Live data from Hacker News

Ente Auth: open-source Authy alternative for 2FA

ente.io

31–40 of 209 posts

Re: Ente Auth: open-source Authy alternative for 2FA

#31
It should be highlighted that the flagship app from ente is not their 2FA but their wonderful encrypted photo app. It is a fully encrypted alternative to Google Photo.

It is far from perfect but already very usable. There’s also a Linux desktop client that allows me to sync all my photos on my computer.

I really recommend them (nice team)

Re: Ente Auth: open-source Authy alternative for 2FA

#32
What's the point of having your 2FA codes synchronized across all your devices?

Isn't it in the name "TWO FACTOR"? It's supposed to be a separate device and ability to "across devices" comes as an anti-feature for me.

1) If you're not using password manager, then you're probably using same password everywhere, including your 2FA app.

2) If you're storing your 2FA codes in your password manager, then it's not really a 2nd factor. It helps against password leaks from services, not from a password manager leak.

Ability to synchronize encrypted backup is a different story.

Re: Ente Auth: open-source Authy alternative for 2FA

#33

People complaining about an "Authy jail" and yet I have no issues with Aegis. Which is also open source, available in the f-droid store, and been around for years.

Am I misunderstanding your comment or do you think that Authy is the same as Aegis? Anyway, Aegis and Ente have export options, Aughy doesn't.

More like, why do they complain if alternatives exist.

Re: Ente Auth: open-source Authy alternative for 2FA

#35
Security platforms should be open source by default. It provides assurance that nothing weird is occurring behind the covers and also shows confidence in the implementation and the cryptography behind it all.

I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform.

I will never use another Twilio product again after that.

Re: Ente Auth: open-source Authy alternative for 2FA

#36
I've been using Authy as a backup for 1Password (previously BitWarden/LastPass)'s 2FA since in a worst-case scenario I can get a replacement SIM card from my phone network's store and get back into my 1Password account via recovery. This has had to be tested once when my phone got pickpocketed in Amsterdam.

Is there a better alternative? Authy is fine for this use, the rest of my 2FA tokens are in 1Password itself.

Re: Ente Auth: open-source Authy alternative for 2FA

#37

What's the point of having your 2FA codes synchronized across all your devices? Isn't it in the name "TWO FACTOR"? It's supposed to be a separate device and ability to "across devices" comes as an anti-feature for me. 1) If you're not using password manager, then you're probably using same password everywhere, including your 2FA app. 2) If you're storing your 2FA codes in your password manager, then it's not really a…

It’s really two step auth. Basically the point is that it defeats password spray attacks.

Higher assurance authenticators need more than TOTP. Usually that means adding a knowledge component (ie pin), challenge/response, a physical token, biometric or all of the above.

Re: Ente Auth: open-source Authy alternative for 2FA

#39

I've been using Authy as a backup for 1Password (previously BitWarden/LastPass)'s 2FA since in a worst-case scenario I can get a replacement SIM card from my phone network's store and get back into my 1Password account via recovery. This has had to be tested once when my phone got pickpocketed in Amsterdam. Is there a better alternative? Authy is fine for this use, the rest of my 2FA tokens are in 1Password itself.

If you’re on a Mac and use Safari, it has a neat 2FA integration built in, which saves and autofills OTPs from iCloud Keychain.
Post reply on HN