11 ms·
Aegis Authenticator – Open-source 2FA for Android
- based2 6y agohttps://github.com/beemdevelopment/Aegis https://github.com/beemdevelopment/Aegis GPLv3
- ryukafalz 6y agoNice, I consider that a good sign! Means it's unlikely to ever go proprietary like Google Authenticator did.
- gchamonlive 6y agoCurrently using Authy. Any way to migrate my keys in bulk?
- deleted 6y ago[deleted]
- ignitionmonkey 6y agoIf you have root access, yes.[1] Otherwise no, sadly. One of the reasons I moved off Authy before it got worse. There is a workaround using the Authy Desktop app but I have no idea if it works.[2] [1] https://github.com/beemdevelopment/Aegis/pull/107 https://github.com/beemdevelopment/Aegis/pull/107 [2] https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93 https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
- gchamonlive 6y agoDone, migrated 40 accounts to Aegis. As I see, it backs up to the internal storage, so I have to use another app to sync the backup to a cloud of my choice
- ignitionmonkey 6y agoMight have a solution for you here: https://news.ycombinator.com/item?id=25804860 https://news.ycombinator.com/item?id=25804860
- ffpip 6y ago> so I have to use another app to sync the backup to a cloud of my choice You can select Google Drive/Dropbox when backing up the vault. https://github.com/beemdevelopment/Aegis/issues/258#issuecomment-570906665 https://github.com/beemdevelopment/Aegis/issues/258#issuecom...
- gchamonlive 6y agodoesn't seem to show for me, only internal space. I have no idea why. edit: this is not released yet, I think
- alexbakker 6y agoOne of the authors here. Unfortunately, Google Drive and Dropbox only partially participate in Android's Storage Access Framework. In Aegis, exporting only requires the creation of a file, so that works with both. Configuring backups on the other hand requires selecting a folder, but most cloud providers don't support that. A notable exception is Nextcloud.
- gchamonlive 6y agoHow about cloud paas providers like AWS? The user could generate a IAM access key with permissions to manage a specific bucket and configure Aegis with the key. Aegis would use the cloud Api to upload the backup. If that is of interest, I could help implement that.
- gchamonlive 6y agocommented on my question with a snipped I wrote based on that extraction method from authy. The code generates a Aegis compatible database instead of printing QR codes
- gchamonlive 6y agoin response to myself, I created a snippet to generate a database in bulk from authy. follow: https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93#file-authytootherauthenticator-md https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d... But change the code with: https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93#gistcomment-3596406 https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
- ktzar 6y agoI use andOTP, open source and can export and import keys so you can have them backed up.
- lucideer 6y agoandOTP used to have some pretty bad issues with security. I switched from andOTP over to Aegis way back then; I've heard that the andOTP author has been extremely active & responsive since, and responded/fixed the aforementioned issues over time, but I've been so happy with Aegis that I haven't felt compelled to go back.
- ignitionmonkey 6y agoThey're pretty similar apps in terms of features (Aegis does all of that too). Personally, comparing screenshots, I think Aegis' interface and choice of colours is more sleek, especially in dark and OLED modes, so it got my pick.
- PradeetPatel 6y agoFrom a user's perspective, what does it have over other 2FA apps such as Google Authenticator or Duo?
- lucideer 6y agoBeing open-source is not of exclusive benefit to non-users. Additionally, being non-Google would be considered a large benefit by many non-technical users I know.
- livre 6y agoI use this after having used Google Authenticator, what made me switch is easy backups and restores, not to the cloud but locally to a file. Also you don't need a Google Account if you wish to transfer your data to a new device.
- ignitionmonkey 6y agoTo add to this. Aegis supports any cloud provider that implements Android's "Storage Access Framework".[1] https://github.com/beemdevelopment/Aegis/issues/258#issuecomment-570906665 https://github.com/beemdevelopment/Aegis/issues/258#issuecom...
- ffpip 6y agoBetter UI and custom icon support for the random website you have. Plus this is offline. Hence more secure.
- gmac 6y agoI can’t tell from the homepage, but perhaps it supports SHA256? Google Authenticator on Android (but not, weirdly, on iOS) pretends to be fine with SHA256 but then goes ahead and uses SHA1, and thus generates wrong codes.
- livre 6y agoIt supports SHA1, SHA256 and SHA512.
