4 ms·
I've used Google Authenticator, Authy, and 1Password. 1Password has been far superior in my experience, the only downside being that it is a paid subscription,
by devoutsalsa 4y ago
I've used Google Authenticator, Authy, and 1Password. 1Password has been far superior in my experience, the only downside being that it is a paid subscription, which won't work for everyone. My 2nd choice would be Authy.
Entertaining related story... a few months ago, I tried signing up for Celsius, the crypto exchange that went bankrupt. Their sign up process required MFA, and for some reason the only app they supported was Authy. Unlike most any other site, instead of giving you a QR Code to scan, Celsius would do something weird where they have some sort of push message mechanism that's supposed to initiate the MFA setup process from within the Authy app. I never did get it to work. I have a personal rule that if the signup/signin process for a service is too arduous, I simply won't use that service if I have viable alternatives. So I didn't lose any crypto in the Celsius bankruptcy because their MFA signup processes sucked.
- _joel 4y agoI have 1password too but that seemed a little incestuous to have the password and the TOTP in the same app, it's not exactly MFA. I use Authy, personally, with backups and encryption.
- jibe 4y agoI have the same 1Password / Authy setup, for the same reason. But I have my Authy password in 1Password, so it is kind of an illusion of extra security. I’m strongly considering moving it all into 1Password at this point.
- _joel 4y agoThankfully I can just about remember 2 passwords :) Also you can use biometrics in Authy, fwiw. Then write down the password and put it in a safe. Then there's only 1 to remember but you can use biometrics in 1password too, so unless your threat model includes someone using your freshly chopped thumb then it should be ok.