Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good motivation to stop using Authy.


What is a good alternative?


Besides all the other advice of using the password manager as a 2FA store as well, on the stand-alone side there is Aegis. I have good experience with it, and allows better interoperability than Authy as well.


Aegis (Android), supports automatic backups. There is also Ente Auth (it's been mentioned on this site), but I haven't used it much.


On iOS, I’ve been using “OTP Auth”.

While it’s nice that password managers can handle this as others have mentioned, the whole point of a 2nd factor is to ensure an attacker can’t get in if they somehow get your password. Storing the second factor along with the 1st factor doesn’t make much sense to me.


Most likely whatever password app you use supports these now. I know for myself, I started using Authy long long ago when there were not really many options.

In my case, 1 Password can do this now. I believe the same is true for Bitwarden and Apple passwords.


I hesitate to use the same app for both authentication factors.

The reason why I started using Authy a long time ago is that it supports multiple devices and isn't linked to any other account (such as Google or Microsoft).


Also KeePassXC -- if you don't like the idea of 2FA codes being in the same db as passwords, it's straightforward to use a separate db for 2FA only.

Manage your own sync between devices with syncthing, dropbox or whatever you prefer.


Personally I dislike the idea of putting the other factor(TOTP) alongside the main two ones (email/password). Kind of ruins most of the purpose of TOTP and MFA in general.


I'll join the choir and recommend Aegis. It's slick, got features, code on Github.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: