13 ms·
Ente Auth: open-source Authy alternative for 2FA
- skinkestek 2y agoIsn't this the thing that fell victim to a hostile takeover a few weeks ago? Or am I just confused?
- lukevp 2y agoAuthy has been having security incidents. This is an OSS competitor to Authy (Twilio).
- andrei-akopian 2y agoI have heard only prise recently... If you find the source or news article please share!
- cendyne 2y agoYou may be thinking of Rovio https://blog.paranoidpenguin.net/2024/05/raivo-otp-breaks-users-one-time-passwords/ https://blog.paranoidpenguin.net/2024/05/raivo-otp-breaks-us...
- xrd 2y agoI'm worried that if my device fails I won't be able to recover all the sites I've registered on my phone. Does anyone know if this can enable backup quickly to another device in a secure way?
- DavideNL 2y agoYea, i was hoping for iCloud / Apple Watch support..but unfortunately: https://github.com/ente-io/ente/issues/182 https://github.com/ente-io/ente/issues/182
- evulhotdog 2y agoSo basically there’s no reason to use this over something with a bit more trust, like Bitwarden’s 2FA app.
- DavideNL 2y agoWell, a downside of Bitwarden (and 1Password) might be that it's hosted on their own servers. So, no separation between the App Developer/software, and the location where your data is stored.
- memset 2y agoI think it has its own backup service. But it otherwise lets you export/import your data. I feel like as long as I can do an export in some way then that’s good enough for me.
- andrei-akopian 2y agoYou don't need regular backups, just every time you add a new service. Ente has free backups and it's own encrypted export format, which sounds promissing.
- SparkyMcUnicorn 2y ago1Password, Bitwarden, and Vaultwarden support 2fa and let you view/export the secrets.
- r0ckarong 2y agoI'm very happy with Aegis.
- NelsonMinar 2y agoAegis is great but it's Android only. I really like their thoughtful export system. Ente has export as well, I wonder how it compares.
- andrei-akopian 2y agoEnte has built in backups and encrypted export options. Export should be better than Aegis
- freedomben 2y ago> Aegis is great but it's Android only. Yes true, but the Aegis format is supported on Linux by Gnome Authenticator: https://apps.gnome.org/en/Authenticator/ https://apps.gnome.org/en/Authenticator/
- okkdev 2y agoMe too, but it had this nasty bug where me and a bunch of other users occasionally only saw a black screen after unlocking. For me rebooting my phone fixed it, but not for everyone. I can't really afford to not be able to access my 2fa codes. This lasted for over a month, so I decided to move to ente auth.
- neop1x 2y agoI have been using Aegis but switched to Ente Auth as I decided to use Ente Photos as well. Both Aegis and Ente Auth are great options. This switch (export and import) was very easy.
- neoecos 2y agoThis looks good, as I wanted to "escape" the Authy jail (you cannot easly move out with your secrets), but moving a lot of 2fa's to a "new thing". How to make sure they are a good project?
- andrei-akopian 2y agoYou can't but they should be better than Authy, at least they have export options...
- neoecos 2y agoI was hoping for allow importing Authy secrets, has anyone sucessfully "taken" the backup out of the app and imported in other tool. As security measure the secrets only live in Authy, but thats when I cannot move out when I want.
- andrei-akopian 2y agoEnte has an Authy export guide. https://help.ente.io/auth/migration-guides/authy/ https://help.ente.io/auth/migration-guides/authy/ You don't even need to have Authy installed. The script pretends to be a new device and gets the keys from your backup. (You might need to run chmod +x for execute permission)
- vishnumohandas 2y agoLike a sibling comment mentioned, unlike Authy, you can easily export your data[1] from Ente. Also, Ente is fully open-source[2]. If you wish, you can self-host the service and point the app your custom server[3]. [1]: https://help.ente.io/auth/migration-guides/export https://help.ente.io/auth/migration-guides/export [2]: https://github.com/ente-io/ente/ https://github.com/ente-io/ente/ [3]: https://help.ente.io/self-hosting/guides/custom-server/ https://help.ente.io/self-hosting/guides/custom-server/
- csdreamer7 2y agoPeople complaining about an "Authy jail" and yet I have no issues with Aegis. Which is also open source, available in the f-droid store, and been around for years.
- andrei-akopian 2y agoAm I misunderstanding your comment or do you think that Authy is the same as Aegis? Anyway, Aegis and Ente have export options, Aughy doesn't.
- croes 2y agoMore like, why do they complain if alternatives exist.
- csdreamer7 2y agoThis^ It is a pain to switch over; but that is the way it is with all sorts of proprietary programs. They just tighten the noose regardless if you pay or not.
- rangerelf 2y agoYou're right, it's a pain to switch, BUT: you only have to do it once, if you do it right. Switch to an alternative that gives you the functionality you need (TOTP, and that's it, for me at least) and allows you to export your data to a format that can be reimported to another application at another time (or restore from it in case catastrophe hits). Once you get rid of the noose, it's no longer a hassle. For everyone going through this situation, please do a little bit of homework and read up on the capabilities of whatever alternative you're going to pick, and make sure that your data is yours and under your control, and you can back it up in a readable format.
- roughly 2y agoAuthy supports normal TOTP but also has its own proprietary TOTP format for which alternatives do not exist.
- tdubey 2y ago[dead]
- vishnumohandas 2y agoScreenshots look cool! It'd be great if you could create a README.md with instructions to build the project (and screenshots if possible!)
- tw04 2y agoHow does this compare to duo? Is there anything beyond being open source that differentiates it?
- evolve2k 2y agoMy hunt for an open source Authy took me to 2FAS, which has been fine. Any opinions on this offering? 2FAS — the Internet’s favorite open-source two-factor authenticator https://2fas.com https://2fas.com
- robxorb 2y ago> 2FAS syncs across your mobile devices. [...] > 2FAS works offline. > 2FAS doesn't store any passwords or metadata. Eh?
- mcpeepants 2y agothis is storing/syncing the shared secret used to generate the TOTP. generating the TOTP is fully offline.
- robxorb 2y agoOk, except that the secret is the TOTP generator. Anyone that has the secret can generate any TOTP for any point in time, and own your 2FA. An attacker needs nothing else. So if the secrets are stored online - ever - it's nullifying the "offline" claim. Does anyone know a 2FA app that only stores secrets offline? Eg without any networking code; as it's not only not required, but IMO is required NOT to be there for it to actually functionally be "two-factor authentication", and therefore locally-isolated. iCloud is the worst choice of a place to store them as it's the same place the other factor may be routinely saved / backed-up, especially if "across devices".
- vishnumohandas 2y ago> Does anyone know a 2FA app that only stores secrets offline? Ente Auth works fully offline. E2EE backups are optional.
- xp84 2y agoYou’re not wrong, a hardware keychain gizmo with a camera for scanning QRs would be the ultimate actually-secure 2FA device (at least against remote attackers). Personally though I view standards-based 2FA more as a tool to reclaim my login abilities from the insane zoo of “let us email or text you a code” confirmations various sites force on you because they assume you must use a stupid and reused password so that’s not enough now. When I store my passwords and their 2FA secrets in my KeePass db, I’m arrogantly taking for granted that I won’t ever leak my whole secrets database, which is a risk I’m willing to take because I know what I’m doing (and don’t have any secrets valuable to state-level actors). I appreciate having the option to make this call so I don’t have to drop in to my email just to log into frigging Patreon.
- pebblesun 2y agoIs there any problem using Password Manager's feature to get 2FA codes? I use 1Password and it has this feature built in and automatically fills after filling the password. Even iPhone's latest Password app also has this built in.
- ffpip 2y agoStoring passwords and 2FA in one place only protects you against password reuse, password leaks, and some more common threats that the large majority of people should be looking out for. It is still a lot better than no 2FA, and more than sufficient for the average person. For someone looking to improve their security a bit more and for someone with a "don't trust anyone" model, having a separate 2FA app has it's advantages. It protects them against unencrypted password DB leaks, security vulnerabilities in the password manager, or any intentional security threat induced by the developer of the password manager
- nicpottier 2y agoThis looks quite nice, thank you for releasing it open source. Also neat to see a real Flutter app in the wild, this seems like a great use case for it. Would love to read your experience building something polished across ios/android on Flutter. One note as I signed up for an account is that the email verification went to gmails spam. Probably nothing to be done about that but mentioning it. I would also add an "authy" option when importing that just goes to an explanation of why it isn't possible and steps you can take to create new tokens etc. In any case, well done and thank you!
