Live data from Hacker News

Ente Auth: open-source Authy alternative for 2FA

ente.io

71–80 of 209 posts

Re: Ente Auth: open-source Authy alternative for 2FA

#72

What's the point of having your 2FA codes synchronized across all your devices? Isn't it in the name "TWO FACTOR"? It's supposed to be a separate device and ability to "across devices" comes as an anti-feature for me. 1) If you're not using password manager, then you're probably using same password everywhere, including your 2FA app. 2) If you're storing your 2FA codes in your password manager, then it's not really a…

It's "Two Factor Authentication", not "Second Factor On A Single Device You Always Have On Your Person Authentication".

That second factor needs to be separate from the originating authenticating service, not that it has to be on a single device hidden away kept in a safe, or on your wrist, or in your pocket. It could be a single device [a server] running bitwarden and you're viewing it through a browser on your .

Not everyone wants to follow every single recommendation from a data security perspective, and it becomes an anti-pattern when laymen start using workarounds to not have to comply with the safety recommendation of the week.

Re: Ente Auth: open-source Authy alternative for 2FA

#73

What's the point of having your 2FA codes synchronized across all your devices? Isn't it in the name "TWO FACTOR"? It's supposed to be a separate device and ability to "across devices" comes as an anti-feature for me. 1) If you're not using password manager, then you're probably using same password everywhere, including your 2FA app. 2) If you're storing your 2FA codes in your password manager, then it's not really a…

It means you are providing two factors, not necessarily that you only have two factors.

There are benefits to this. I've left my phone at work, and would have been SOL, except I have a tablet that never leaves my home which can also provide my second factor.

Re: Ente Auth: open-source Authy alternative for 2FA

#75

I feel like this misses the problem with Authy. There are hundreds, possibly thousands of 2FA alternatives for Authy. But when my 401K provider requires Authy to login in without providing a generic 2FA option, THAT is the problem.

Authy has this 7 digit TOTP, which seems kind of proprietary. But Aegis supports that too, and is open source.

Is it possible to 'transfer' the 7 digit account from Authy over or best to start over?

Re: Ente Auth: open-source Authy alternative for 2FA

#76

I feel like this misses the problem with Authy. There are hundreds, possibly thousands of 2FA alternatives for Authy. But when my 401K provider requires Authy to login in without providing a generic 2FA option, THAT is the problem.

THE problem with Authy in my humble opinion isn’t just that it’s an obnoxious proprietary app I shouldn’t need — it’s that it forces you to accept SMS as a get-out-of-security-free card. Being able to get a reset text to your registered number (and you MUST register a number, of course) unlocks all your OTPs for the attacker (who slipped some teenaged phone salesman $50 or a fake ID to swap your sims.)

SMS is cancer to security and I won’t use any system that forces me to accept something so easy to exploit as proof of my consent.

Re: Ente Auth: open-source Authy alternative for 2FA

#77
post #5

This looks good, as I wanted to "escape" the Authy jail (you cannot easly move out with your secrets), but moving a lot of 2fa's to a "new thing". How to make sure they are a good project?

You can't but they should be better than Authy, at least they have export options...

I was hoping for allow importing Authy secrets, has anyone sucessfully "taken" the backup out of the app and imported in other tool. As security measure the secrets only live in Authy, but thats when I cannot move out when I want.

Re: Ente Auth: open-source Authy alternative for 2FA

#78

Hello, one of the folks working on Ente Auth here. Thanks for putting us on the frontpage! To give some context, we built Auth for ourselves because we wanted a product that was cross-platform, open source[1] and offered end-to-end encrypted backups[2]. Since launch[3], the product has undergone iterations[4][5]. Auth is now available on Android, iOS, Linux, Mac and Windows[6]. We also have a read-only companion app…

That’s fantastic you can optionally self host. Well done!

Re: Ente Auth: open-source Authy alternative for 2FA

#79

I don't see people mention this enough, but iCloud Keychain generates TOTPs. I've been migrating all of my accounts slowly to just use the built-in Apple Passwords functionality. In Safari, right click on TOTP QR codes.

Additionally, iOS 18 will introduce a Password app making the functionality easier to discover. People are still surprised to learn that iOS has built in TOTP support, but it's just buried deep in the settings.

BTW, there's a hack you can do to create an iOS Password app in iOS 17 and below by using Shortcuts to launch the deep linked setting directly.

Re: Ente Auth: open-source Authy alternative for 2FA

#80

People complaining about an "Authy jail" and yet I have no issues with Aegis. Which is also open source, available in the f-droid store, and been around for years.

The "jail" is having ~100 secrets there that you cannot take out, so moving out is adding new 2fa on each service.
Post reply on HN