arda,
@arda@micro.arda.pw avatar

Hey iOS :apple_inc: users, what 2fa app are you using?

I'm going to migrate from Raivo to another, actively-maintained open-sourced app which is not a product.

I was using Raivo OTP, but it got purchased by a company, and development has been frozen.

There are some open-sourced apps such as Ente or 2fas, but I was wondering what are you guys using and why.

I have personal backups so lack of import is not a problem for me.

#iOS #2fa #mfa #authenticator #raivo #ente #2fas #Apple

arda,
@arda@micro.arda.pw avatar

Migrated my TOTPs to @ente Auth. It's an open-sourced no bullshit app that does the job right. Can run offline, and defaults are offline (unlike @2fas , which enables iCloud as default ), locally encrypted keys, could be unlocked via face ID, and you can export encrypted backups. It could also import from raivo and other tools, and is not a total piece of product. so all of my concerns are covered.

https://github.com/ente-io/auth

It's also cross platform, so you could also check on Android as well.

ocubom,

@arda Few months ago I migrated to https://2fas.com/. It has migration, export and backup mechanisms. Works smoothly

arda,
@arda@micro.arda.pw avatar

@ocubom Thank you! I was thinking about migrating to 2fas, but needed some feedback for real time users. Appreciate the input.

arda,
@arda@micro.arda.pw avatar

@ocubom Hey again, sorry for the late second reply, but how secure do you find 2fas?

The discussion at @privacyguides put me in dilemma:

https://discuss.privacyguides.net/t/add-2fas-authenticator-app/12958

DirkSchernikau,
@DirkSchernikau@norden.social avatar
arda,
@arda@micro.arda.pw avatar

@DirkSchernikau @ho1ger @bitwarden

I'm already using it. I believe putting passwords and TOTP codes in the same basket is a bad practice.

Please see my reply here: https://micro.arda.pw/@arda/111708685114073673

dentaku,
@dentaku@fnordon.de avatar

@arda @ho1ger I use Bitwarden (with a self hosted Vaultwarden as vault).

ho1ger,

@dentaku ah =) Me too!

@arda And by the way: you can install Vaultwarden on a VPS using Docker in ... 5 Minutes.

arda, (edited )
@arda@micro.arda.pw avatar

@ho1ger @dentaku I also use bitwarden + selfhosted vaultwarden as well 😊

However, I believe storing passwords + TOTP codes together is a bad practice overall, so I try to avoid it.

I could theoretically raise a second vaultwarden container instance just for totp, but it'd be hard to manage on the client side, going back and forth between accounts.

That's why I'm looking for a totally offline open-sourced totp app (I could be okay with selfhosted backends though).

tobi,

@arda I’m using OTPAuth (https://apps.apple.com/de/app/otp-auth/id659877384?l=en-GB) which has also a watch app as well as widgets for macOS and iCloud backup. Pretty neat.

arda,
@arda@micro.arda.pw avatar

@tobi Heya, thanks for the suggestion! This looks quite decent! If only it was open-sourced. However, I'll definitely check this and will try if it's actually secure, as it claims. Thanks!

vsaw,
@vsaw@mastodon.social avatar

@arda NextCloud Passwords

zaherg,

@arda 1Password 😅

arda,
@arda@micro.arda.pw avatar

@zaherg Nope, not leaning my 2fa codes to a closed source product 😆

In all seriousness, I already use @bitwarden + #vaultwarden open source alternative backend self-hosted, so even though that may be a good alternative, I don't need to overcomplicate my flow.

zaherg,

@arda if i recall bitwarden provides 2fa functionality.

So you can hosted locally, have a vpn with your local machine to access it, just so it wont be accessible to everyone

arda,
@arda@micro.arda.pw avatar

@zaherg I'm not sure if vaultwarden supports it (I didn't check), but nevertheless: It's not a good practice to put TOTP codes and passwords in the same basket, even if they are totally self-hosted. So I'm avoiding it.

zaherg,

@arda you can run two services one for the 2fa and the second for the passwords.

arda,
@arda@micro.arda.pw avatar

@zaherg I'd rather not run any service and make it totally an offline app, like it's 1993 😆 For ideal 2fa appliance, the code should be generated locally and not touch any services.

If I go that route, as 2fa definition, even my ISP, or VPN provider, or Cloudflare proxy etc. could be a attack/risk factor, if I'm that paranoid or perfectionist (I'm not, just lazy 😂 and since offline app covers the definition and it's just an app so I'd go that route instead)

zaherg,

@arda I use those cases as learning :D

btw, check tailscale (alternative to CF)

arda,
@arda@micro.arda.pw avatar

@zaherg You are like 3rd person telling me to check Tailscale 😅 . I will, when I have some decent free time, thanks man! 🙏

  • All
  • Subscribed
  • Moderated
  • Favorites
  • iOS
  • DreamBathrooms
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • GTA5RPClips
  • JUstTest
  • ethstaker
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • tacticalgear
  • anitta
  • Leos
  • provamag3
  • cisconetworking
  • megavids
  • lostlight
  • All magazines