So basically what title says.

Im using 2FA with google authenticator for multiple accounts. What if my phone gets stolen? Can I have some kind of backup? Or maybe sync with some self hosted service?

Bonus question: what 2FA should I use instead of google?

  • Cotillion@lemmy.world
    link
    fedilink
    arrow-up
    27
    ·
    1 year ago

    Use Aegis on android or 2FAS on iOS. And just backup your seed on hdd/usb stick. Dont upload on cloud.

  • rambos@lemm.eeOP
    link
    fedilink
    arrow-up
    9
    ·
    1 year ago

    Thank you all for tips. I got Aegis and backing it up to my selfhosted nextcloud. I will also keep google app in use for now, but I might get keypassxc or vaultwarden in the future

    Cheers

  • akilou@sh.itjust.works
    link
    fedilink
    arrow-up
    9
    ·
    1 year ago

    I use Authy and am logged in on multiple devices so if I lose my phone I can still access the 2FA on my laptop. Then log back into the new phone using the laptop.

  • m0yP@lemmy.ml
    link
    fedilink
    arrow-up
    4
    ·
    1 year ago

    Aegis or Ente Auth for Android. Backup your databases in your cloud of choice. Do not use Google Authenticator.

  • Zerush@lemmy.ml
    link
    fedilink
    arrow-up
    3
    ·
    1 year ago

    I prefer an authentication code, which I can save on a pendrive or, if not, a second email. I never use 2FA with a phone number, precisely because a phone is never secure and is also a privacy hole. It’s enough that they know my email, it’s not necessary that they also know my phone number.

  • Synthead@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    All you need is the TOTP secret, and it will generate OTPs. If you enter the secret in another TOTP app, you’ll also get OTPs. Here’s a Ruby lib that will render OTPs from a secret, for example: https://github.com/mdp/rotp

    For an Android TOTP tool, I like FreeOTP+. You can even use it for Steam OTPs.

  • peasntanks@lemmy.ml
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    1 year ago

    You could use a python script with oathtool copied onto each of your devices. This is not a good suggestion.

    • shortly2139@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      1 year ago

      Just a heads up. There is no way to export from authy. So if you ever want to switch apps for whatever reason, lets say they were bought by big evil corp., then you would have to go and regenerate all your keys. Where as a good app would let you export and import from anywhere

      • AtmaJnana@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        edit-2
        1 year ago

        lets say they were bought by big evil corp

        Is this an intentional joke? (I often miss jokes so I am asking seriously)

        Authy was bought ages ago by Twillio, which also owns Segment (customer data platform)… So Twilio may not be all that big, but they’re fairly big players in the tracking and ads space. Which I loathe.

        I’m in this thread because I want to move away from Authy for this very reason.