- petespeed 6y agoAnyone knows if and how to use this instead of Microsoft authenticator?
- ffpip 6y agoI think Microsoft Authenticator is internet based. The 2FA secret key is backed up to their servers. Aegis is open source, free and has backup and restore functionality. It also has a great UI and custom icon support. Under active development - http://github.com/beemdevelopment/aegis http://github.com/beemdevelopment/aegis
- technion 6y agoWhen you setup Microsoft Authenticator, it defaults to a QR code that will be invalid to standard TOTP apps. However, that's because it assumes you want to use the push notification of the app. If you click a button like "key without notify", it will give you a different QR code which is fully standard and works with common apps like this.
- aorth 6y agoWow, that is a great tip! I have been avoiding setting up a TOTP with Microsoft for months because I didn't want to install their app and I didn't know you could click "without notifications" to get a standard code. Super annoying that they insist on texting me every freaking time I log into email or Teams. Now I can use Aegis, phew!
- supernova87a 6y agoI don't know about you but does anyone else screenshot (and even print physical copies of, to keep safe) their authenticator barcodes given by websites, in case some day your chosen app dies or your phone(s)/tablets/everything gets lost?
- Hamuko 6y agoThat's really what scratch codes are for.
- deleted 6y ago[deleted]
- cuu508 6y agoYes, but not every service offers recovery codes.
- loloquwowndueo 6y agoThat’s like a must. Services that don’t probably have an easy way to reset your 2FA via email verification which entirely negates the benefit of 2FA (last line of defence if your password or email are compromised). You probably want to stay away from those services entirely.
- ffpip 6y agoI sometimes do that when I don't have to write them down.
- tarruda 6y agoAegis has an option to export an encrypted backup of the database. I export one every time I add a new code to the app.
- alexbakker 6y agoOne of the authors here. Recent versions of Aegis also come with an automatic backup feature, so that an export is created at a location of your choosing automatically every time a change is made to your entry list. Might be a little more convenient than doing manual exports every time.
- ffpip 6y agoCan you add 'app' to the title? Open source 2FA App for Android.
- Ayesh 6y agoSucks that there is no Windows version. Android one looks pretty nice and I like that there are many import/export options
- loloquwowndueo 6y agoLol windows :) no seriously if you need an OATH application for windows you can probably coerce oathtool to run under WSL or even natively.
- Zizizizz 6y agoyou can install this > export backup to JSON > import to pass-otp and you have 2fa in your command line and phone
- m-p-3 6y agoThere are some KeePass-compatible password managers on Windows that can generate TOTP codes if that's something you want.
- anthony_barker 6y agoBeen testing this - migrated from FreeOTP (redhad). I have a conflict on export of keys for backup. But then you kind of need it in the event you loose the phone (so you don't have to rely on sms or email to recover account access). Personally I think the best security I have seen is in Keybase or Matrix with the trusted devices concept. I like how keybase allows for one of the devices to be a paper device.
- literallycancer 6y agoThere are scripts to help you export from FreeOTP (and transform to the FreeOTP+ format), even without a rooted phone. The opposition to export features by FreeOTP maintainers is idiotic, because there is no contract that TOTP seed never moves or lives only on one device. The only expectation is that it is not shared with 3rd parties and is carefully kept secret. At the same time, migrating to a new phone and having to change 30 different 2FA codes individually is untenable.
- exabrial 6y agoSounds awesome! Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA. Worse off, some SAASs _require_ Authy specifically. Think about that. That means the security of an enterprise system at your company is completely dependent on whether or not an individual secures their personal cell phone account. Absolutely stupid, avoid Authy like the plague.
- phreack 6y agoAnecdotally, I've seen a few places that instead of mentioning the protocol just say 'download G Auth' or 'download Authy', and so far all of those worked with Aegis when I tried.
- tobib 6y agoI've been using Authy for a long time and have never come across SMS for security. When would that be triggered?
- MeinBlutIstBlau 6y agoI think it's a point of recovery for your authy account that they're talking about.
- tobib 6y agoGotcha, thanks.
- NikolaeVarius 6y ago> Authy is fricken awful. It requires SMS for "security" entirely defeating the purpose of 2FA Explain. There is a separate password to defeat traditional SMS attacks.
- mynameisvlad 6y agoI believe it uses it for account recovery if you don't have a device with it installed anymore.