- vishnumohandas 2y agoThank you! Apps like Auth are a great fit for Flutter, where desktop support is nice to have. We're also using Flutter for our Photos[1] app, and it has served us well so far. Wherever necessary (cryptography, ML, transcoding, ...), we use a bridge to communicate with the native layer, and Flutter becomes a presentation layer of sorts. Reg. Gmail marking our verification emails going to spam, we aren't sure what the issue is. We migrated from Zoho to SES recently hoping to fix this, but that has not helped. If anyone here understands email deliverability, please do share your thoughts, we'd be grateful! We've a migration guide from Authy here[2]. They make it difficult, but it's possible. [1]: https://ente.io https://ente.io [2]: https://help.ente.io/auth/migration-guides/authy/ https://help.ente.io/auth/migration-guides/authy/
- chillydawg 2y agoThe migration guides dont work as of the hack as they all rely on desktop tools which used the api that script kiddies used to dump that list of 33m phone numbers. Any updated guides?
- vishnumohandas 2y agoThat's unfortunate, thanks for letting me know. I'm currently unable to find a straight forward way of getting data out of Authy, will bump up this thread when I do.
- 2y ago
- secstate 2y agoI feel like this misses the problem with Authy. There are hundreds, possibly thousands of 2FA alternatives for Authy. But when my 401K provider requires Authy to login in without providing a generic 2FA option, THAT is the problem.
- ezekg 2y agoIf we're talking OTP/TOTP -- it's all the same. Even if a provider instructs you to use a specific app, e.g. Google or Authy, you can simply scan the QR code with whatever authenticator app you're using. All the QR code does is encode a URI containing the secret and issuer.
- RockRobotRock 2y agoI don’t think that’s what they’re saying. Authy supports TOTP but they also have a proprietary format.
- roughly 2y agoAuthy supports TOTP, but also has its own proprietary TOTP-esque format that a bunch of sites & companies use (Twitch and my bank, among them) that can't be copied into another site. (Yes, it's bad, no, it shouldn't exist, no, I don't know why they don't just <...>, etc.)
- 77pt77 2y ago
- mrbluecoat 2y agoEnte Auth is awesome - I've been using it ever since Authy discontinued their desktop app: https://mrbluecoat.blogspot.com/2024/03/bah-authy-discontinues-their-desktop-app.html https://mrbluecoat.blogspot.com/2024/03/bah-authy-discontinu...
- ploum 2y agoIt should be highlighted that the flagship app from ente is not their 2FA but their wonderful encrypted photo app. It is a fully encrypted alternative to Google Photo. It is far from perfect but already very usable. There’s also a Linux desktop client that allows me to sync all my photos on my computer. I really recommend them (nice team)
- BonusPlay 2y agoWhat's the point of having your 2FA codes synchronized across all your devices? Isn't it in the name "TWO FACTOR"? It's supposed to be a separate device and ability to "across devices" comes as an anti-feature for me. 1) If you're not using password manager, then you're probably using same password everywhere, including your 2FA app. 2) If you're storing your 2FA codes in your password manager, then it's not really a 2nd factor. It helps against password leaks from services, not from a password manager leak. Ability to synchronize encrypted backup is a different story.
- Spooky23 2y agoIt’s really two step auth. Basically the point is that it defeats password spray attacks. Higher assurance authenticators need more than TOTP. Usually that means adding a knowledge component (ie pin), challenge/response, a physical token, biometric or all of the above.
- kstrauser 2y agoI mentioned all this in another story, but: Having it integrated with a password manager is less secure than having it as a separate app in a separate device, but it makes it so much easier for the average person that they're more likely to actually use it. In a vacuum, yes, you're right. It's not as secure this way. I wouldn't use that for something hyper-sensitive like classified systems. But as a system, "less secure but widely used" beats "more secure but most people avoid using it whenever possible". It's like with the NIST recommendation against regularly rotating passwords. In an ideal world, it's a great ideal to require new passwords frequently. In this world, it only makes people pick bad passwords and append the date or serial number to it. As a system, it's more secure to require strong passwords and then leave them alone until/unless you suspect they've been compromised.
