76 ms·
Aegis v3.0 – a free, secure and open source 2FA app for Android
- opticsreviewer 3y ago[flagged]
- wofo 3y agoAegis should really be more well-known IMO. I installed it on an old phone that didn't have enough storage for Google Authenticator and was really pleased with the app. The fact that it's a community project is also a nice bonus.
- mrd3v0 3y ago> The fact that it's a community project is also a nice bonus. It is more than a bonus. This is the only kind of project you know that tomorrow, the day after or a year from now there wouldn't have profit incentives or a pending IPO to completely abuse your experience as a user and extract as much profit as possible.
- nicoco 3y agoGreat app that does the job! The kind I don't mind installing on my phone. I use it for nextcloud, github and my microsoft account (it was really buried in the settings but it is possible to avoid using MS auth something app).
- SushiHippie 3y agoI really like it that more and more apps start using Material 3/You. Apples UI design was never my cup of tea, but I love the consistency of UI design in most iOS apps, compared to the wild UI inconsistencies on Android.
- mrd3v0 3y agoI'd take a more diverse UI experience on Android any day over a more polished yet heavily opinionated experience at iOS. That being said, I feel like the main complaint about Android apps design is the fact that a lot of apps are just horrible half-assed implementations of old Material UI slapped together on a drag and drop editor like the Android Studio widget system. Offering an incentive for people to build anything and make money off data collection and ads without the corporate tyranny of Apple results in just that. So apps that are on FOSS repositories such as F-Droid are usually much cleaner to use, despite their UI/UX being just as diverse.
- SushiHippie 3y agoAgreed I've never owned an iPhone, so I'm kind of used to the android experience and don't mind that much, but I'm just happy that it gets more and more consistent, at least the apps I use. Though I only use FOSS apps so I can't speak for the playstore apps.
- ParetoOptimal 3y agoAegis is good and I enjoy using it. I hope others don't follow Microsoft Authenticators footsteps in creating their own Authenticator, saying others are insecure, and not allowing Authenticators like Aegis.
- noman-land 3y agoAegis is really great. So nice not to use proprietary authenticators. And it can do import and export. Does anyone know the history of this project? It seems legit but an authenticator is a pretty sensitive application so making sure this app is trustworthy is a little more important than for other apps.
- kristjank 3y agoI used it until I switched to KeePassXC for all of my secret management means, but it's still a great app to fall back to, and allows for simple information exchange when moving to another app.
- RandomGuy456 3y agoHi! I use both plus Syncthing to automatically backup my vault to the pc. Great combo!
- sebastiennight 3y agoLast year Google Authenticator started syncing secrets to the cloud[0] which means that those secrets can now be accessed in new ways outside of the user's control[1], which resulted in a huge breach at a startup called Retool[2]. From then on I started moving my company's team and contractors (as well as family and friends) off of Google Auth and onto Aegis. The app is clean, easy to use, open source, has all the options we could dream off. (and its privacy policy isn't tens-of-pages-long like some other apps, where privacy seemed to be part of the marketing strategy but not the product itself) I've been a very happy user. [0]: https://news.ycombinator.com/item?id=35690398 https://news.ycombinator.com/item?id=35690398 [1]: https://news.ycombinator.com/item?id=35708869 https://news.ycombinator.com/item?id=35708869 [2]: https://news.ycombinator.com/item?id=37500895 https://news.ycombinator.com/item?id=37500895
- warkdarrior 3y agoSyncing to the cloud is an opt-in setting in Google Auth.
- cmiles74 3y agoIt was not in my case. I found out about this feature when I saw the green cloud icon and pressed it to find out what it meant. At that time I was made aware the my data was saved in my Google account.
- sangnoir 3y agoIt's likely your company's administrator forced this default behavior. Cloud sync was an opt-in on my account too, fwiw. It would have been a huge story had it been opt-out.
