5 ms·
> I started moving my company's team and contractors (as well as family and friends) ... onto Aegis An important question on this, if you don't mind: If the p
by Elbrus 3y ago
> I started moving my company's team and contractors (as well as family and friends) ... onto Aegis
An important question on this, if you don't mind:
If the phone, where Aegis was installed, is dead/lost/stolen, which options are available to make sure that access to the accounts linked to that phone wouldn't be lost either?
- deleted 3y ago[deleted]
- microflash 3y agoYou can optionally backup your encrypted data using Android's built-in backup utility tied to your Google account. It can, then, automatically restore codes when you sign in on a new device.
- lxgr 3y agoDoes that back up TOTP seeds in Google Authenticator? I thought apps had to opt in to this type of backup and would assume that Authenticator doesn't, but Google has changed the Android backup mechanism so many times, I lost track.
- microflash 3y agoIt backs up TOTP seeds. You need to enable this manually. As a part of Android Device backup, Google does backup certain things automatically[1] but non-Google apps require explicit opt-in. [1]: https://support.google.com/googleone/answer/9149304?hl=en&co=GENIE.Platform%3DAndroid https://support.google.com/googleone/answer/9149304?hl=en&co...
- lxgr 3y agoInteresting, thank you! I would have expected Google Authenticator to somehow tangle the encryption keys used to the device it’s running on, but apparently it doesn’t if this works.
- bonki 3y agoIt has android cloud as well as automatic local backups. I do automatic local backups and use Syncthing to sync them off my phone. Works a charm!
- thombles 3y agoEvery service I've used with TOTP codes (12 at current count) has given me some sort of randomised backup token at the same time to use if I lose my 2FA app. I store those somewhere separate. I'm not going to argue that this is user-friendly but AFAIK there's no reason you're obliged to use cloud backups today.
- lxgr 3y agoThis is actually a pattern I really don't like: Why do I mostly get these thrown at me for TOTP, but not other 2FA methods? What am I supposed to do with these "backup codes"? Store them all in my password manager? At that point, I might as well store the TOTP seed there and rely on its multifactor authentication – which is probably fair for many use cases, but suffers from the problem outlined by GP. I think sites should treat TOTPs effectively equivalent to Passkeys, i.e. as maybe synced, maybe backed up, but maybe neither – and then the user needs an alternative login method, just like for all 2FA methods.
- brewdad 3y agoPersonally, I use Bitwarden for passwords and store my 2FA seeds in a Keepass database on my PC and backed up to my cloud. It isn't perfect by any means but at least if my Bitwarden gets compromised, my 2FA tokens are safe and vice versa. If I lose control of both, welp, it's gonna be a bad time I guess.
- sowbug 3y agoChoosing 2FA segregates users into two buckets. Most people are satisfied with the risk of allowing password reset emails and social engineering attacks. They don't pick 2FA. The rest are generally more sophisticated users, and are willing to risk loss of the entire account if they lose their credentials. That's the price for an overall increase in account security. From this perspective, it makes sense to provide backup codes as another tool in the DIY account-management toolbox. These buckets oversimplify the situation, but they help explain why backup codes are offered as last-ditch authentication for 2FA.
- ploxiln 3y ago
- Zuiii 3y agoAegis can export an encrypted backup file that can be imported on another phone.
- vraylle 3y agoIt can put encrypted backups on almost any cloud service, pCloud in my case.
- notabee 3y agoYou can copy an encrypted backup file to a usb drive and then either copy that to a few other secure places or just put it in a safe depending on how much redundancy you need. I use Aegis these days as a backup MFA option for a yubikey. You can password protect access to open Aegis with its own unique password which I like (no cloud dependency or access), but it's kind of inconvenient if you have a decently sized password so I prefer it as the backup option if the yubikey goes missing.