- rangerelf 2y agoIt's "Two Factor Authentication", not "Second Factor On A Single Device You Always Have On Your Person Authentication". That second factor needs to be separate from the originating authenticating service, not that it has to be on a single device hidden away kept in a safe, or on your wrist, or in your pocket. It could be a single device [a server] running bitwarden and you're viewing it through a browser on your <whatever>. Not everyone wants to follow every single recommendation from a data security perspective, and it becomes an anti-pattern when laymen start using workarounds to not have to comply with the safety recommendation of the week.
- mikepollard_dev 2y agoSecurity platforms should be open source by default. It provides assurance that nothing weird is occurring behind the covers and also shows confidence in the implementation and the cryptography behind it all. I will also never forgive Authy for removing desktop support with near immediate deprecation and no way to export off their platform. I will never use another Twilio product again after that.
- benbristow 2y agoI've been using Authy as a backup for 1Password (previously BitWarden/LastPass)'s 2FA since in a worst-case scenario I can get a replacement SIM card from my phone network's store and get back into my 1Password account via recovery. This has had to be tested once when my phone got pickpocketed in Amsterdam. Is there a better alternative? Authy is fine for this use, the rest of my 2FA tokens are in 1Password itself.
- 9dev 2y agoIf you’re on a Mac and use Safari, it has a neat 2FA integration built in, which saves and autofills OTPs from iCloud Keychain.
- deleted 2y ago[deleted]
- dotancohen 2y agoIf _I_ can get a replacement SIM card from your phone network's store, can I get into your 1Password account via recovery?
- benbristow 2y agoYou'd need ID to get one. And you'd need the security key also. I guess there has to be a vulnerability _somewhere_ to make it possible to get back in again in an emergency.
- dotancohen 2y agoID can easily be social engineered. What is the security key?
- benbristow 2y ago1Password accounts have a password and a security key/token you need to login.
- bdcravens 2y agoDo any of the many TOTP options have the ability to organize, or put codes into vaults? One you have more than a couple of dozen saved, it starts to get tedious.
- jorams 2y agoAegis allows you to create groups and put codes into them, and then you can filter the list to any number of groups. Works quite well for me.
- vishnumohandas 2y agoWith Ente Auth you can assign tags to a code, and use them as a filter. You can also pin your favorite codes to the top.
- deleted 2y ago[deleted]
- andrewmcwatters 2y agoI don't see people mention this enough, but iCloud Keychain generates TOTPs. I've been migrating all of my accounts slowly to just use the built-in Apple Passwords functionality. In Safari, right click on TOTP QR codes.
- andrewinardeer 2y agoAnd when Apple's automated systems disable your account you're locked out of your accounts.
- freedomben 2y agoIndeed, I don't understand why people's reactions to not liking and being trapped by a lock-in walled garden strategy (Authy) is to switch to another lock-in walled garden strategy (Apple).
- 0cf8612b2e1e 2y agoI trust no corporate entities, and try to minimize my exposure, but I agree it makes some sense. Apple is too big/public to screw around with making a quick buck by changing terms. They are also likely to have significantly better security posture on every aspect of application development and distribution. How much stringency does a code/platform change get at Authy vs Apple? However, once you are in the Apple walls, they are just as ruthless at keeping you locked inside, which is why I try to minimize my dependencies where possible.
- andrewmcwatters 2y agoI mean the same happens with GMail, sure.
- dvzk 2y agoIf a single remote service can lock you out of your 2FA accounts then you failed with your backup policy. I don't use it, but Apple Passwords makes TOTP secret backups possible, via bulk export and initial key setup.
- 2y ago
- jamesralph8555 2y agoI’ve had a really poor experience with the (open source) 2FA app Raivo on ios. Developer got bought out. Ads got added, and a bug was introduced where users lost 2fa backup. Losing 2fa access was not as bad as I expected since I stored 2fa backup codes in bitwarden notes. A lot of sites also feature email recovery. I ended up migrating totp 2fa to bitwarden and its been very convenient.
