Live data from Hacker News

The complete list of alternatives to all Google products – TechSpot

techspot.com

11–17 of 17 posts

Re: The complete list of alternatives to all Google products – TechSpot

#11
post #7

Earlier quoted context omitted.

Yes, use aegis instead of authy or google authenticator. Open source and option to export your keys (both encrypted and unencrypted)

Would prefer a cross-platform option. That one appears to be Android only.

I imagine if the secrets are exported, you could import them to any app which would be excellent.

Re: The complete list of alternatives to all Google products – TechSpot

#12
post #4

> Authy I don't trust Authy and a discerning security professional shouldn't either. There are _a lot_ of red flags. * First: Forcing users to download their stupid app. TOTP is a widely documented protocol. There shouldn't be a need to download a particular app unless there is an ulterior motive. * Second: secrets are stored in the cloud. Guess what the key to access them is? An SMS. Yes those un-encrypted, un-signe…

Couldn't be happier with Raivo OTP on iPhone. Unfortunately it's iOS only but as far as I know it's 100% work of passion and bullshit free app maintained by a single user. Allows to export your entries in a very nice way... which is very securing regarding the kind of data entrusted. No risk of being locked out. Thanks @tijme!

Re: The complete list of alternatives to all Google products – TechSpot

#13
post #12
post #4

> Authy I don't trust Authy and a discerning security professional shouldn't either. There are _a lot_ of red flags. * First: Forcing users to download their stupid app. TOTP is a widely documented protocol. There shouldn't be a need to download a particular app unless there is an ulterior motive. * Second: secrets are stored in the cloud. Guess what the key to access them is? An SMS. Yes those un-encrypted, un-signe…

Couldn't be happier with Raivo OTP on iPhone. Unfortunately it's iOS only but as far as I know it's 100% work of passion and bullshit free app maintained by a single user. Allows to export your entries in a very nice way... which is very securing regarding the kind of data entrusted. No risk of being locked out. Thanks @tijme!

Also. Whatever app you use, when you set up OTP don't forget to save screenshots of your original qr codes, in a veracrypt container ideally. Don't rely (only) on other people's work and will for such sensitive and personal data.

Re: The complete list of alternatives to all Google products – TechSpot

#14
post #4

> Authy I don't trust Authy and a discerning security professional shouldn't either. There are _a lot_ of red flags. * First: Forcing users to download their stupid app. TOTP is a widely documented protocol. There shouldn't be a need to download a particular app unless there is an ulterior motive. * Second: secrets are stored in the cloud. Guess what the key to access them is? An SMS. Yes those un-encrypted, un-signe…

What's a 2FA tool that meets your requirements?

Re: The complete list of alternatives to all Google products – TechSpot

#15
Just looking down the list makes me tired. If I have to give my data to one and only one party in return of many valuable service, I chose it to be google. I know they are not the initial google anymore but I do not have time to redesign my life with many, but many-many privacy focused apps, just because. My privacy from one single company is not that important. Benefits I get in return, and combining them under one umbrella, which is google, is extremely valuable on the other hand.

Re: The complete list of alternatives to all Google products – TechSpot

#16
post #13
post #12

Earlier quoted context omitted.

Couldn't be happier with Raivo OTP on iPhone. Unfortunately it's iOS only but as far as I know it's 100% work of passion and bullshit free app maintained by a single user. Allows to export your entries in a very nice way... which is very securing regarding the kind of data entrusted. No risk of being locked out. Thanks @tijme!

Also. Whatever app you use, when you set up OTP don't forget to save screenshots of your original qr codes, in a veracrypt container ideally. Don't rely (only) on other people's work and will for such sensitive and personal data.

I've never done this, but it seems like an excellent idea. With the QR code, you could always reinstall to a different app.

Re: The complete list of alternatives to all Google products – TechSpot

#17
post #4

> Authy I don't trust Authy and a discerning security professional shouldn't either. There are _a lot_ of red flags. * First: Forcing users to download their stupid app. TOTP is a widely documented protocol. There shouldn't be a need to download a particular app unless there is an ulterior motive. * Second: secrets are stored in the cloud. Guess what the key to access them is? An SMS. Yes those un-encrypted, un-signe…

Ah how timely, Authy outage today.

Again: avoid like the plague.

Post reply on HN