CM'd HTC EVO 3D. Because two-step authentication users need the Authenticator app to sign in on a new computer, this could cause a few headaches for anyone affected. So if you're running CM, or a custom ROM based upon it, we'd recommend holding off updating until more is known, or an official fix is available.

In the meantime, if you find yourself unable to use the new version of Google Authenticator, you can always authenticate your account over the phone, or use one of your emergency sign-in codes (you remembered to write those down, right?) After you're signed in, you'll then be able to disable two-stage authentication until either Google or the CM team comes out with a fix.

If you're not running a custom ROM, however, you should be just fine. You'll find the usual QR code and Android Market links after the break.

grindking says:

I think you can still use two step authorization with an android phone without the authenticator app, it just has to text you a # each time you need to authorize. I could be wrong, but I think while I was upgrading phones I had a situation like this where I couldn't use authenticator, but I can't remember the specifics or the exact setup I had during that time.

Correct. Right under the box to enter the code, there is a link to get a code through other means ie Text/backup code.

wscaddie56 says:

Been using two step for almost a year and I never even heard of the app. Might have to check it out but I'm not sure what functionality I need that the app would provide.

If my lastpass account got hacked it would be worse but once I put payment info on my google account for the market I went to the two step.

Well, when my wife got a new phone, she couldn't sign into Google on that phone. So we had to be online on our pc and disable the dual authentication first.

We just left it off as its been more of a pita than anything else.

lnxfrk says:

Just a FYI, there is a workaround to this issue for those not wishing to wait for another update. Basically the new version of the app is looking for /system/bin/chmod and this does not exist in CM7.1. The workaround involves remounting /system read-write, cd /system/bin; ln -s ../xbin/chmod chmod; remount /system read-only (or reboot).

Credit to Fiouz's market comments

Confirmed on Samsung Captivate running CM7.1

roberte1342 says:

Just tried this on my Droid X and it worked.

Gekko says:

i love Google but this seems like a PIA.

lorddrgn says:

There is a new release today that claims to have fixed it, not running a rom right now to test, but hopefully it did