Live data from Hacker News

Aegis Authenticator – Secure 2FA App for Android

getaegis.app

101–110 of 143 posts

Re: Aegis Authenticator – Secure 2FA App for Android

#101

Earlier quoted context omitted.

Aegis is fully offline and doesn't have an official desktop application. You could of course create an export of your Aegis vault and import it in a third-party desktop application, like GNOME's Authenticator or OTPClient.

This is what I do. Two "live" authenticators with my phone and laptop and a secure offsite backup. I don't add new keys particularily often, so it isn't that big of a hassle two manually sync the authenticators.

What app do you use on the laptop?

Re: Aegis Authenticator – Secure 2FA App for Android

#103
post #86

Who makes this? How do I know it is trustworthy? I know its supposed to be open source, but when you install from the app store you don't really know what you are installing. I trust Twilio's Authy a tad more than a random app with a nice home page.

Authy has a questionable privacy policy: > When you use our app we collect: Your phone number, device information, and email address. > When you use an Authy token to log into an account, whether the token was generated on the app or one sent to you via your phone number, we collect and keep information associated with your login activity including information like your IP address, what application or program you log…

Unfortunately I didn't manage to set up Aegis with SendGrid, so I have to have Authy just for SendGrid (both belong to Twilio).

Re: Aegis Authenticator – Secure 2FA App for Android

#104
post #34

I switched to Aegis recently, and I did it for only 2 reasons: 1) I prefer to use OSS when possible 2) Aegis supports import/export/backup - so if I get a new phone, I don't have to spend days setting up my dozens of accounts again! This also means I can setup the same OTPs in both Keepass and my phone, so I can always get into my accounts I'm really liking it, it does the same job as the Google and Microsoft Authent…

I just keep a copy of all QR codes in a safe place. When I need to move to a new device I just install andOTP and scan them all on the new device. I don't like my keys to be protected by only a password somewhere. I prefer to add physical protection to them. If they are accessible from my computer then it's not really 2FA.

Re: Aegis Authenticator – Secure 2FA App for Android

#107
post #86

Who makes this? How do I know it is trustworthy? I know its supposed to be open source, but when you install from the app store you don't really know what you are installing. I trust Twilio's Authy a tad more than a random app with a nice home page.

It is also available on f-droid, and they compile the apps themselves instead of distributing compiled apps. So if you trust f-droid, you know it is the same as the open source code.

You need parties you trust auditing all the code and each change, before you run it.

Re: Aegis Authenticator – Secure 2FA App for Android

#108

The killer feature for me is a way to quickly access tokens in my (cloud-side, encrypted) vault from a desktop (or web) app in case of emergency. It's not clear to me if Aegis allows this somehow? The other day I broke my phone. I was traveling and needed to do some 2FA level changes to a GH repo asap. I didn't even know there was an Authy desktop app until then. It saved my ass, literally.

Bitwarden can store and then copy/paste TOTPs. I'm not sure if it's the best security practice to have your password and TOTP key saved together like that. But I tend to use it for sites that I don't consider critical. I then use Google Authenticator for everything else. I might try Aegis next time I get a new phone though.

Re: Aegis Authenticator – Secure 2FA App for Android

#110

I just put a 2FA implant in my arm

Update your threat scenario to encompass dismemberment and create a recovery protocol accordingly. Not sure you would be able to do drills, at least not a second time.

That's why I put mine in my neck. If they cut it out, external access to my accounts is not my main concern.
Post reply on HN