4 ms·
I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a stro
by dnr 7y ago
I've used Google Authenticator for a long time, but the lack of backups is a really serious downside. What I would really like is encrypted backups using a strong passphrase that I can write down on paper (like Authy), but from a trusted source like Google, and with no other features to widen the attack surface (no internet access, no SMS).
Without backups, having a phone die or get lost is a very frustrating experience. If you use backup codes, you have to go re-register 2FA on every account with backup codes. And of course some don't offer backup codes.
You could screenshot and print out the QR code at registration time (I've done this for a few accounts), but shared printers apparently retain history of everything they've printed, so you'd need to own a personal printer, which seems absurd.
You could write down the TOTP secret on paper instead. Ideally with multiple copies and then move them to different physical locations. That's a big hassle to do for each new account registration, which seems to happen every few months.
Encrypted backups solve this easily: you get one key, which you write down once and distribute to different locations if you want. After that there's nothing new to do for new accounts at registration time. And restoring onto a new phone after one dies is also easy.
- ryall 7y agoTotally agree, I had my phone stolen a few years back. Had to buy a new one. What a surprise when I restored Google Authenticator and all my sites were gone. However I do have an issue with 1password's feature of auto-filling those codes, seems like it's just invalidated the whole "something you have" party of MFA. For me Authy is a happy medium
- ThePowerOfFuet 7y agoGoogle Authenticator is backed up on iOS if you use an encrypted local backup via iTunes (or macOS Catalina) or iMazing.
- c9fc42ad 7y agoI've been using the OTP Auth[1] app on iOS as it has support for encrypted backups with a passphrase. It also offers iCloud backup but I have that disabled as I'd rather manage the backups myself. No affiliation, just a happy user. [1]: https://apps.apple.com/us/app/otp-auth/id659877384 https://apps.apple.com/us/app/otp-auth/id659877384
- ThePowerOfFuet 7y agoGoogle Authenticator is backed up on iOS if you use an encrypted local backup via iTunes (or macOS Catalina) or iMazing.
- eikenberry 7y agoUse the text based secret and save a copy in an encrypted file and keep it on a usb memory stick. Put that in a safety deposit box if are paranoid enough. Either way, you lose your phone you have all your auth secrets available to re-enter.
- dnr 7y agoRight, so ideally I would like to keep something in a safe deposit box (or similar), but the point is I don't want to keep going back and forth to the bank every time I sign up for a new account with 2fa. That's why I want one long-lived secret that I can put there, and have the TOTP secrets encrypted with that one.
- kureikain 7y agoHi David, I built exactly this: https://github.com/yeo/bima https://github.com/yeo/bima I stored everything into a SQLite in `~/.bima/bima.db` Your OTP secret is encrypted using a master password that you chooese. I use AES GCM for encryption: https://github.com/yeo/bima/blob/master/shield/encrypt.go#L19-L31 https://github.com/yeo/bima/blob/master/shield/encrypt.go#L1... You then has 2 options to backup/sync among device it: 1. backup that file using dropbox, icloud, google drive 2. Enable sync to my backend. You sync encrypted data, even me cannot see it. Then other device can sync from my backend, and you enter your master password to decrypt it. Entire thing is open source, implement using Golang Fyne UI toolkit so it run across linux/mac/window/ios/android. If you want to help beta test it, I can send you a beta build.
- dnr 7y agoI definitely want to keep 2fa secrets on a phone, not my laptop, otherwise it's not a true second factor. If you have an Android build to try, I'll check it out. Also, part of my ideal requirements is an app built by an entity that I trust as much as Google. Open source is great, and this app is simple enough that I can skim the code once, but I'm not going to do it for every update, and I might miss something. There's still something to be said for that kind of accumulated trust. (I might not trust Google as much as I used to, but I still keep my life on gmail, so I have to trust them pretty far.)