- MayeulC 6y agoI used to use andOTP, mainly because it was possible to export OTP tokens when upgrading or resetting my phone. Then IIRC I heard that andOTP wasn't that secure/maintained. Or maybe that their backup file encryption wasn't that great. I am not sure about these claims, but I migrated to Aegis, that could nicely import AndOTP tokens. Nowadays, I use it in combination with bitwarden (it supports OTP), which I use for my less important accounts. Bitwarden (self-hosted with bitwarden-rs) allows me to generate those without my phone. I still keep every token in Aegis as well. AndOTP features I miss with Aegis: - Icon library for common websites using OTP - Maybe Steam OTP support? I never used it though, since it would more or less lock me out of trading, without the app, so I use e-mail.
- deleted 6y ago[deleted]
- alexbakker 6y agoOne of the authors here. > Icon library for common websites using OTP Someone from the community is maintaining an icon pack for Aegis: https://github.com/aegis-icons/aegis-icons https://github.com/aegis-icons/aegis-icons. We're currently working on making icon packs easier to use in Aegis, see: https://github.com/beemdevelopment/Aegis/issues/509 https://github.com/beemdevelopment/Aegis/issues/509. > Maybe Steam OTP support Steam is supported, actually! But like you said, you'd still need the Steam app if you're doing trading.
- MayeulC 6y agoHey there, thanks for Aegis, it is my main OTP vault for important suff. Thank you and your sibling comment. I'm glad this is being worked on! Discovery is also important IMO, so a one-tap install of the most widely used icon pack would be nice to have too :)
- alexbakker 6y agoThanks for your support! That's a fair point. We'll see what the feedback is like when we release initial support for icons packs and decide whether to include a pack out of the box after that.
- teamspirit 6y agoMy big thing with these apps, Authy, Duo, Google Authenticator is site icons. Authy finally figured out a way to query the website and either get the favicon or some image from the website. I know, it's really the most minuscule part but it frustrates me to see "(D)" for Digital Ocean. But it's enough to keep me with it.
- ignitionmonkey 6y agoIcon packs are coming [1] and you can set your own for the more niche sites. The problem with querying websites for their icon is that it leaks data about you (your phone and desktop) to a third-party without a proxy, requires a domain to match against, and like with Authy, the icons go out of date and become inconsistent. Worst of all, you have to give network access to the entire app for a trivial feature, making it less secure and trustworthy. Offline icon packs that have a consistent look is a good solution to all of this. [2] [1] https://github.com/beemdevelopment/Aegis/issues/509 https://github.com/beemdevelopment/Aegis/issues/509 [2] https://github.com/aegis-icons/aegis-icons https://github.com/aegis-icons/aegis-icons
- enshake 6y agoAuthy now adds the site logo automatically. If not, you can search one up in the app
- Fnoord 6y agoBitwarden has this feature, and it is optional. I wouldn't mind if Aegis has it, as long as it is optional.
- darkteflon 6y agoThis looks great. Is there any chance it will make it to iOS?
- jdright 6y agoCan this import from Google Authenticator?
- alexbakker 6y agoOne of the authors here. Yes! Aegis can scan the QR codes that Google Authenticator presents in the "Transfer accounts" screen. It's also possible to import directly from Google Authenticator's internal database if you have root access.
- jdright 6y agoJust migrated all devices in my home. Without root access, I had to use another phone to take a picture of the QR and then scan with Aegis. This way it had difficulty understanding QR that had more then 4 entries. Anyway, waiting for the icons support, but for now it is another Google app down! Thanks a lot.
- amiga-workbench 6y agoThank you so much for this feature! Google Authenticator has been holding my phone ransom on Android 9. I've got way too many 2fa keys to reconfigure manually and add to a new client. I'm all backed up and installing the latest Lineage OS build now.
- shaicoleman 6y agoI've switched to it recently, it's really great: * Open source * Has search functionality * Has biometric unlock functionality * Has no external dependencies (SMS/remote accounts) * Nice design/UX * Dark mode * Can import from other apps * Just works * Can do an encrypted export * Encrypted export can be read by other apps, see https://github.com/beemdevelopment/Aegis/blob/master/scripts/decrypt.py https://github.com/beemdevelopment/Aegis/blob/master/scripts...
- circularfoyers 6y agoI don't see any reason to use it over andOTP, which has all those features and has been around years before Aegis. It even looks suspiciously similar to andOTP, if not heavily inspired by it.