- cmiles74 3y agoTLDR: From what I can tell, the "consent" to cloud backup from Google Authenticator was misleading at best and blocked access to the tool until it was given. IMHO this is another example of Google forcing decisions on customers in order to extract even more data. Thumbs down! It looks like Google didn't make clear what was happening... There are almost no settings in Authenticator and there is no place to turn "cloud backup" on or off. I found this article that described the feature when it rolled out. https://www.bleepingcomputer.com/news/google/google-authenticator-now-backs-up-your-2fa-codes-to-the-cloud/ https://www.bleepingcomputer.com/news/google/google-authenti... If the screenshot is accurate, they blocked access to the tool until "consent" was given to backup codes to Google. The text itself is clear in retrospect but, in my opinion, implies that there will be a choice to backup to Google and that choice was never presented. "Google Authenticator is Upgrading... You can now sign into your Google Account and backup your Google Authenticator codes to the cloud." A button is presented labeled "Get Started" and, if you click it, Authenticator will backup all of your codes to the cloud. I don't remember being presented with this screen but I don't remember a lot of things. I suspect I needed to get a code and simply clicked the button to get to the list of codes. If I read it, I likely thought there was a new setting and I could manage this "backing up" from there. Clearly this was not the case and I "consented" to let Google have all of by 2FA codes.
- nzeid 3y agoI happened upon this app recently when I was frantically searching for a Google replacement. Couldn't believe something this polished was lurking. I used another open source app several years ago but it got discontinued (FreeTOTP or something).
- yoavm 3y agoI love Aegis but I can't help but think that it's sad we ended up in this place with regards to 2FA. When all these temporary codes started they were sent over SMS, which was insecure but at least all I needed to do was to pick up my phone. Nowadays I open Aegis and I have > 20 services there, and trying to look for my code between all the running numbers is a pain. It would have been so much more comfortable if we flipped this around a little - the website would present a QR code, you would open the phone and scan the code, the phone would make a request signed with your key to a URL, and the website would authenticate you because by making this signed request you proved that "something you have" part is done. It feels like when the 2FA thing started no one considered that sooner or later all services will require it, and the UX will be terrible.
- fcsp 3y agoThat's pretty close to webauthn, which works very nicely with yubikeys if the service supports it. 2fa? Please tap yubi button - done.
- khimaros 3y agoyou might enjoy Bitwarden (self hosted with vaultwarden) which copies the TOTP to clipboard after logging in to a site.
- yoavm 3y agoI'm using Bitwarden, for passwords, but I always felt uncomfortable with the idea of having my 2FA on my laptop too. It feels a little silly - if Bitwarden has both my password and my 2FA code, it's enough to hack my Bitwarden and all this "multi-factor authentication" isn't very "multi" anymore...
- sunaookami 3y agoYou shouldn't lose any security when your vault itself is protected with 2FA.
- 3y ago
- TrailMixRaisin 3y agoI use this app and are very happy. For me the selling point was the possibility to backup my profile and therefore all the configured keys.
- sunng 3y agoI have being using andOTP for years but the development seems to halt, also it's no longer available from f-droid. The feature that backup with gpg encryption is broken. I hope it's possible to import my otps from andotp into aegis. Also the backup encryption with gpg (openkeychain) is welcomed.
- CorrectHorseBat 3y agoYes it's possible to import from andOTP
- MRPockets 3y agoI have been a happy long-time user of andOTP since migrating to it from FreeOTP (iirc) and was unaware that it was no longer maintained. Some quick digging shows that the Github repo links to this XDA post[0] where the author announced he was ceasing development. :( The good news is that migrating to Aegis is quite simple. Export from andOTP, in Aegis go to Settings -> Import & Export -> Import from File, & choose andOTP. Pick your file and away you go. It doesn't seem to have a database of icons like andOTP does though; none of my imported items show an icon though several did in andOTP. (Could this be because of the method they were added?) [0] https://xdaforums.com/t/unmaintained-app-4-4-open-source-andotp-open-source-two-factor-authentication-for-android.3636993/page-6#post-87021655 https://xdaforums.com/t/unmaintained-app-4-4-open-source-and...
- Caligatio 3y agoOld andOTP user turned new-ish Aegis user here: it's super easy to migrate and Aegis just feels like a better product.
