techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

4.6K
active users

#GoogleAuthenticator

0 posts0 participants0 posts today

¿Alguien utiliza TOTPs? Yo utilizo #googleauthenticator pero como estoy en ese camino de desgooglearme estoy buscando alternativas.

Desde el sitio wed de #disroot mencionan un par pero uno, #andOTP parece ya no tener su página en #fdroid, y el otro que es #FreeOTP+ no se ha actualizado desde el 2024. Igual estos los he chequeado desde el repositorio por default de F-Droid así que todavía no he visto en otros repos.

Pero bueno, quienes usan TOTPs ¿Cuáles usan o cuáles recomiendan?

Parece que no es posible importar las claves de #GoogleAuthenticator en #Aegis si no tienes el móvil rooteado, salvo quizás haciendo cosas muy raras con emuladores en un portátil o usando dos dispositivos y escaneando códigos QR de uno en uno.
Pero quizás no sea mala idea empezar de cero y que tus códigos 2FA no estén en poder de Google.

If you are like me, then you might have installed the #GoogleAuthenticator app, back in the days when it was the only solution out there for #TOTP #2FA.

But that is long ago. Since then, #Google has closed-sourced it's solution, forced #cloudsync otto it's users and stores these information unencrypted; plus it's suspected to collect even more data from you than needed. And it's a US BigTech company.

I've looked into a couple of alternatives and landed with #Aegis and #EnteAuth which are both excellent #free #opensource choices from #europe. I went with @ente because of it's larger platform support.

So why are you not already using an alternative? It's super easy, and took me less then 10 minutes:
1. On GoogleAuthenticator go to the ☰
2. Select transfer codes
3. Select all the codes you want to transfer --> Google will create a number of QR-Codes, each containing 10 accounts.

On your alternative say import, and scan the Google codes and you're good to go and can let go of yet another proprietary US BigTech dependency (and thus liability).

If you are already using a different #TOTP #2FA app on your smartphone, which one is it, and why?

On multiple sites my #2FA codes from #GoogleAuthenticator on #Android are now only accepted in roughly the first half of the code window. After that I have to wait until the rollover to a new code. This is very frustrating. Authenticator has almost no settings, certainly nothing to resync the clock. Should I assume it's a configuration issue with the target sites and notify them?

As I got a new phone, I'm looking for a secure alternative to #GoogleAuthenticator

Because AFAIK it stores "seeds" in cleartext, and I try to #degoogle step by step.

I seem to remember a website which listed (#Android) #Security Tips (I this it was a .sh TLD domain)

So two questions:

  • Can anyone recommend a Google Authenticator alternative (ideally open source
  • Does anyone know this website?

Edit: It could be that the website was book.hashbang.sh/ but it doesn't have anything about Google AUthenticator 😞

book.hashbang.shAbout This Book

Ok, I'm going to fully admit I'm not entirely sure how to use #YubicoAuthenticator amongst multiple #YubiKeys vs, say, #Authy or #GoogleAuthenticator after a year+ of off/on looking to try it out.

Do I need to store the #TOTP seeds on every #YubiKey I own? And they all take up a slot? If so, I'm glad for most high value ones, I've been saving encrypted copies of the initial secret key in my password manager. Is that the way it works, all stored in the keys, and not some DB on each device?

A very special Fuck You to #Google #Googleauthenticator which has such vile dark patterns that all my OTP generation codes are now "backed up" to the cloud

Under my work account no less, even though it's not the default on that device and I most certainly didn't want that

If that happens to me with a single stray click, to how many other does it happen without them realizing?

Let's not mince words here: This reduces the security of my "two factor" to near zero. Fuck everyone involved in this