Hi guys

What 2FA for iOS would you recommend after Raivo OTP been sold?

    • Supertramper@feddit.de
      link
      fedilink
      arrow-up
      5
      ·
      10 months ago

      From a security perspective, unlocking your third-party password manager AND your 2FA authenticator on the same phone with FaceID is not the best solution. An attacker who manages to compromise FaceID will have access to your credentials as well as your 2FA codes.

      That’s why I recommend a separate 2FA app with a custom 6-digit pin lock.

  • Raisin8659@monyet.cc
    link
    fedilink
    English
    arrow-up
    6
    ·
    10 months ago

    Try 2FAS. Open-sourced. Also works on Android. Has a browser extension that allows automatic 2FA entry paired with a phone.

    OTH, if you need a Windows client, then Authy may be the way to go. Need to religiously copy the TOTP secret (when setting up) and save it somewhere else, though. Because it doesn’t officially allow export, it might be a bitch to move to other authenticators.

  • skv@lemm.ee
    link
    fedilink
    arrow-up
    6
    arrow-down
    1
    ·
    10 months ago

    Protonpass, it’s free, opensource and supports multiple platforms as well.

    • Harrison@infosec.pub
      link
      fedilink
      arrow-up
      4
      ·
      10 months ago

      From what I can see on their website, the 2FA feature is only available if you pay $1/month. No gratzie.

      • skv@lemm.ee
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        10 months ago

        Just seen it lol, and now I cant access my 2FA unless I pay, remember seeing in their website 2FA as part of free plan. Shame it isn’t. Apple keychain it is then for me.

    • Kwa@derpzilla.net
      link
      fedilink
      arrow-up
      3
      ·
      10 months ago

      I’ve just checked it, but it seems the 2FA is only available with the paid subscription. Or am I misunderstanding something?

  • ebits21@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    ·
    10 months ago

    I just use KeePassium with a keepass database (with just totp in it).

    I used to use Authy but I like to control my own data.

  • Nix@merv.news
    link
    fedilink
    arrow-up
    2
    ·
    10 months ago

    Wow I didn’t know it was sold. Just exported my backup from it and gonna search for a new one.

  • Simon@lemmy.utveckla.re
    link
    fedilink
    arrow-up
    2
    ·
    10 months ago

    I use Authy. I tried to migrate to using a Yubikey, but the Yubikey 5 NFC which I have has a limit of 32 TOTPs and I need to store more than that.

    • DuckGuy@lemmy.zip
      link
      fedilink
      arrow-up
      1
      ·
      10 months ago

      That’s what I’m using. It works as expected and is multi-platforms so I’m happy with it.

  • Eggyhead@artemis.camp
    link
    fedilink
    arrow-up
    2
    ·
    10 months ago

    I can’t recommend Raivo. One day I opened the app to find all my codes just… gone. It was like the app updated and was behaving like a new installation. I had made a backup, but I apparently assigned it a password I didn’t know. I switched to 2FAS and had to visit all my sites to create new tokens for each one. 2FAS hasn’t inexplicably deleted my tokens as of yet so I think I’m safe now.

  • Harrison@infosec.pub
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    10 months ago

    I just tried “2FAs”, which seems to be the most recommended free one. It failed to import any 2FAs from the Raivo export with 7 digits, but otherwise worked fine. Problem is it failed to import silently, didn’t give any errors, which was offputting. Using it for now, but Raivo was better software. Pouring one out.