~~There are many forms of 2FA. I'm guessing you mean TOTPs~~ oh you actually wrote that, my bad lol.
I copy the keys from Aegis to KeePassXC. KeyPassXC's database is part of my regular backup. This way I have two apps generating the same TOTPs.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
~~There are many forms of 2FA. I'm guessing you mean TOTPs~~ oh you actually wrote that, my bad lol.
I copy the keys from Aegis to KeePassXC. KeyPassXC's database is part of my regular backup. This way I have two apps generating the same TOTPs.
I was afraid of using keypassxc since I dont trust myself, but using it as a backup sounds like amazing solution. Thank you
Personally I recommend just using KeePassXC and a KeePass app (I use KeePassium on iPhone).
You always have access to all your data that way. No company is monitoring you. A lot of apps make it very difficult to backup!
My totp database is in the cloud for syncing but needs a key file I don’t keep in the cloud (and a password). My passwords are entirely separate.
Thank you all for tips. I got Aegis and backing it up to my selfhosted nextcloud. I will also keep google app in use for now, but I might get keypassxc or vaultwarden in the future
Cheers
As a user of Nextcloud, Aegis, and Vaultwarden, I can say it's a great set of tools. I don't know how I ever got by without Bitwarden/Vaultwarden.
Aegis is a free open source TOTP 2FA app like Google Authenticator, and available on both F-Droid and Google Play. You should be able to export from Google Authenticator and import into Aegis.
Edit: I had assumed because Aegis had an option to import from Google Authenticator that this would mean you could export in bulk. Bad assumption to make, it sounds like you can do it if you have a rooted phone but Authenticator doesn’t make it easy. I did find this that shows a method to do a handful at once: https://blog.jay2k1.com/2021/11/17/how-to-bulk-migrate-from-google-authenticator-to-aegis/
Most comments recommend aegis, Im installing it right now. Thx
You should be able to export from Google Authenticator and import into Aegis.
If there is a way, I was unable to find it
I had assumed because Aegis had an option to import from Google Authenticator that this would mean you could export in bulk. Bad assumption to make, it sounds like you can do it if you have a rooted phone but Authenticator doesn't make it easy. I did find this that shows a method to do a handful at once: https://blog.jay2k1.com/2021/11/17/how-to-bulk-migrate-from-google-authenticator-to-aegis/
Yes, I just did it. Go to google auth - transfer accounts - you get QR code, screenshot it - and import in Aegis
Huh. I was not able to make it work, perhaps I just overlooked something.
What's the benefit of Aegis over FreeOTP+?
For one, Aegis is more well known. Aegis has 6k+ stars where FreeOTP+ has about 500. This doesn't mean it's better, just that people are more likely to recommend it.
Aegis also has more features, and can import from many different authenticator apps (though as many don't allow exports, this may require technical knowledge to get the database and feed it in). If you have root then Aegis can pull directly from the other apps.
Aegis claims they are better than FreeOTP because the encrypt passwords at rest.
One big difference is FreeOTP+ lets you not have to enter a pin/password to see the codes while Aegis you need to enter a pin, password, or biometric to see your codes.
Popularity aside, you sold me on the import compatibility. FreeOTP+ can export to other FreeOTP+ installations, but I've had issues with exporting to other apps. I had to manually import using the secrets displayed within FreeOTP+. The encryption sold me. I will be migrating to Aegis. I haven't heard of it until this post, and have been using FreeOTP+ sans encryption.
Use Aegis lol.
This, I've just installed it this week and I think it's better than Google (though I'm suspicious of the "free" service.
Its not a service its an app. And yes nothing is free so please donate to the Devs
I use Authenticator Pro. It allows backups for itself or for exporting to other apps.
+1 To AuthPro, the guy behind the app is really cool
I use Aegis like several others here and then backup my codes to a Cryptomator vault which I can then sync online for cloud backup
Aegis or Ente Auth for Android. Backup your databases in your cloud of choice. Do not use Google Authenticator.
When enrolling with the 2FA take a screenshot of the QR code, print it and add it to wherever you keep your secure documents. The QR code is your private key, just scan it again to add a new device if you lose your original.
Obviously you need to keep the code secure!
deleted
Keepass + Syncthing
KeepassDX is a good android client, and it supports TOTP.
Just take a screenshot of the QR code and save the image somewhere
I dont know why you got downvote. Seems like perfect backup if stored somewhere safe. Am I missing something?
You could use a python script with oathtool copied onto each of your devices. This is not a good suggestion.
I prefer an authentication code, which I can save on a pendrive or, if not, a second email. I never use 2FA with a phone number, precisely because a phone is never secure and is also a privacy hole. It's enough that they know my email, it's not necessary that they also know my phone number.
Who knows my phone number if I use Aegis?