- jrm4 3y agoSince we're here: Anyone else dealing with the stupid thing where your organization won't let you have your generating token thing and instead force you into e.g. Duo? I have only one, and its frustrating. I know it's probably breakable with rooted Android or something but haven't had much time to look into it (or fight it)
- explosion-s 3y agoDuo lets you use a physical security key, I then use bitwarden to store that as a passkey. Not quite a full replacement but good enough for me (you can also self host bitwarden [0]) [0] Vaultwarden
- lxgr 3y agoTOTPs are inherently less secure than many of these proprietary solutions (they don't offer control over where people store them and whether they create backups of them, for one thing), so I do somewhat understand companies preferring those.
- jrm4 3y agoI agree that "TOTP with user held keys offer relatively more control to the user than to the organization," but I would never call this "inherently less secure." Just a different kind of insecure.
- genpfault 3y agoAegis will happily slurp the secrets out from Duo on a rooted device.
- devsda 3y agoSome organizations disable totp entirely. Instead, everytime there's a login attempt a pop-up notification with "allow" & "deny" options is pushed to the registered device.
- panick21_ 3y agoI use one that has to be activated with the Yubikey over NFC. Pretty slick.
- freedomben 3y agoI adore Aegis, and view it as one of the most important apps on my phone. If you use Aegis on Android and use a Gnome-based Linux distro, I highly recommend complementing with Gnome Authenticator[1][2][3][4]. flatpak install flathub com.belmoussaoui.Authenticator Gnome Authenticator is still a little early and buggy (mainly performance issues when you have lots of tokens), but it can import and export Aegis format (and a few others). It's been downright luxurious having my seeds on my phone and my laptop and desktop. [1] https://gitlab.gnome.org/World/Authenticator https://gitlab.gnome.org/World/Authenticator [2] https://flathub.org/apps/com.belmoussaoui.Authenticator https://flathub.org/apps/com.belmoussaoui.Authenticator [3] I think (I hope) that Gnome Authenticator will be distributed as part of Gnome at some point in the future, but it isn't yet [4] It's also super easy to build and run from source using Gnome Builder[5]. Just open Builder and clone the source from gitlab, and click the "Build" button and it will do its thing [5] https://wiki.gnome.org/Newcomers/BuildProject https://wiki.gnome.org/Newcomers/BuildProject
- lxgr 3y ago> It's been downright luxurious having my seeds on my phone and my laptop and desktop. The same is possible for my iOS tool of choice (called "OTP auth"). It can also synchronize to iCloud (passphrase encrypted) and make use of that on macOS. I've resisted the temptation of that comfort so far (and of just putting the TOTP seeds into Bitwarden or 1Password), because it does seem a lot like collapsing what's now definitely two or maybe three factors into two or sometimes only one.
- freedomben 3y agoIndeed, I went through a very similar philosophical dilemma as well. I eventually decided that the convenience outweighed the security reduction, in part because the security reduction feels fairly minimal as they still live only on local devices and not on a device accessible to anyone besides me. I still can't bring myself to put them into bitwarden, though. I suspect that will be a line I refuse to cross for quite some time, even though the convenience and luxury of doing so is tempting. Having my seeds in the cloud to me definitely reduces a factor
- 3y ago
- Narushia 3y agoI'm currently a happy user of 2FAS[1], any idea how Aegis compares to it? A quick search suggests that Aegis doesn't support multiple devices and is not available on desktop. [1]: https://2fas.com/ https://2fas.com/
- brandensilva 3y agoLet's hope they add a desktop app. I'm on that screen more than my phone. I'm not one to care about having my phone on me all the time.
- lern_too_spel 3y agoJust use Bitwarden. The UI is clunkier, but the UX is better. After it fills in the username and password, it puts the OTP in the clipboard, so you can just paste and go without opening an app and manually copying it into the login form.
- tremarley 3y agoUsing a password manager as your authenticator seems very risky to me. You should use separate services. If your password manager is breached, at least the infiltrator cannot pass 2FA.
- lern_too_spel 3y agoIt is no different from Passkeys in that regard, yet we're fine with that. If you want extra security, you would have your password manager and your OTP generator on different devices, but only a small fraction of people do that. Storing your OTP generator secrets and your passwords in the same app provides a reasonable trade-off between security and convenience for most people.
- patrakov 3y agoLet me add: for services like GitHub that never log you out, 2FA is pure security theater. The only factor in this case is a browser cookie.
