Live data from Hacker News

Aegis Authenticator – Secure 2FA App for Android

getaegis.app

121–130 of 143 posts

Re: Aegis Authenticator – Secure 2FA App for Android

#121

Earlier quoted context omitted.

Update your threat scenario to encompass dismemberment and create a recovery protocol accordingly. Not sure you would be able to do drills, at least not a second time.

That's why I put mine in my neck. If they cut it out, external access to my accounts is not my main concern.

If they cut out my arm, that wouldn't be my main concern either

Re: Aegis Authenticator – Secure 2FA App for Android

#122
Why is anyone even modestly technical still using a phone for 2FA? I do not understand.

Yubikeys, Ledgers, Trezors, Nitrokeys, Mooltipass, Precursor, QubesOS Vault... There are so many solutions that avoid exposing your 2FA secrets in plaintext to the system memory of an internet connected device.

Re: Aegis Authenticator – Secure 2FA App for Android

#123
post #116

Earlier quoted context omitted.

I keep a second key as backup for this reason, which honestly is overkill and I only do because I got a second one for free at a conference. Easier solution (which I also use in case I someday need the second one only to discover that the blue smoke leaked out) is to just print out the TOTP secrets and keep them somewhere. I'm usually printing out recovery codes when I get a new TOTP secret so this has never felt lik…

Everyone should read this risk mitigation solution for loosing 2FA. I always think about printing recovery codes, but having keepass vault with those codes also sounds great. You may even have some random password there and store it printed out in some locations just for emergency. Anyways, people should think about these risks when dealing with 2FA: flood, fire, stolen, lost, (I) broke (Smartphone, yubikey, usb, etc…

And also something we usually don’t consider: loss of memory, which can occur in combination with a traumatic event like your house burning. Then you can loose your smartphone, your Yubikey, your printed copy, and your memory all at the same time if everything is stored in one place. And this is exactly when you will need those the most. Not easy to defend against such a nightmarish scenario.

Re: Aegis Authenticator – Secure 2FA App for Android

#124
post #86

Who makes this? How do I know it is trustworthy? I know its supposed to be open source, but when you install from the app store you don't really know what you are installing. I trust Twilio's Authy a tad more than a random app with a nice home page.

It has the name of a very powerful shield from Greek mythology, so it will protect you.

Re: Aegis Authenticator – Secure 2FA App for Android

#125
post #120

Earlier quoted context omitted.

My Yubikey always loses its credentials. (If anyone else knows about it and have a fix I'm all ears.) I guess I need a new one, but what I want to say is don't rely on a single Yubikey or even two. Do have backups.

Which model do you own and how does the loss manifest? The single-tap and long-tap don't produce expected output? Can you share more info on it? I own many Yubikeys (due to research I've been doing in 2017.) and I had many Yubikeys to play with, for TOTP/HOTP/U2F purposes, even using it to unlock Windows and I haven't had a case of a Yubikey basically deprogram itself. I washed them in the washing machine, ran them o…

Classic USB. Plastic. (I don't know the exact model, I got it from work.)

After adding a site or a computer it works a few days and then suddenly when I try to use it with my phone or computer I just get an error about no .

So yes, probably defective.

Re: Aegis Authenticator – Secure 2FA App for Android

#126

Earlier quoted context omitted.

That's why I put mine in my neck. If they cut it out, external access to my accounts is not my main concern.

If they cut out my arm, that wouldn't be my main concern either

But you would be able to have concerns at least

Re: Aegis Authenticator – Secure 2FA App for Android

#127
post #83
post #36

Earlier quoted context omitted.

I can import/export with Google authenticator (via QR codes).

You can import/export to Google Authenticator only and you must have two phones. You cannot backup QR codes because screenshot is forbidden for security reason. You cannot migrate to another application.

I just took a pic of the QR codes with my webcam and stored that in KeePass.

Re: Aegis Authenticator – Secure 2FA App for Android

#128
post #60
post #36

Earlier quoted context omitted.

I can import/export with Google authenticator (via QR codes).

Tends not to work to well in the scenario where you drop your phone into the ocean.

Normally one does their backups before they are necessary.

Re: Aegis Authenticator – Secure 2FA App for Android

#129
post #120

Earlier quoted context omitted.

Which model do you own and how does the loss manifest? The single-tap and long-tap don't produce expected output? Can you share more info on it? I own many Yubikeys (due to research I've been doing in 2017.) and I had many Yubikeys to play with, for TOTP/HOTP/U2F purposes, even using it to unlock Windows and I haven't had a case of a Yubikey basically deprogram itself. I washed them in the washing machine, ran them o…

Classic USB. Plastic. (I don't know the exact model, I got it from work.) After adding a site or a computer it works a few days and then suddenly when I try to use it with my phone or computer I just get an error about no . So yes, probably defective.

Not enough info to even guess what might be wrong, but I'd assume it's defective and I'd try with another key as well. I wish you good luck with the next Yubkey you get! :)

Btw. this is the first time I've read on a public forum that someones Yubikey is defective, they are really well made and I didn't manage to break one via regular use and bad maintenance.

Re: Aegis Authenticator – Secure 2FA App for Android

#130

Earlier quoted context omitted.

Update your threat scenario to encompass dismemberment and create a recovery protocol accordingly. Not sure you would be able to do drills, at least not a second time.

That's why I put mine in my neck. If they cut it out, external access to my accounts is not my main concern.

people do not cut off fingers for fingerprints so they wont cut my arm off for my github...
Post reply on HN