- ackyshake 2y agoLast week, I started to explore `pass`[1], to move away from my current Authy + iCloud Keychain ecosystems. It's pretty barebones but that's what I like about it. I like it so much that one week later, I've fully migrated away and couldn't be happier. And the news about the Authy leak yesterday validated my move, if anything. I don't really care for ente; it's more complicated than what I need from a password manager. And the fact that pass is so much more customizable (being as it's only 700 or so lines of shell script), I don't feel like I need anything more _personally_. [1]: https://www.passwordstore.org/ https://www.passwordstore.org/
- stevekemp 2y agoI use the same thing, and put together a "distribution" of pass, with a couple of plugins including the OTP extension: https://github.com/skx/pass https://github.com/skx/pass Just clone beneath /opt/pass and configure with the standard environmental variables, or use the default password-store location, and you're good to go. I use this to ensure all my systems have access to the same passwords (which are stored in a private git repository).
- fishcrackers 2y ago[dead]
- vishnumohandas 2y agoHello, one of the folks working on Ente Auth here. Thanks for putting us on the frontpage! To give some context, we built Auth for ourselves because we wanted a product that was cross-platform, open source[1] and offered end-to-end encrypted backups[2]. Since launch[3], the product has undergone iterations[4][5]. Auth is now available on Android, iOS, Linux, Mac and Windows[6]. We also have a read-only companion app for the web[7]. Backups are end-to-end encrypted, optional and free. You can use all our apps (minus the web) without an account. You can also self-host[8] if you wish. Please let me know if you have any questions! [1]: https://github.com/ente-io/ente https://github.com/ente-io/ente [2]: https://ente.io/architecture https://ente.io/architecture [3]: https://ente.io/blog/auth/ https://ente.io/blog/auth/ [4]: https://ente.io/blog/auth-v2/ https://ente.io/blog/auth-v2/ [5]: https://ente.io/blog/auth-v3/ https://ente.io/blog/auth-v3/ [6]: https://github.com/ente-io/ente/releases?q=tag%3Aauth-v3 https://github.com/ente-io/ente/releases?q=tag%3Aauth-v3 [7]: https://auth.ente.io https://auth.ente.io [8]: https://help.ente.io/self-hosting/ https://help.ente.io/self-hosting/
- smcleod 2y agoThat’s fantastic you can optionally self host. Well done!
- jeanofthedead 2y agoAny plans to release an Apple Watch app? That’s my one requirement for a 2FA app.
- vishnumohandas 2y agoYes, this is on our roadmap: https://github.com/ente-io/ente/discussions/485 https://github.com/ente-io/ente/discussions/485
- ecesena 2y agoOut of curiosity, have you tested what happens if you buy a new iPhone and upgrade from old to new one? (Preferably no backup, just the new/standard upgrade procedure where you bring the new device close to the old one, and Apple does its magic.) The only reason why I use (and recommend) Authy is that when I get a new phone it just works, while other apps require to somehow open them and do some operation between old and new phone. If it works, happy to switch to an open alternative! (Asking about iPhone, but I assume Android folks would also be interested.)
- ditiyaf1 2y ago[flagged]
- ditiyaf1 2y ago[flagged]
- LorenzoGood 2y agoI'm waiting for bitwarden or aegis export capability before trying this out. You cant easily export your codes into a different format using this app, meaning that it is difficult to migrate away once you have already moved your codes over. Other than the (hopefully temporary) lock-in, this is a great app.
- vishnumohandas 2y agoHey, you can migrate your data in bulk to a plain text / encrypted[1] file. There is also an option to view / export individual QR codes. Let me know what we could do better, would love to do better. [1]: https://help.ente.io/auth/migration-guides/export#how-to-use-the-exported-data https://help.ente.io/auth/migration-guides/export#how-to-use...
- LorenzoGood 2y agoDoes the plain text format easily translate to other apps, or are you still stuck manually copying codes over one by one?
- vishnumohandas 2y agoThere is no universally agreed upon format for bulk imports. We've adopted one that we found to be used by a few other apps - a plain text file with otpauth:// URIs separated by a newline.