- belthesar 3y agoI'm hard opposed to storing my second factor codes alongside my first factors. Part of the reason why I use 2FA is because if my password store is compromised, the accounts in it that are compromised do not contain all of the credentials necessary to log into the accounts protected by 2FA. I also do not store my emergency removal codes in the same secret store as my passwords for this reason.
- tremarley 3y agoAre there any good 2FA applications for Desktop? Using the phone to authenticate every login seems very inefficient. Some of us do not like using the phone.
- mhitza 3y agoI use Bitwarden for passwords and 2FA (browser plugin, Android app for mobile). Definitely not recommended by anyone security focused, but these 2fa are forced onto me by different platforms and not something I chose/care. There should be desktop authenticator software. If I can have one on Linux I'm sure all the other desktop OSs have at least 1.
- Zizizizz 3y agohttps://github.com/tadfisher/pass-otp https://github.com/tadfisher/pass-otp
- jonotime 3y agoI use keepass on phone and desktop
- alisonatwork 3y agoI use KeePass. It's a little bit cryptic to set up the OTP - you have to create an advanced field called TimeOtp-Secret-Base32 with the seed in it - but after that you just Ctrl-T to get the latest code.
- usr1106 3y agoI use my own 15 lines of Python code calling pyotp. At least for desktop means preferably CLI.
- patrakov 3y agoI would say that the "generic desktop app" approach is to be avoided. The reason is that there is a strictly better alternative that targets almost the same audience. By implementing a TOTP generator as a desktop browser extension instead, one gets visibility into which site the user visits, and can show only the relevant code, or, if there is none, a phishing warning. The users that are left behind in the browser extension approach are those who need TOTP for non-web things like SSH. Happy user of https://authenticator.cc/ https://authenticator.cc/
- occam65 3y agoI've been using Aegis for a number of years, and have found nothing I don't like about it. It's a perfectly functional app, and I'm looking forward to trying out the new update!
- bonki 3y agoI totally agree, it's probably the only app I ever used that I would consider flawless.
- Semaphor 3y agoIt’s why I was a bit scared when reading the title (though the screenshot makes it look like I’ll be fine), I’ve had two open source apps make their UI/UX vastly worse recently with major updates (granted, I’m assuming some people like the changes), one was Gajim (XMPP messenger) on Desktop, and another Breathly (guided breathing) on mobile.
- korm 3y agoHere's a utility to convert exported Aegis JSON to a Keepass 2 or KeepassXC database if anyone's interested https://github.com/GeKorm/atk https://github.com/GeKorm/atk (binaries in the releases page)
- jonotime 3y agoThis looks very nice. Had I not just moved all my 2FA to keepass, I would give it a go. My setup: mac desktop, linux desktops, android with syncthing to tie it all together.
- cosmojg 3y agoBitwarden and KeePassXC also provide free, secure, and open-source 2FA in addition to password management. I keep my TOTP secret keys separate from my passwords simply by storing them in separate vaults. I don't know why anyone would use anything else (although I'd love for someone to comment and tell me).
- Xaiph_Rahci 3y agoBecause doing this reduces the 2FA into 1FA (i.e. there is no longer a possession factor).
- 911e 3y agoThe goal is to protect your data from brute force not from yourself, it’s perfectly reasonable to have 2fa in your password manager, saying it’s 1fa is just fud
- aryonoco 3y agoIt's not fud. 2FA traditionally means relying on one thing you know (i.e. a password) plus one thing you have, or one thing you are (biometrics). Every single one of my passwords is unique and randomly generated and at least 32 characters, none of them are getting brute forced unless there is a sudden gigantic leap in quantum computing. And if that happens, the world has bigger problems than my passwords. Having a separate identity factor, something that I own, is not to save me from myself. It's to save me if someone steals my phone or laptop and is able to get into it. Now we all face different threat models and if your threat model doesn't call for having a totally separate identity factor, great! There's nothing wrong with that. But we don't all face your threat model, and some of us do indeed need a second identity factor that's not stored in the same place as the password.
