Live data from Hacker News

Aegis Authenticator – Open-source 2FA for Android

getaegis.app

51–60 of 121 posts

Re: Aegis Authenticator – Open-source 2FA for Android

#51
post #42

I used to use andOTP, mainly because it was possible to export OTP tokens when upgrading or resetting my phone. Then IIRC I heard that andOTP wasn't that secure/maintained. Or maybe that their backup file encryption wasn't that great. I am not sure about these claims, but I migrated to Aegis , that could nicely import AndOTP tokens. Nowadays, I use it in combination with bitwarden (it supports OTP), which I use for m…

One of the authors here. > Icon library for common websites using OTP Someone from the community is maintaining an icon pack for Aegis: https://github.com/aegis-icons/aegis-icons . We're currently working on making icon packs easier to use in Aegis, see: https://github.com/beemdevelopment/Aegis/issues/509 . > Maybe Steam OTP support Steam is supported, actually! But like you said, you'd still need the Steam app if yo…

Hey there, thanks for Aegis, it is my main OTP vault for important suff.

Thank you and your sibling comment. I'm glad this is being worked on! Discovery is also important IMO, so a one-tap install of the most widely used icon pack would be nice to have too :)

Re: Aegis Authenticator – Open-source 2FA for Android

#52
post #42

I used to use andOTP, mainly because it was possible to export OTP tokens when upgrading or resetting my phone. Then IIRC I heard that andOTP wasn't that secure/maintained. Or maybe that their backup file encryption wasn't that great. I am not sure about these claims, but I migrated to Aegis , that could nicely import AndOTP tokens. Nowadays, I use it in combination with bitwarden (it supports OTP), which I use for m…

Icon packs are coming. [1] Steam accounts can be imported if you have root access, or you can try [2]. IIRC Steam codes are almost standard except they use a different encoding because... Valve likes to roll their own stuff (?). I agree that trading makes only having codes a bit less useful. They could've used the same codes to confirm trades instead of an entirely separate interface. [1] https://github.com/beemdevel…

Thanks for pointing this out.

Yeah, steam rolling their own stuff is a bit troublesome at ties, but I think they were among the first to use TOTP tokens, IIRC ? There was a story here the other day on how they roll their own password encryption over HTTPS for logging in... It's a shame they don't use standard authentication mechanisms, though.

And I should clarify: my yubikey is my main 2FA token, though support for U2F/Webauthn is a bit limited.

Re: Aegis Authenticator – Open-source 2FA for Android

#53

Sounds awesome! Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA. Worse off, some SAASs _require_ Authy specifically. Think about that. That means the security of an enterprise system at your company is completely dependent on whether or not an individual secures their personal cell phone account. Absolutely stupid, avoid Authy like the plague.

Anecdotally, I've seen a few places that instead of mentioning the protocol just say 'download G Auth' or 'download Authy', and so far all of those worked with Aegis when I tried.

Re: Aegis Authenticator – Open-source 2FA for Android

#54

Sounds awesome! Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA. Worse off, some SAASs _require_ Authy specifically. Think about that. That means the security of an enterprise system at your company is completely dependent on whether or not an individual secures their personal cell phone account. Absolutely stupid, avoid Authy like the plague.

I've been using Authy for a long time and have never come across SMS for security. When would that be triggered?

Re: Aegis Authenticator – Open-source 2FA for Android

#55
post #51

Earlier quoted context omitted.

One of the authors here. > Icon library for common websites using OTP Someone from the community is maintaining an icon pack for Aegis: https://github.com/aegis-icons/aegis-icons . We're currently working on making icon packs easier to use in Aegis, see: https://github.com/beemdevelopment/Aegis/issues/509 . > Maybe Steam OTP support Steam is supported, actually! But like you said, you'd still need the Steam app if yo…

Hey there, thanks for Aegis, it is my main OTP vault for important suff. Thank you and your sibling comment. I'm glad this is being worked on! Discovery is also important IMO, so a one-tap install of the most widely used icon pack would be nice to have too :)

Thanks for your support! That's a fair point. We'll see what the feedback is like when we release initial support for icons packs and decide whether to include a pack out of the box after that.

Re: Aegis Authenticator – Open-source 2FA for Android

#56
post #25

I don't know about you but does anyone else screenshot (and even print physical copies of, to keep safe) their authenticator barcodes given by websites, in case some day your chosen app dies or your phone(s)/tablets/everything gets lost?

Aegis has an option to export an encrypted backup of the database. I export one every time I add a new code to the app.

One of the authors here. Recent versions of Aegis also come with an automatic backup feature, so that an export is created at a location of your choosing automatically every time a change is made to your entry list. Might be a little more convenient than doing manual exports every time.

Re: Aegis Authenticator – Open-source 2FA for Android

#57

I don't know about you but does anyone else screenshot (and even print physical copies of, to keep safe) their authenticator barcodes given by websites, in case some day your chosen app dies or your phone(s)/tablets/everything gets lost?

I use Aegis, but also import the TOTP URI to pass, and use it with pass-otp[1].

It kind of defeats the purpose of 2FA, but I keep my pass repo relatively secure, and the convenience is worth it.

[1]: https://github.com/tadfisher/pass-otp

Re: Aegis Authenticator – Open-source 2FA for Android

#59

I don't know about you but does anyone else screenshot (and even print physical copies of, to keep safe) their authenticator barcodes given by websites, in case some day your chosen app dies or your phone(s)/tablets/everything gets lost?

I keep screenshot of QR Codes, & phrases itself in a separate keypass database.
Post reply on HN