Hacker News new | past | comments | ask | show | jobs | submit login

Very cool. I already started moving all my 2FA stuff out of Authy but guess it needs to be hastened now.



IMO it's good practice to not one's vital 2FA codes held hostage on a service where one's accounts or IP address can be flagged for spam or abusive behavior by automated systems. (This also applies to Google Authenticator, for what it's worth!) Especially in a world where customer service teams are being trimmed wherever possible!

I use 1Password - its UI leaves some things to be desired, and it's not cheap, but it has zero incentive to cancel the account of any paying customer!


Google Authenticator is completely offline isn't it? How are accounts / 2FA material at risk of lockout by using Google Authenticator?


I switched out of Google Authenticator when they updated the app and all my 2FA just went away.

They did fix it with another update, but that was a seriously un-fun few days. Luckily I was just logged in to my AWS account so I could disable the 2FA.


It is, and because of that people regularly lose their vault when switching phones and forgetting to transfer the data.


What alternative are you using?


I migrated to Aegis a few months ago and would recommend it.

Exporting the configuration was a bit tricky, but I found a guide on GitHub: https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...


Passkeys if the site supports them as a secure authenticator for 2FA/MFA (should pop up in your device if you try to setup a secure hardware authenticator on iphones and android) or TOTPs stored securely somewhere that isn't vendor locked.


I use https://github.com/tadfisher/pass-otp with pass, which has a FOSS client for desktop and smartphone (at least for andriod, no idea for ios)


It's built in to passforios

https://github.com/mssun/passforios


iCloud Keychain


Bitwarden


I don't really like the idea of TOTP and passwords in the same place. If it gets compromised someone has both your password and TOTP code.


I use Bitwarden for passwords only. I use Authy for the TOTP, although I should use something else.

I backup my TOTP seeds in KeepassXC. I also have an offline backup of my Bitwarden vault that is in a separate KeePassXC vault. I agree that I don't like the idea of one vault holding both bits of info.


Yep I agree so I use 1Password only for passwords and Bitwarden only for TOTP.


Is there an easy way to import from authy to bw? Or do I have to do one at a time.


The officially supported method is to login to each 2FA account and delete the old 2FA and generate a new one that you make sure to record separately. Authy really locks you in.

There are some unsupported methods a Google search away. I have had luck with this one in the past but haven't used in over a year, so can't vouch for it still working.

https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...


Sorry I'm not sure.


I had no idea authy was owned by twilio. Well I know what I'm doing this weekend


how does this impact Authy?


Twilio owns Authy but regardless it doesn't. Authy is mostly used client-side with a server-side backup option.


ah gotcha, i didn't realize that


Authy appears to be up, but I guess if it were down, the only issue would be trying to setup a new device and have it sync over the 2FA codes? My understanding is after that initial sync, the TOTP it displays should all work offline.


Authy is owned by Twilio.


Twilio owns Authy. I guess they’re assuming future issues there or with syncing.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: