I just use Authy
Privacy Guides
In the digital age, protecting your personal information might seem like an impossible task. We’re here to help.
This is a community for sharing news about privacy, posting information about cool privacy tools and services, and getting advice about your privacy journey.
You can subscribe to this community from any Kbin or Lemmy instance:
Check out our website at privacyguides.org before asking your questions here. We've tried answering the common questions and recommendations there!
Want to get involved? The website is open-source on GitHub, and your help would be appreciated!
This community is the "official" Privacy Guides community on Lemmy, which can be verified here. Other "Privacy Guides" communities on other Lemmy servers are not moderated by this team or associated with the website.
Moderation Rules:
- We prefer posting about open-source software whenever possible.
- This is not the place for self-promotion if you are not listed on privacyguides.org. If you want to be listed, make a suggestion on our forum first.
- No soliciting engagement: Don't ask for upvotes, follows, etc.
- Surveys, Fundraising, and Petitions must be pre-approved by the mod team.
- Be civil, no violence, hate speech. Assume people here are posting in good faith.
- Don't repost topics which have already been covered here.
- News posts must be related to privacy and security, and your post title must match the article headline exactly. Do not editorialize titles, you can post your opinions in the post body or a comment.
- Memes/images/video posts that could be summarized as text explanations should not be posted. Infographics and conference talks from reputable sources are acceptable.
- No help vampires: This is not a tech support subreddit, don't abuse our community's willingness to help. Questions related to privacy, security or privacy/security related software and their configurations are acceptable.
- No misinformation: Extraordinary claims must be matched with evidence.
- Do not post about VPNs or cryptocurrencies which are not listed on privacyguides.org. See Rule 2 for info on adding new recommendations to the website.
- General guides or software lists are not permitted. Original sources and research about specific topics are allowed as long as they are high quality and factual. We are not providing a platform for poorly-vetted, out-of-date or conflicting recommendations.
Additional Resources:
- EFF: Surveillance Self-Defense
- Consumer Reports Security Planner
- Jonah Aragon (YouTube)
- r/Privacy
- Big Ass Data Broker Opt-Out List
I used to use them a while back but now I use Aegis. I prefer my 2fa offline and disconnected from the internet. I still keep my backups saved in safe spaces though. It served me well to get off of Authy too because last year, they got compromised.
I prefer my 2fa offline and disconnected from the internet.
That's great until you lose your phone or something...
Well, that's what backups are for. I sync my Aegis backups between phone, tablet and PC via syncthing. It's convenient to have authy handle bwckups for me, but if I use 2fa I don't want to water down its usefulness right away.
Yeah I tried that. Couldn't figure it out.
Why are people switching away from Raivo?
/c/outoftheloop
Edit: Looks like it's been bought by a generic app developer about which there are few details to be found: https://discuss.techlore.tech/t/raivo-otp-authenticator-has-been-acquired/4962/2
Edit: After digging into 2FAS, I think it is now my top choice. Seems like more of a drop in replacement for Raivo. https://2fas.com/
My second choice is (as of this edit) Owky. I’ve not seen anyone talking about it, but it’s FOSS and has the ability to export your TOTP codes.
Im a little worried about it not being maintained though, since it’s a single developer.
https://apps.apple.com/us/app/owky-two-factor-authenticator/id1602245257
Other options I’ve considered:
Tofu Authenticator. Unfortunately it’s basic though and lacks the ability to export.
ente Authenticator. Account required, and I’m a little undecided on the company. Might be a serious option though.
I switched to 2FAS.
You can’t export from FreeOTP. Ente doesn’t appear to be open source. Tofu is an option but I’m afraid it might not be maintained.
Edit: Use Ente. It’s the best option.
Ente Auth seems open source: https://github.com/ente-io/auth
But the need for account is trowing me off a little bit. I’ll give a try to 2FAS as well.
You can export from freeOTP+ Its great. You can back up to another password manager by simply copying the shared secret also. But I don't think it's available for iOS. Oh well, if you want more freedom and privacy, you'll have to move to android.
Tofu is an option but I’m afraid it might not be maintained.
They made an annoucement 2 weeks ago about switching maintainer.
https://github.com/iKenndac/Tofu
2FAS
They only support iOS/iPadOS 16.4 or later.. no go for me
The password manager for iphone or ios has mfa built in - seems to work ok. Its a bit annoying if you use a desktop thats not mac though and have to search for the mfa code among the millions of passwords.
True but like someone else mentioned here it’s not the best having all eggs in the same basket. If for eggsample 🙂 the apple account gets compromised it’s going to be hard.
Check this video from techlore.
So I'm not on iOS but... the websites I need to use for various work things all require that you use a specific authenticator. But they all choose a different random one. It drives me insane. I have 4 different apps. Google Authenticator, Authy, Duo Mobile, and Onelogin Protect. I pray I change jobs before I get a new phone.
Oh that's interesting. I know for my work, it says to use Google Authenticator, but I am still able to sign up with any app of my choice.
I have been using ProtonMail and Drive already so it was an easy decision to switch to Proton Pass when it came out. It's an all-in-one password manager which let's you store 2FA as well and also let's you make email aliases. It's synced everywhere, on Firefox on my linux desktop to my android phone to my iPad.
Totp with bitwarden. Such a nice integration
I'm curious. I know Bitwarden or keepass can handle TOTPs, but can't I unlock your Bitwarden vault and have access to your password and 2fa code? Or do they have protection against it? Otherwise I have everything I need.
yes, that's the downside of it. You can add additional password requests for some things, but not sure if it works for 2FA. (basically: if you want to use this resource, unlock the vault, but also additionally request the password again)
I'm currently enjoying ProtonPass' built-in 2FA. You gotta be on a paid plan, however, but it's worth it imo.
I use Bitwarden for everything, including my totp codes. I should probably use a separate app solely for Bitwarden's totp code, but the danger of losing it all gives me such a rush!
You can write down your Bitwarden 2FA recovery codes and keep multiple copies of them in safe and private places
I use keepassxc topt
Apple Keychain OTP
I’m a fan of OTP Auth.
It’s been reliable, supports local and cloud backup / exporting, is simplistic in use and has a strong privacy policy.
I’m currently in the process of switching to 2fas. It seemed the best available alternative for me.
OTP Auth
The built in password manager and keychain can handle OTP since a few versions back.
I am undecided btw 2FAS and Ente. 2FAS has an excellent UI, but there is no desktop app. Ente requires an account, but it’s not a problem considering that everything is E2EE and it’s a company with good reputation.
I'll be using BitWarden as my 2FA app. I use KeePass as my password manager so it would still be two different services/apps.
I was planning on using Tofu but it has no FaceID which is mandatory IMO.
Fan of OTP Auth
None, just using the built in manager.
I recommend Raivo or Tofu both open source and I believe you can save and export it somewhere else to backup.
I like Tofu, and I also quite like Authenticator, but so far 2FAS seems to be the only option that offers backups without an account and that isn't a full-blown password manager.