- MrDrMcCoy 3y ago> Having a separate identity factor, something that I own, is not to save me from myself. It's to save me if someone steals my phone or laptop and is able to get into it. What if that second factor is physical and stolen along with the things it was supposed to protect? What if your biometrics are cloned in some way? Having TOTP synchronized across devices, but protected by passwords mitigates those risks as well as the risk that you lock yourself out by loss of a physical token.
- rkagerer 3y agoWhat's the backup story like? Can you do an encrypted backup on demand (protected with a password you supply)? Is there any desktop app such backup can be opened/read with (or even eg. read with something like sqlite db browser)? Can the app be configured to save an encrypted copy to eg. Dropbox whenever changes are made? Is it recommended to install from Play store, or the APK off GitHub?
- logicprog 3y agoI use Aegis as my main app for 2FA so I can answer these questions: > Can you do an encrypted backup on demand (protected with a password you supply)? Yes! > Is there any desktop app such backup can be opened/read with (or even eg. read with something like sqlite db browser)? It's just plain JSON once decrypted, so it's always readable; I do know the GNOME Circle app "Authenticator" can natively import Aegis backups as well, since it's what I use on my desktop machine, but I don't know what other apps exist. > Can the app be configured to save an encrypted copy to eg. Dropbox whenever changes are made? It does have some facilities for automatic and cloud backups judging from the settings page, but I've never tried them > Is it recommended to install from Play store, or the APK off GitHub? If you do the latter you'd lose automatic updates. I used F-Droid.
- greenmartian 3y ago>If you do the latter you'd lose automatic updates. Obtainium[1] will give you automatic updates from most sources, including Github/Gitlab/Codeberg and F-Droid repos. Especially relevant to this discussion, since Aegis 3.0 hasn't hit F-Droid yet, as at the writing of this comment. [1] https://github.com/ImranR98/Obtainium https://github.com/ImranR98/Obtainium
- nogajun 3y agoFreeOTP, supported by Redhat, is another open source 2FA application. I use it. FreeOTP: https://freeotp.github.io/ https://freeotp.github.io/
- fidelramos 3y agoSame here. I haven't compared it in depth with Aegis, but besides some UI quirks I'm happy with FreeOTP. Am I missing anything important?
- borplk 3y agoDoes it support folders for separating entries? I like to separate work from personal entries.
- microflash 3y agoIt supports Groups to organize entries.
- e12e 3y agoThose interested in this, might also be interested in Ente auth: https://github.com/ente-io/ente/tree/main/auth https://github.com/ente-io/ente/tree/main/auth
- Fervicus 3y agoHappy Ente user on ios.
- Zuiii 3y agoTruly open-source, available on f-droid, works on everything including low-end android hardware with everything except microsoft (because microsoft). What's not to like.
- KTibow 3y agoWhile we're talking about places to use 2FA, if you have a watch it might be a good idea to put your 2FA codes there for redundancy.
- Timber-6539 3y agoLong ago, I used Google Authenticator to store 2FA tokens without giving it much thought. When I lost the app data to a phone reset, I also lost my 2FA tokens. Got lucky I didn't have many tokens saved at the time and was able to restore all the important accounts despite losing the tokens. Even though it was my fault for not reading the T&C of the Google Authenticator app, I cursed Google for creating an inferior product on an OS they controlled. What was the use of requiring login with a Google account on the Android device if you are not going to persist this kind of data. Then I moved to Authy which syncs and stores your tokens online to their cloud, allaying all the fears I had from previous experience. Incidentally another phone reset happened. Now Authy allows you to access your tokens "locally" to any device that can install their app or browser extension. Using more than one "device" locally gives you data redundancy. I cannot just trust a browser extension with my 2FA tokens (yikes), so at the time I only had my Android device with the tokens locally. When this "trusted device" (read app data) was lost I had to request support for a reset to gain back my data from Authy. That process takes 48 hours after initiating the reset. (The app data counts as a device, not the other way around; this is the crux of my problem with 2FA application design.) As soon as I got my tokens back I moved to Aegis and never looked back. I can export backups, save them encrypted on any location and import them anytime without fear of losing app data aka device.
- abhinavk 3y agoWhat do you guys prefer to use on iOS?
- halJordan 3y agoRaivo is a source-available ios app. It has exports, icloud sync and can generate a new QR code. Keychain is also not bad.
