Live data from Hacker News

Aegis Authenticator – Open-source 2FA for Android

getaegis.app

71–80 of 121 posts

Re: Aegis Authenticator – Open-source 2FA for Android

#71
post #66

I've been trying to switch away from a closed source authenticator and this ticks most of the boxes. The only thing it's missing is the ability to quickly filter by group. Currently you have to open app -> 3 dot menu -> filter -> select group (4 steps total), whereas the authenticator I'm currently using allows you to side swipe -> select a group (2 steps), or add a shortcut on homescreen that opens the app with the…

Can recommend AndOTP in this case, provided using Android. Grab a build off F-Droid - easy tag-hopping with options for single or multiple tag selection. Have very few complaints, and I 2FA anything I can, at work and personally, so tags strictly necessary

I love AndOTP. It's boring, it keeps the master key in my head and offers simple backups.

Re: Aegis Authenticator – Open-source 2FA for Android

#72
post #66

I've been trying to switch away from a closed source authenticator and this ticks most of the boxes. The only thing it's missing is the ability to quickly filter by group. Currently you have to open app -> 3 dot menu -> filter -> select group (4 steps total), whereas the authenticator I'm currently using allows you to side swipe -> select a group (2 steps), or add a shortcut on homescreen that opens the app with the…

Can recommend AndOTP in this case, provided using Android. Grab a build off F-Droid - easy tag-hopping with options for single or multiple tag selection. Have very few complaints, and I 2FA anything I can, at work and personally, so tags strictly necessary

The main problem with andotp is the excessive amount of padding that they add to each entry, even with the "compact" option. The group/tag selection is better (only two steps), but not nearly as convenient as the app I'm using where you can view a group/tag directly from the home screen.

Re: Aegis Authenticator – Open-source 2FA for Android

#73

I don't know about you but does anyone else screenshot (and even print physical copies of, to keep safe) their authenticator barcodes given by websites, in case some day your chosen app dies or your phone(s)/tablets/everything gets lost?

Always keep a hardcopy in a safe, for that day your phone is lost or dies. You don't wanna ask Amazon to remove your 2FA, as this involves paperwork. I learned the hard way, but luckily located backups

Re: Aegis Authenticator – Open-source 2FA for Android

#74
post #54

Sounds awesome! Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA. Worse off, some SAASs _require_ Authy specifically. Think about that. That means the security of an enterprise system at your company is completely dependent on whether or not an individual secures their personal cell phone account. Absolutely stupid, avoid Authy like the plague.

I've been using Authy for a long time and have never come across SMS for security. When would that be triggered?

I think it's a point of recovery for your authy account that they're talking about.

Re: Aegis Authenticator – Open-source 2FA for Android

#75

I don't know about you but does anyone else screenshot (and even print physical copies of, to keep safe) their authenticator barcodes given by websites, in case some day your chosen app dies or your phone(s)/tablets/everything gets lost?

You really only not do this once. When you lose your phone, you learn.

Re: Aegis Authenticator – Open-source 2FA for Android

#76
post #25

I don't know about you but does anyone else screenshot (and even print physical copies of, to keep safe) their authenticator barcodes given by websites, in case some day your chosen app dies or your phone(s)/tablets/everything gets lost?

Aegis has an option to export an encrypted backup of the database. I export one every time I add a new code to the app.

Yes, and the exact reason I use aegis (plus open source!)

Re: Aegis Authenticator – Open-source 2FA for Android

#77
post #54

Earlier quoted context omitted.

I've been using Authy for a long time and have never come across SMS for security. When would that be triggered?

I think it's a point of recovery for your authy account that they're talking about.

Gotcha, thanks.

Re: Aegis Authenticator – Open-source 2FA for Android

#78

Anyone knows if and how to use this instead of Microsoft authenticator?

When you setup Microsoft Authenticator, it defaults to a QR code that will be invalid to standard TOTP apps. However, that's because it assumes you want to use the push notification of the app. If you click a button like "key without notify", it will give you a different QR code which is fully standard and works with common apps like this.

Re: Aegis Authenticator – Open-source 2FA for Android

#80

Sounds awesome! Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA. Worse off, some SAASs _require_ Authy specifically. Think about that. That means the security of an enterprise system at your company is completely dependent on whether or not an individual secures their personal cell phone account. Absolutely stupid, avoid Authy like the plague.

Authy's trying to make an open standard proprietary. I don't understand why you have to sign up for it with your phone number, or how they've gotten websites like Twitch to offer Authy-exclusive 2FA. In any case I was able to phish myself out of my old phone's Authy account really easily. It's a really bad thing to happen for regular consumers.
Post reply on HN