One more step to unhitching from Google…

Right now the only option I see in F-Droid is Aegis.

I’m not sure what to actually look for side from checking for unexpected permissions and reasonably frequent updates.

Hopefully something I can sync with a GNOME app…

    • Lyra_Lycan@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 months ago

      As I’ve seen gaming server subscriptions go from £36/y to £23/m (Xbox) in a few years, and cloud CCTV storage from £40/y to £16/m (Google via acquisition of Nest) in a few months, I say we count our stars when a subscription cost remains fair.

    • HereIAm@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 months ago

      Same. Self hosting it sounds nice, and I self host a handful of services, but I don’t want to be stuck without passwords in another country with a dead server at home because a power cut happened at some point.

    • ikidd@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      Yah, I can’t see a point to have another app/extension when Bitwarden has it built in, and it’s a great password manager.

        • ikidd@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 months ago

          Right under Password in the edit screen of an item: Authenticator Key. You put in the auth key the target site provides you when you enable TOTP and it will start generating timed tokens. Usually you’ll also get a one-time pad of backup keys, I usually toss those in the Notes of the edit screen there as well in case something goes wrong.

      • Lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        The point of 2FA is “something you have” and “something you know” to enter a secured system.

        If you put both of those into one system that is accessible by one password, the whole concept is defeated.

        • ikidd@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          4 months ago

          My threat model isn’t having someone take my computer and log into stuff so my concern when using 2FA is more about them having gotten hold of a password remotely. But a TOTP makes that password pretty hard to use, no matter where it’s stored. And my BW is also protected by a Yubi/password combo, so I guess I’m just vulnerable to having that beaten out of me.

      • waspentalive@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        But if they get your Bitwarden vault and crack it - they have everything Throw a roadblock in their way - use a separate app for OTP.

  • AMillionMonkeys@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    2
    ·
    4 months ago

    Bitwarden Authenticator because Bitwarden seems to have a good reputation. I don’t use their password manager, though.
    It does seem faintly insecure that it displays all of the codes at once on one page, but I’m having trouble imagining a scenario where it’s actually a problem.

  • retro@infosec.pub
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    4 months ago

    Proton Authenticator. Has both Desktop and Mobile apps. Free. Don’t have to sync to Proton.

  • Lka1988@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    4 months ago

    I use Aegis, automatically backed up every time a new key is added. Was using Authy for a while, but they’re going down the enshittification hole, so I dumped them.