- LorenzoGood 2y agoThanks
- charlietango592 2y agoThis makes me want to restart working on Owky - my 2FA open-source pet project. Owky is short for “Own your keys”. Therefore the user owns the data - can easily be exported, and there’s no server sync (on purpose). No iCloud sync, nothing. The app needs some love indeed, but it’s in a usable state.
- out-of-ideas 2y agosounds more simple than Ente's Auth; for instance I can see having a simple totp record-keeping app on an internet-less rpi or similar (or highly restricted networking where an auth'd user can only webui interface with some backup/restore feature when blue-green'ing the device), integrated with some built in (touch)?screen to select/search service-account to read totp from and adding-new via screen as well. edit: simple in terms of only ever needing to compile/validate the thing for linux (arm + intel)
- vishnumohandas 2y agofwiw, Ente's Auth works fully offline. E2EE backups / account creation is optional. If you have an RPi that is accessible over a network, you could self host it as well: https://help.ente.io/self-hosting/ https://help.ente.io/self-hosting/
- out-of-ideas 2y agoyep i did check all that; i however did not check Owky and only now realize it is an apple app; i was implying dont giveup on simple-apps just because another has similar features - sometimes simple things can have huge benifits (all subjective though)
- vishnumohandas 2y agoUnderstood :)
- SSchick 2y agoTangentially: I just got rid of Authy, it took me 2h to to migrate everything, moved to apple passwords (yea yea, still propriatary) which has a so far solid export feature. I will never forgive Authy/Twillio for deliberately making exports impossible.
- vishnumohandas 2y agoHey, would you mind sharing how you exported your codes out of Authy?
- memset 2y agohttps://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93 https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
- vishnumohandas 2y agoThanks! But this method requires Authy's Desktop client, which is unfortunately unavailable at this point. Also, if this comment[1] is right, API access has also been broken. [1]: https://news.ycombinator.com/item?id=40885456 https://news.ycombinator.com/item?id=40885456
- SSchick 2y agoManually, hence the 2 hours. Authy completely broke all exporting.
- InfiniteVortex 2y agoSomewhat related: I hope there will be more news coverage/attention on the whole Ravio situation. It totally seems like something that should be reported on. Raivo, marketed as open source, despite never being OSI-defined open source, created by a computer security professional & expert sold it (2fa app) to a shady & unknown guy from Morocco, who put people's codes behind a paywall. Crazy story. And we (probably) found out the guy behind it too.
- Loranubi 2y agoBecause I got fed up with all the existing 2FA apps (lack of backup, export, ...) I created a simple (desktop) CLI app which works for me: https://github.com/Dobatymo/otp-tool https://github.com/Dobatymo/otp-tool It's just a one day project so far. But it has some nice features like taking a screenshot and reading qr codes from it and storing everything in a single enrypted file (which you can easily put on a cloud drive if you want to sync, otherwise it's completely offline) It only supports the standard RFC 6238 TOTP so far.
- UberFly 2y agoNice role-your-own solution. Just a FYI - Aegis does have backup, export etc. I would also not use it if it couldn't export.
- anssip 2y agoI've developed a command-line password manager and authentication application in Rust. Here are the key features: 1. Uses KeePass file format for secure credential storage 2. Supports One-Time Passwords (OTP) for two-factor authentication (2FA) 3. Provides a convenient CLI interface for retrieving 2FA codes The project, named Passlane, offers a streamlined approach to password management directly from the terminal. It's particularly satisfying to generate 2FA codes via command line! For those interested in exploring the code or contributing, you can find the project on GitHub: https://github.com/anssip/passlane https://github.com/anssip/passlane I'd appreciate any feedback or suggestions for improvement.
- rattray 2y agoAnyone else confused with this name vs Microsoft Entra, the new name for Active Directory? Is there any shared etymology between Ente and Entra? I'm curious where both come from.
- vishnumohandas 2y agoNo shared etymology, "ente" means "mine" in Malayalam. Felt like a nice name to build a privacy company around. Also the domain was available :) If you're interested, here's more of the backstory: https://ente.io/blog/ducky/ https://ente.io/blog/ducky/