- microflash 3y agoRaivo was acquired by Mobime[1] and since then the status of project has been up in the air and so is its privacy policy. [1]: https://twitter.com/RaivoOTP/status/1683372954002808833 https://twitter.com/RaivoOTP/status/1683372954002808833
- alibert 3y agoI use OTP Auth, it doesn’t get updated much but still maintained. I consider it « feature complete ». https://apps.apple.com/fr/app/otp-auth/id659877384 https://apps.apple.com/fr/app/otp-auth/id659877384
- Ringz 3y agoOTP Auth. In use for years. Backups, iCloud Sync, Widgets, Folders. Perfekt.
- billforsternz 3y agoI'm a veteran developer, but really more of a "normal" than the type of developer who is commenting on this story. I admit I find this stuff really, really, really confusing. I hate dealing with any of this stuff, I don't do it voluntarily for the same reasons I don't (for example) use pretty good privacy for email (I just use web gmail like a regular person). Anyway, I do (involuntarily) use 2FA for two services, and managed to set myself up with Google Authenticator on my Android phone. Both services that onboarded me for this explained it really poorly, but at least got me hooked up and I now routinely (and reluctantly) login to those services this way. Reading this I suddenly realised, whoaaa, if I lose my phone do I lose access to those (important) services? Well no, I hope not at least, when I look at the Authenticator app it has the green "your codes are being saved to your google account" cloud icon. That's kind of reassuring. I suppose. I'm not really sure what my point is, other than online security is an ever more important issue, it's a swamp and even many technical people who might know everything there is to know about some arcane corner of the technology universe don't necessarily properly understand it. Although I suspect most would not be prepared to admit it like I just did. Actual normal people (like my wife for example) have absolutely no chance of getting on top of the details and navigating their way to a best practice solution. I hope Google (or Apple) don't either give up on this or go full evil, that would be really bad. I think I will check out whether my two services can give me recovery codes. I am confident I can manage vital username/password combinations and recovery codes, that's the level of sophistication (or not) I'm comfortable with in this space.
- GoblinSlayer 3y agoBut can you access your google account if you lose your phone? That account belongs to google, not to you.
- qingcharles 3y agoI lost access to mine. I have the username, password and recovery email, but it won't let me in because I lost my phone.
- billforsternz 3y ago
- jpeeler 3y agoEtrade (probably some other companies?) uses Symantec VIP, which is a proprietary TOTP client. I was really glad to have found a project that allows me top stop using it and instead utilize other standard TOTP clients. https://github.com/dlenski/python-vipaccess https://github.com/dlenski/python-vipaccess https://gist.github.com/jarbro/ca7c9d3eebba1396d53b4a7228575948 https://gist.github.com/jarbro/ca7c9d3eebba1396d53b4a7228575...
- OJFord 3y agoApparently I missed the memo, still using Authy while everyone's moved to Aegis? Any particular reason/benefit(/con or breach of Authy), other than being FOSS (which I do see as a benefit)?
- Belphemur 3y agoNot linked to your phone number. It does encrypted backup that can be synced with Google Android backup (if you want). Support Steam authenticator (if you follow the guide how to get the key). You can group the MFA provider in groups that make sense to you. You're in full control and the keys never leave your device unless you want to. You can see the keys whenever you decide. And the list goes on. I've been using it for years and it's the best MFA app on the market.
- PurpleRamen 3y agoAuthy has no official backup-solution, it's vendor lockin. They discontinued their desktop-app last week, are owned by a company, and so you never know when they might charge money or discontinue the app as a whole. There are unofficial solutions for backup, but who knows when those will stop working.
- noman-land 3y agoFOSS, import/export.
- ShoneRL 3y agoCan we just get a 2FA app that's cross-platform and synchronized? I understand the security implications of that but I don't care, I would rather have my social media hacked and have it convenient than just have to go grab my phone whenever I want to login into something. Authy is discontinuing their desktop app...
- stranded_hippo 3y agoOn F-Droid there is still version 2.2.2 (last updated 6 month ago). If I try to install the app from Github releases I get a version conflict with my current version from F-Droid. Any tips?