Live data from Hacker News

Aegis Authenticator – Open-source 2FA for Android

getaegis.app

81–90 of 121 posts

Re: Aegis Authenticator – Open-source 2FA for Android

#81
post #42

I used to use andOTP, mainly because it was possible to export OTP tokens when upgrading or resetting my phone. Then IIRC I heard that andOTP wasn't that secure/maintained. Or maybe that their backup file encryption wasn't that great. I am not sure about these claims, but I migrated to Aegis , that could nicely import AndOTP tokens. Nowadays, I use it in combination with bitwarden (it supports OTP), which I use for m…

> I migrated to Aegis, that could nicely import AndOTP tokens.

Thanks. I use andOTP too and was hoping this point was answered somewhere here :-).

Re: Aegis Authenticator – Open-source 2FA for Android

#83
post #63

I don't know about you but does anyone else screenshot (and even print physical copies of, to keep safe) their authenticator barcodes given by websites, in case some day your chosen app dies or your phone(s)/tablets/everything gets lost?

I store my password manager (Bitwarden) TOTP code in my safe in QR code format. I keep all my other TOTPs in my password manager. My Bitwarden password is long (at least 40 characters long, I didn't count precisely) and never used or reused.

Doesn't it kinda defeat the point of storing TOTP codes in your password manager?

Re: Aegis Authenticator – Open-source 2FA for Android

#84
post #63

Earlier quoted context omitted.

I store my password manager (Bitwarden) TOTP code in my safe in QR code format. I keep all my other TOTPs in my password manager. My Bitwarden password is long (at least 40 characters long, I didn't count precisely) and never used or reused.

Doesn't it kinda defeat the point of storing TOTP codes in your password manager?

You wouldn't need to store the codes, but you would need to store the key that makes the codes.

Re: Aegis Authenticator – Open-source 2FA for Android

#85
I've been in the market for an open source authenticator that works on android and desktop with a cloud sync.

I cannot find one and so I'm stuck on using authy. I have exported all my TOTP tokens in hopes that one might turn up.

Aegis, like andOTP and others, does not appear to have a desktop client.

Re: Aegis Authenticator – Open-source 2FA for Android

#86
Can I throw in a question here? How do I get my accounts imported from the old Google Authenticator into the new one?

I'm currently locked out of my AWS account because I made the mistake of adding MFA to my root account at the wrong time.

The crazy thing is that AWS have my phone number but due to formatting or similar they can't send me an SMS! IT's possible that they're trying a US number but mine is Australian.

Re: Aegis Authenticator – Open-source 2FA for Android

#87
post #63

Earlier quoted context omitted.

I store my password manager (Bitwarden) TOTP code in my safe in QR code format. I keep all my other TOTPs in my password manager. My Bitwarden password is long (at least 40 characters long, I didn't count precisely) and never used or reused.

Doesn't it kinda defeat the point of storing TOTP codes in your password manager?

If it's secured by TOTP and a unique and secure password, it's not the weakest link.

Re: Aegis Authenticator – Open-source 2FA for Android

#88

Sounds awesome! Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA. Worse off, some SAASs _require_ Authy specifically. Think about that. That means the security of an enterprise system at your company is completely dependent on whether or not an individual secures their personal cell phone account. Absolutely stupid, avoid Authy like the plague.

> Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA Explain. There is a separate password to defeat traditional SMS attacks.

I believe it uses it for account recovery if you don't have a device with it installed anymore.

Re: Aegis Authenticator – Open-source 2FA for Android

#89
post #63

Earlier quoted context omitted.

I store my password manager (Bitwarden) TOTP code in my safe in QR code format. I keep all my other TOTPs in my password manager. My Bitwarden password is long (at least 40 characters long, I didn't count precisely) and never used or reused.

Doesn't it kinda defeat the point of storing TOTP codes in your password manager?

I would say not when you can secure bitwarden with a hardware key 2FA.

Re: Aegis Authenticator – Open-source 2FA for Android

#90

Sounds awesome! Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA. Worse off, some SAASs _require_ Authy specifically. Think about that. That means the security of an enterprise system at your company is completely dependent on whether or not an individual secures their personal cell phone account. Absolutely stupid, avoid Authy like the plague.

I use Authy for a few reasons. One is the ability to sync and use it across multiple devices. This is really convenient.

But the killer is the desktop app. I've had a number of instances where someone I was helping could not get the time of their phone and computer close enough to properly generate codes. Running the Authy app on the machine meant the time matched perfectly and they were finally able to log in.

It's not perfect but has some killer features.

Post reply on HN