Just keep TOTP in your password manager at this point. Whatever security is lost by it not being a "true second factor" is made up for by not having to recover or restore backups due to a lost or stolen phone.
Aegis Authenticator – Secure 2FA App for Android
61–70 of 143 posts
Re: Aegis Authenticator – Secure 2FA App for Android
#62Recently had a hard time exporting 20+ OTP secrets from Google Authenticator. I believe I discovered a bug in the app: if you long press a secret > edit > leave an empty string as the comment, and then export a QR code containing this secret, your other device will fail to import ("QR code cannot be interpreted."). I've only seen this happen with secrets where the comment is put in parentheses and appended to the reg…
There's a third option to switch from Google Authenticator to Aegis. You can simply scan those export QR codes of Google Authenticator with Aegis.
Re: Aegis Authenticator – Secure 2FA App for Android
#63Re: Aegis Authenticator – Secure 2FA App for Android
#64Earlier quoted context omitted.
Yubikeys store everything on the key. I can lose my phone and use your phone to see my 2FA codes. It's honestly one of the only way MFA make sense - otherwise you lock yourself out of your entire digital life when you lose your phone and need to rely on storing your backup codes (which opens up a storage security wormhole). It's also a lot easier to wear around your neck.
So you've moved the worry from losing/breaking your phone to losing/breaking your YubiKey?
Re: Aegis Authenticator – Secure 2FA App for Android
#65Earlier quoted context omitted.
Yubikeys store everything on the key. I can lose my phone and use your phone to see my 2FA codes. It's honestly one of the only way MFA make sense - otherwise you lock yourself out of your entire digital life when you lose your phone and need to rely on storing your backup codes (which opens up a storage security wormhole). It's also a lot easier to wear around your neck.
So you've moved the worry from losing/breaking your phone to losing/breaking your YubiKey?
Also easy enough to maintain a keepass[xc] vault for totp secrets, you could keep a separate one from your passwords if you were feeling paranoid. Great support on mobile and desktop for using a keepass db as a TOTP source - and easy to sync with dropbox/email/ssh/your web server/whatever
Re: Aegis Authenticator – Secure 2FA App for Android
#66The killer feature for me is a way to quickly access tokens in my (cloud-side, encrypted) vault from a desktop (or web) app in case of emergency. It's not clear to me if Aegis allows this somehow? The other day I broke my phone. I was traveling and needed to do some 2FA level changes to a GH repo asap. I didn't even know there was an Authy desktop app until then. It saved my ass, literally.
Yubikeys store everything on the key. I can lose my phone and use your phone to see my 2FA codes. It's honestly one of the only way MFA make sense - otherwise you lock yourself out of your entire digital life when you lose your phone and need to rely on storing your backup codes (which opens up a storage security wormhole). It's also a lot easier to wear around your neck.
I am currently carrying 2 tokens :(
Re: Aegis Authenticator – Secure 2FA App for Android
#67Re: Aegis Authenticator – Secure 2FA App for Android
#68Re: Aegis Authenticator – Secure 2FA App for Android
#69Earlier quoted context omitted.
Yubikeys store everything on the key. I can lose my phone and use your phone to see my 2FA codes. It's honestly one of the only way MFA make sense - otherwise you lock yourself out of your entire digital life when you lose your phone and need to rely on storing your backup codes (which opens up a storage security wormhole). It's also a lot easier to wear around your neck.
So you've moved the worry from losing/breaking your phone to losing/breaking your YubiKey?
anyway I wouldn't but s Yubikey for TOTP. OTP sucks. Sure it's better than no 2FA and TOTP is better than SMS OTP still it's not grate.
WebAuthn-like auth can provide all the benefits of TOTP while being way more secure and in some cases even not convenient.
The main drawback is how to backup your 2FA which makes it less of a choice for a "casual" user.