Earlier quoted context omitted.
Tends not to work to well in the scenario where you drop your phone into the ocean.
Keep away from oceans.
Aegis Authenticator – Secure 2FA App for Android
81–90 of 143 posts
Re: Aegis Authenticator – Secure 2FA App for Android
#82The more exciting thing I learned here is that I can backup my entire GrapheneOS phone to my Nextcloud server for recovery. I just go into Android settings->Backup to get started. This will save me a lot of time the next time I lose my phone. Thank you!
Re: Aegis Authenticator – Secure 2FA App for Android
#83I switched to Aegis recently, and I did it for only 2 reasons: 1) I prefer to use OSS when possible 2) Aegis supports import/export/backup - so if I get a new phone, I don't have to spend days setting up my dozens of accounts again! This also means I can setup the same OTPs in both Keepass and my phone, so I can always get into my accounts I'm really liking it, it does the same job as the Google and Microsoft Authent…
I can import/export with Google authenticator (via QR codes).
Re: Aegis Authenticator – Secure 2FA App for Android
#84The killer feature for me is a way to quickly access tokens in my (cloud-side, encrypted) vault from a desktop (or web) app in case of emergency. It's not clear to me if Aegis allows this somehow? The other day I broke my phone. I was traveling and needed to do some 2FA level changes to a GH repo asap. I didn't even know there was an Authy desktop app until then. It saved my ass, literally.
Re: Aegis Authenticator – Secure 2FA App for Android
#85Earlier quoted context omitted.
There's a third option to switch from Google Authenticator to Aegis. You can simply scan those export QR codes of Google Authenticator with Aegis.
Wouldn't that need a second device since one can't screenshot Google Authenticator?
Re: Aegis Authenticator – Secure 2FA App for Android
#86Re: Aegis Authenticator – Secure 2FA App for Android
#87The killer feature for me is a way to quickly access tokens in my (cloud-side, encrypted) vault from a desktop (or web) app in case of emergency. It's not clear to me if Aegis allows this somehow? The other day I broke my phone. I was traveling and needed to do some 2FA level changes to a GH repo asap. I didn't even know there was an Authy desktop app until then. It saved my ass, literally.
The exported file can be encrypted when you make it.
Re: Aegis Authenticator – Secure 2FA App for Android
#88Who makes this? How do I know it is trustworthy? I know its supposed to be open source, but when you install from the app store you don't really know what you are installing. I trust Twilio's Authy a tad more than a random app with a nice home page.
Re: Aegis Authenticator – Secure 2FA App for Android
#89Who makes this? How do I know it is trustworthy? I know its supposed to be open source, but when you install from the app store you don't really know what you are installing. I trust Twilio's Authy a tad more than a random app with a nice home page.
> When you use our app we collect: Your phone number, device information, and email address.
> When you use an Authy token to log into an account, whether the token was generated on the app or one sent to you via your phone number, we collect and keep information associated with your login activity including information like your IP address, what application or program you logged in to, that you logged in, and when. If you change your phone number or email associated with your Authy account, we will also keep a log of that. We collect this information to monitor for suspicious activity and also as another piece of information that could be used to verify your identity if your account is compromised or may be compromised.
> We also share your information with our third party service providers as necessary for them to provide their services to us. We may also have to share your information with third parties if required to do so by law.
> Your information will be transferred to the U.S.
> Your personal information may be transferred to the United States, and possibly other countries where we or our service providers operate.
> In addition, we may share your information with third parties as follows: Compliance with Laws. We may disclose your personal information to a third party if (i) we reasonably believe that disclosure is compelled by applicable law, regulation, legal process or a government request (including to meet national security or law enforcement requirements), (ii) to enforce our agreements and policies, (iii) to protect the security or integrity of our services and products, (iv) to protect ourselves, our other customers, or the public from harm or illegal activities, or (v) to respond to an emergency which we believe in good faith requires us to disclose personal information to assist in preventing a death or serious bodily injury.
> Business transfers. If we go through a corporate sale, merger, reorganization, dissolution or similar event, personal information we gather from you may be part of the assets transferred or shared in connection with the due diligence for any such transaction. Any acquirer or successor may continue to use the personal information as described in this notice.
https://www.twilio.com/legal/privacy/authy
I would trust Aegis over Authy any day. As you can see from the source code, Aegis does not expose users to these privacy risks. Even though Aegis has automatic encrypted backup features, Aegis itself does not request the internet access permission.
Re: Aegis Authenticator – Secure 2FA App for Android
#90Just keep TOTP in your password manager at this point. Whatever security is lost by it not being a "true second factor" is made up for by not having to recover or restore backups due to a lost or stolen phone.
I would argue that the most important account to have TOTP enabled IS your password manager. So, if you already have a TOTP app to generate codes for your Password Manager why not consolidate it? Besides, if you dont have a physical and digital backup of your TOTP seeds you really like to live dangerously.