10 ms·
One really good TOTP app for desktops is Authy [0] from Twilio. Some people are not aware that it exists and you don't need an app on your phone for TOTP. Authy
by codegeek 5y ago
One really good TOTP app for desktops is Authy [0] from Twilio. Some people are not aware that it exists and you don't need an app on your phone for TOTP. Authy works from your desktop as well.
[0] https://authy.com/download/ https://authy.com/download/ (scroll down to see Desktop version for download)
- robertlagrant 5y agoInteresting! I didn't know that. Pretty handy for corporate stuff - keep the 2FA on the work computer.
- banana_giraffe 5y agoOn the topic of TOTP apps, I like "OTP Auth" for iOS devices. It's fairly simple, and offers an Apple Watch client that works well.
- jcims 5y agoYou can also roll your own with https://github.com/pyauth/pyotp https://github.com/pyauth/pyotp
- codetrotter 5y ago> roll your own Libraries for a couple of other languages: https://crates.io/search?q=4226 https://crates.io/search?q=4226 https://pkg.go.dev/search?q=4226 https://pkg.go.dev/search?q=4226
- tyingq 5y agoIt's almost overkill to bother with a library. #!/usr/bin/env python3 import time, hmac, base64, struct def totp(seed,curtime,period,len): k = base64.b32decode(seed) mac = hmac.new(k, struct.pack('>Q', int(curtime/period)), 'sha1').digest() offset=mac[-1] & 0x0f otp=struct.unpack('>L', mac[offset:offset+4])[0] & 0x7fffffff return str(otp)[-len:].zfill(len) myseed='KRUGS4ZANFZSAYJAOJQW4ZDPNUQHG5DS' # use gpg or similar to store print(totp(myseed,time.time(),60,6))
- jjnoakes 5y agoTrue, I also type this in from memory whenever I need a quick TOTP calculation.
- foxtacles 5y agoI can recommend oathtool (in combination with GPG) on the CLI: https://www.nongnu.org/oath-toolkit/oathtool.1.html https://www.nongnu.org/oath-toolkit/oathtool.1.html
- commoner 5y agoHard no from me. I remember when Authy refused to delete my account, prior to their acquisition, despite promising to do so upon request in their terms of service. I wasn't the only one: https://news.ycombinator.com/item?id=9100525 https://news.ycombinator.com/item?id=9100525 There are plenty of free and open source TOTP authenticators (that don't require you to provide your phone number), and I don't see a good reason to use Authy over them.
- ncann 5y agoWhat about this link? Seems pretty straightforward to delete an account for me: https://authy.com/account/delete/ https://authy.com/account/delete/
- commoner 5y agoGood to see that they added an account deletion page some time between their acquisition and now. However, that bridge has already been burned for me and I'll be sticking with Bitwarden (self-hosted using Vaultwarden) for TOTP. Bitwarden doesn't require my phone number.
- thaumasiotes 5y agoWhat's the concept behind having an Authy account? It converts a TOTP seed into a time-based TOTP code. No part of that suggests that you'd need an account.
- SturgeonsLaw 5y agoIt means getting access to your 2FA codes on a new device is as straightforward as installing the app and signing in. Other commenters have mentioned authenticator apps that let you transfer the codes by initiating a backup or generating a QR code, but that won't work if the previous device is at the bottom of a lake.
- thaumasiotes 5y ago> authenticator apps that let you transfer the codes by initiating a backup or generating a QR code, but that won't work if the previous device is at the bottom of a lake. You've got a strange definition of "backup" if you think it won't work after the subject of the backup has been destroyed. What would be the point of a backup that stopped working whenever you needed it?
- sebazzz 5y agoFor those with a Yubikey, those people can use Yubikey Authenticator on both mobile and desktop.
- philjohn 5y ago+1 to this. Yes, it's a bit of a pain to setup with multiple keys, but your secret is stored within the Yubikey itself which is far more secure.
- tzs 5y agoAuthy also works on Apple Watch. I've found it very difficult to get Siri to understand "open Authy". It usually ends up saying there is no app name "oathy". Spelling it out usually works: "open A U T H Y".
