• adbenitez@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    2 days ago

    I used it for a while, it is quite good, but I recently switched to a webxdc (in-chat mini-app) in Delta Chat which allows me to access the codes from any device where I have Delta Chat installed and adding a new token in one device synchronizes to all other devices this also mean that my tokens are safe if one of my devices die and I will not lose them. All of this is without depending on a server holding your data

    • easily3667@lemmus.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      Syncthing bud, just use syncthing. Aegis will export a backup on any change and keep N backups. Just use syncthing. Just. Use. Syncthing.

      • adbenitez@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        21 hours ago

        No need bud no need for additional app, no need for unencrypted backup files exposed on filesystem public storage, just use Delta Chat bud, just use Delta Chat

    • pipes@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      1 day ago

      I don’t need it but I have to try this 😄 I’ve been using Delta chat for a while now but never tried any mini “apps”, do you have any suggestion?

      • adbenitez@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        21 hours ago

        Go to your “Saved Messages” chat there you can save notes or use mini-apps in private, click the paperclip attachment button select the apps button you will see the mini-apps list, some useful apps are the to-do list app to track things you need to do or shopping lists, and the one called TOTP is the one I was talking about for 2FA PINs, the Time tracking app is also useful

  • aldfin@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    I use 2FAS Auth personally as an iOS user. Is it considered a good choice?

  • pipes@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    2 days ago

    I use this, a couple of tips: set up a fingerprint unlock so you dont have to type a pin everytime; and I advise not to keep your TOTP codes only in a phone app, you can save them in KeepassXC on your pc for example.

    • RogueBanana@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      You can setup regular auto backups along with syncthing to keep it safe. That’s what I am doing so to store the file in multiple devices and locations.

      • pipes@sh.itjust.works
        link
        fedilink
        arrow-up
        0
        ·
        1 day ago

        I love syncthing, so versatile. I don’t backup the Aegis database with it only because my TOTPs are already in Keepass and because Aegis is backed up by Seedvault already (Lineageos)

    • x00z@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 day ago

      If both your password and TOTP code are saved in the same place, that’s a single attack vector. Saving your TOTP codes in Keepass destroys the second factor part of the protection.

        • LastYearsIrritant@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 day ago

          Keeping it on physical paper helps in almost all cases.

          1 - It separates the backups from the internet, helping prevent security vulnerabilities from stealing your MFA codes. Cloud backups along with cloud passwords means you would get caught up in any major data breach.
          2 - It allows you to set up a new device without needing to have the old device. If you lost/broke your phone, then those local QR code exports are gone.
          3 - People generally know how to keep physical things safe. You can put them in a bank’s safety deposit box, in a fire safe, or just in a folder in your desk. As long as they’re not also sitting near your passwords, they’re pretty useless to most people, and the likelihood that someone is going to physically try to swipe your account data is extremely low.

    • GreatAlbatross@feddit.uk
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      I have some of the NFC/USB sticks Token2 make.
      Which are neat, as you can stick the seeds on there, then retrieve them so long as you have physical access, and the passkey.

  • Lazycog@sopuli.xyz
    link
    fedilink
    arrow-up
    0
    ·
    3 days ago

    Been using Aegis after switched from FreeOTP and I love it. UI is also pleasing (although I don’t spend much time in the app, but still)

    • vaguerant@fedia.io
      link
      fedilink
      arrow-up
      0
      ·
      2 days ago

      Looks like development on AndOTP stopped ~4 years ago (July 2021). There’s definitely an “if it ain’t broke” factor, but the way Android keeps dropping support for older SDK apps, you will probably need to switch to something else eventually. I hadn’t heard of Aegis before this thread, but apparently one of its big features is support for importing from other authenticator apps (including AndOTP and Google Authenticator).