- shaicoleman 6y ago* Aegis has a nicer design * Aegis has an extensive import functionality, andOTP does not seems to have it * andOTP relocks every time you switch apps, which can be annoying if you need multiple codes when you login to multiple services. In Aegis that behaviour is configurable * andOTP makes you choose between biometric encryption and password, Aegis supports both at the same time * andOTP supports tags, Aegis does not Due to the import functionality, it's easy enough to give it a try, and see if you like it yourself.
- circularfoyers 6y agoThanks for responding. I should have mentioned I've been a user of andOTP for a few years so that's why I brought the comparison up. I wish more projects (including Aegis) mentioned what distinguishes themselves from very similar options. I think the fact that Aegis allows you to import from a number of other authenticators, notably proprietary ones, is an important feature in getting people to move over to an open source equivalent, which is something I respect. One minor correction to what you said though - andOTP doesn't relock every time you switch apps. I tried this just now to verify this.
- gruez 6y agoI've been trying to switch away from a closed source authenticator and this ticks most of the boxes. The only thing it's missing is the ability to quickly filter by group. Currently you have to open app -> 3 dot menu -> filter -> select group (4 steps total), whereas the authenticator I'm currently using allows you to side swipe -> select a group (2 steps), or add a shortcut on homescreen that opens the app with the filter enabled (1 step).
- chessmango 6y agoCan recommend AndOTP in this case, provided using Android. Grab a build off F-Droid - easy tag-hopping with options for single or multiple tag selection. Have very few complaints, and I 2FA anything I can, at work and personally, so tags strictly necessary
- phs 6y agoI love AndOTP. It's boring, it keeps the master key in my head and offers simple backups.
- gruez 6y agoThe main problem with andotp is the excessive amount of padding that they add to each entry, even with the "compact" option. The group/tag selection is better (only two steps), but not nearly as convenient as the app I'm using where you can view a group/tag directly from the home screen.
- alexbakker 6y agoOne of the authors here. We've gotten a lot of similar feedback lately. This is something we plan on addressing in a future release by introducing filter chips, either directly on the main view, or one tap away. Hopefully that'll make it a bit easier to quickly filter based on groups.
- alisausaaaaa 6y agoWanna have hot-lovin' conversations? You’re on the right way! - https://adultlove.life https://adultlove.life
- PascLeRasc 6y agoCheck out Tofu if you're on iOS! Open-source, way nicer UI than Google Auth, and you can back it up to iCloud. https://github.com/calleerlandsson/tofu https://github.com/calleerlandsson/tofu
- dengolius 6y agoI'm using andOTP https://github.com/andOTP/andOTP https://github.com/andOTP/andOTP
- aynawn 6y agoI've been in the market for an open source authenticator that works on android and desktop with a cloud sync. I cannot find one and so I'm stuck on using authy. I have exported all my TOTP tokens in hopes that one might turn up. Aegis, like andOTP and others, does not appear to have a desktop client.
- emmelaich 6y agoCan I throw in a question here? How do I get my accounts imported from the old Google Authenticator into the new one? I'm currently locked out of my AWS account because I made the mistake of adding MFA to my root account at the wrong time. The crazy thing is that AWS have my phone number but due to formatting or similar they can't send me an SMS! IT's possible that they're trying a US number but mine is Australian.
- alisaus 6y agoI was a really bad girl. Punish me with your dick in my mouth. - https://adultlove.life https://adultlove.life
- antpls 6y agoI have no printer at home. Does anyone know how to backup all those QRcodes on paper ?
- alexbakker 6y agoIf you write down the secrets and the other parameters on paper, that would suffice as a backup as well. I'd recommend using Aegis' encrypted backup though.
- scintill76 6y agoBit OT: I’m interested in an open standard for “push” 2FA. Receive a push notification on Google or Apple’s standard platform, or at the least be able to open the app and just tap the account to send second factor auth (maybe when you open the app it queries all accounts to find which is currently waiting for auth). Are there security concerns blocking this?
- dastx 6y agoThere is server-sent events.
- alisaus3 6y agoTop burny busty chicks only on this site! Follow the link, and you won’t be sorry! - https://adultlove.life https://adultlove.life
- nikolay 6y agoNice! I am using 1Password's 2FA, but, basically, it puts both the password and the second factor in one place, which turns 2FA into essentially 1FA!