One more step to unhitching from Google…

Right now the only option I see in F-Droid is Aegis.

I’m not sure what to actually look for side from checking for unexpected permissions and reasonably frequent updates.

Hopefully something I can sync with a GNOME app…

  • sbird@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    6
    ·
    3 hours ago

    Aegis seems like a pretty good 2FA app on Android from what I’ve heard. Personally, I use Ente Auth as sync is very helpful when I don’t have my phone nearby (you can either use the desktop app or use your browser, both work). Don’t think you can self-host sync, though I might be wrong. Ente Auth also works without sync, so there’s that.

    I would not suggest using a password manager’s 2FA integration (e.g. Bitwarden, I think Proton Pass has one if you use that?) as it kind of defeats the point of 2FA, since if someone got access to your password manager, they would also get the 2FA codes.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    4 hours ago

    Authenticator and Authenticator.

    Damn thoe innovative tech companies, what will they think of next.

  • retro@infosec.pub
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    5 hours ago

    Proton Authenticator. Has both Desktop and Mobile apps. Free. Don’t have to sync to Proton.

  • Fair Fairy@thelemmy.club
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    edit-2
    1 hour ago

    Vaultwarden, bitwarden does 2fa tokens as well.
    I use it now.
    I used to use aegis before.

    • HereIAm@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 hours ago

      Same. Self hosting it sounds nice, and I self host a handful of services, but I don’t want to be stuck without passwords in another country with a dead server at home because a power cut happened at some point.

        • HereIAm@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          50 minutes ago

          Oh, that’s actually good to know. I guess it makes sense for when you don’t have a good connection as well.

  • Max@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 hours ago

    I use bitwaarden and stratum since it has a wearos app as well and it’s nice to use that for 2fa codes

  • ohshit604@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    6 hours ago

    Yubikey for 2Fa codes also works well for sudo and su (2Fa) or if you still use Windows I think it supports single sign on there. Absolutely worth the purchase have had my keys for years.

    • 5ymm3trY@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      Can you explain a little more how you handle them in your daily life? I always liked the idea if Yubikeys, but I am a bit worried that I just would switch back to my phone (Aegis) for convenience. Things like:

      Are there accounts that you didn’t get to work? Do you have separate keys for personal and work accounts? Do you just have it on your keychain an plug it in whenever you need it? Because always plugged in keys in your phone or laptop doesn’t really make sense. As far as I know you can’t just clone a key. How easy is it to setup a backup key? Does this work for all accounts? I try to not use my phone for critical stuff, but there are times I have to just check an account. Do you use your phone with Yubikeys? How is your experience? USB or NFC?

      • ohshit604@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        5 hours ago

        Can you explain a little more how you handle them in your daily life? I always liked the idea if Yubikeys, but I am a bit worried that I just would switch back to my phone (Aegis) for convenience.

        I have two Yubikey 5 NFC’s, one I keep majority of my 2Fa auth codes on and keep on my keychain the other I leave at home mainly for backup 2Fa setups or desktop/WebAUTH/Single Sign-On logins, most websites won’t let you setup 2 2Fa keys so the second one mostly handles the plug-in and touch key portion of my setup.

        Are they inconvenient? Yes, the amount of times where I got annoyed because I’ve had to grab my keychain to sign in has gotten annoying but not enough to switch back to online providers. I prioritized security over convenience in this circumstance. The Yubikey that I keep on my keychain also handles my work 2Fa codes, doesn’t feel necessary to have a dedicated key for that unless my company is willing to pay for it.

        Do you just have it on your keychain a plug it in whenever you need it? Because always plugged in keys in your phone or laptop doesn’t really make sense.

        It actually works out quite nice having it plugged in all the time, especially if you’re doing multiple 2Fa authentications, the keys won’t authenticate until you enter the password of the key (if you set one up) and touch the key, so even if your computer is compromised they still need to physically touch the key to generate the authentication codes.

        As far as I know you can’t just clone a key.

        So no you cannot clone a Yubikey to another Yubikey, which I think is dumb, but they have their security reasoning behind it I believe. Like I mentioned earlier all my 2Fa codes/keys are on my keychain so if I break that key I am in a horrible position as I lose access to a lot of accounts that I couldn’t setup multiple 2Fa’s for.

        How easy is it to setup a backup key?

        While Yubico does recommend having two keys as I mentioned certain services only let you setup 2Fa once and not multiple times. However, Linux (and I want to assume Windows as well) let you setup as many 2Fa keys as you want, so both the Yubikey on my keychain and the one I leave at home both grant Root access to my desktop and server.

        I try to not use my phone for critical stuff, but there are times I have to just check an account. Do you use your phone with Yubikeys?

        So I don’t have a USB C Yubikey ironically both my iPhone and iPad are USB C so I have the option to use a dongle or NFC, both have worked great, I have had a couple scares where the app will error and say “No response from key” but it seems that error is due to bad contact/connection. I’ve attached a few images of the iOS app to help get an idea of the layout.

        Once you open the app

        Swipe down to scan for NFC

        After scanning key it shows you your accounts

        Click on your desired account

        Click calculate and scan your key again

    • Matt The Horwood@lemmy.horwood.cloud
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 hours ago

      We use yubikeys at work, far better then an OTP. Also I have 2 for home use, the only issue is I need to put 1 on some keys I carry as I sometimes need 1 and don’t have it.