However, those who synced their desktop apps with the mobile versions have discovered that some of their tokens did not correctly synchronize, making their associate accounts inaccessible.
Lol
Well that fucking sucks.
Yeah, laughing at the customers (who were making a good decision to make sure they had 2FA enabled) is kind of a dick move.
But from the perspective of the company fucking up that bad it’s funny.
I use their phone app. I sure have a weekend chore to get the fuck off that app.
This prompted me to move away from Authy, and looking it up, it doesn’t allow you to export your TOTP tokens. There were some workarounds but then have been plugged, I tried.
Mostly switched over to Bitwarden’s equivalent. I’ve been using their password manager for many many years now and am very happy with it. They have an export feature in a few different formats.
What are some good multi-platform alternatives/ replacements?
Bitwarden or Proton Pass.
Keepass. Standalone FOSS apps for desktop/phone. Has OTP support.
Password/tokens are stored in a small encrypted db file you can copy/paste anywhere you need it. Has hundreds of plugins to do various things.
Use something like syncthing/nextcloud/onedrive to keep the file in sync across devices.
I use KeePassXC and a Yubikey 5. You can store a certain number of 2fa on the key but i also back up the secret key and recovery codes on KeePassXC which is backed up on my Nextcloud. When using the Yubikey there is an app on desktop and mobile that reads they key but doesn’t store the codes. Open the app, plug in the key, the TOTP appears, take the key out and the TOTP is gone.
I like using bitwarden, the selfhosted vaultwarden server stores it with passwords and makes codes available in the app / browser extension. I also keep them backed up on a nas and synced off-site just in case.
Along with others already mentioned, 1Password can support 2fa.
1Password has impressed me. I’ve used KeePassXC, LastPass, Bitwarden (but not extensively and one of the early versions), and even CyberArk (🤮).
1Password is closed source but it’s one of those pieces of software that just works the way you expect it to. Hard to confirm a lot of their security claims. Just rolling with “Have not heard a lot about 1Password breaches” mentality.
We got lucky at work and used it to replace an unmanageable long list of KeePass database files that were sprawling everywhere. With that everyone who uses 1Password at work gets an associate private family account. Made managing my kids passwords and share some of our common family passwords way easier and I still get to lock them out of my passwords I don’t want them using.
I believe modern Bitwarden for enterprise has a similar licensing sweetener with a private family account for each corporate account.
andOTP + bitwarden for me
AndOTP is great. Its free and had simple and easy encrypted backups. I love how its timer counts down, not up like some others and highlights the token in red so you know you need to hustle or wait.
It seems I cannot install it because the app is too old for Android 14…
Welp, time to finally migrate one at a time to Proton.
Well that’s already my Monday morning gone. I use Authy desktop for all of my work 2FA tokens.
KeePass has native TOTP support now
this is what I did, syncthing syncs the DB across all my devices(including my phone), and it uses a certificate key + password for the master. It lets me secure all my stuff in one location without having to mess with my phone.
I know it’s less secure but, nobody has a desktop app anymore, so I would rather just have it all in one place then have to dedicate another mobile app for it.
Just spent a week manually moving everything off Authy. Total pain, but there are lots of better solutions out there now.
I used Authy a couple years ago, do I need to be worried?
Only if you use it currently. Otherwise no worries.
Thanks. I couldn’t understand if there was a data breach that led to this or if it was just current users.
Whoa