- thaumasiotes 5y agoDo you pronounce "authy" and "oathy" the same way? I'd expect "authy" to use whatever vowel you use for "caught", not the vowel of "au revoir".
- tzs 5y agoI've tried a variety of pronunciations. Trying for "au" as in "caught" got me "healthy" and once it opened PCalc(?!). Pronouncing "au" like the "ou" in "ouch" seems to be about the best, but then it tends to mess up the other end, thinking I want "authi". Sometimes it even think "alfie". Somehow it even occasionally hears "elsewise" or "offline". I have no idea how it gets those.
- conductor 5y agoAlso, KeePassXC[0] (a password manager) has integrated TOTP, which is very handy. [0] https://keepassxc.org/ https://keepassxc.org/
- sureglymop 5y agoWow really? I never knew that, I've been using andOTP.
- remuskaos 5y agoThere is also Aegis[1]. It's FOSS and available in F Droid and Play Store. Authy is pretty good, but doesn't support export of the secrets used for TOTP, whereas Aegis supports export to json and GPG encrypted json. I've been using Authy for a few years, but switched to Aegis about three years ago and couldn't be happier. Since Authy doesn't support direct export of the secrets, I've had to use a workaround [2]. [1] https://getaegis.app/ https://getaegis.app/ [2] https://gist.github.com/JacobJohansen/5f688d45049be440b8ee87cc5e854b75 https://gist.github.com/JacobJohansen/5f688d45049be440b8ee87...
- saganus 5y agoI was interested in using Aegis, but unfortunately I can't import my current keys from Google Authenticator. It's "supported" but only via accesing the Authenticator's files (or by havitng root access) which in my celphone is not possible (OnePlus Nord). Weirdly enough, Aegis does not support bulk importing keys from a QR code, which is how you can migrate from one Authenticator instance to another (e.g. to a new phone). And I am too lazy to go over each key, reset it and load it up again in Aegis. Hooefully they'll add this feature at some point in the future.
- nichos 5y agointeresting, i migrated from authenticator, but did it 1 at a time. Check out andOTP, another great open source alternative, maybe it has these features.
- lolinder 5y agohttps://github.com/beemdevelopment/Aegis/issues/701 https://github.com/beemdevelopment/Aegis/issues/701 Aegis does support importing from Google authenticator, it just doesn't make that very clear. You do it the same way you add any other code. The hard part for me was getting the QR code into scannable form. This issue explains one way, but you can also just take a picture of the phone with another device.
- _Anima_ 5y agoI deleted my Authy account after the acquisition. The deletion process was a bit of a struggle for reasons I don't recall clearly. I now use Aegis on phone and the otp plugin of pass on my Linux desktops (+ a ulauncher plugin).
- toastal 5y agoThere's also an TOTP pass extension. https://github.com/tadfisher/pass-otp https://github.com/tadfisher/pass-otp Like others have mentioned, it unlike Authy this doesn't use your phone number as identity
- timwis 5y agoNote that authy’s login (twilio login) uses sms-based 2fa itself, which is very vulnerable to sim-swap attacks. There is no way to disable sms 2fa on it. To counter this I recommend disabling device sync in Authy, and only enabling it temporarily when you add a new device.
- fetzu 5y agoFor iOS users, I can really recommend Raivo OTP[0] a FOSS app that offers everything Authy does (backups included) with easy ways to migrate in- and out- of the app through an encrypted ZIP export of all your TOTP keys. [0] https://github.com/raivo-otp/ios-application https://github.com/raivo-otp/ios-application
- AnonC 5y agoThe mandatory requirement of a phone number to even set this up (with SMS as the verification method) doesn’t suit me. I use other TOTP apps that don’t ask for a phone number or email address or anything else.
- jamra 5y agoAuthy once deleted local credentials during an app update. I had to restore with my backup keys.. only I lost my backup keys so I had to go the long way to circumvent my 2fa. They didn’t seem very sorry about it either.