7 ms·
De-Googling TOTP Authenticator Codes
- tigrezno 1y agoFor years I've managed all my TOTP codes with KeepassXC. Not a single problem, great software.
- progbits 1y agoI can recommend the Aegis app for Android. Works great and has encrypted backups.
- 0x49d1 1y agoOr Ente Auth: https://ente.io/auth https://ente.io/auth. Opensource, encrypted, can be used on any OS, has sync/backup. The problem with using same password manager for OTP is that you kind of loose 2nd factor: 1 app compromised - passwords and OTP are compromised too. My approach is to use password manager's OTP generator for non critical services and dedicated app for the critical ones..
- styanax 1y agoReplied to another comment with the same recommendation before seeing this, here's the URL for those interested: https://github.com/beemdevelopment/Aegis https://github.com/beemdevelopment/Aegis
- blackbear_ 1y agoJust consider that storing TOTP codes in the password manager negates the advantage of two factors authentication, namely the added security of needing a second device. This would keep your logins safe even if somebody managed to breach your KeePassXC database.
- wolvesechoes 1y agoYou are allowed to have two separate databases, with different passwords. You can even store them on different devices!
- speedgoose 1y agoIt’s still one device.
- quchen 1y agoThe second factor does not have to be a second device. Like everything security, it’s what you’re protecting against. Shoulder surfing and device theft are not something I worry about in my home setup, for example.
- speedgoose 1y agoYes it depends on your treat model. But being defeated by one simple keylogger isn’t a risk I’m willing to take even at home.
- AstralStorm 1y agoAnd yes, 2FA single use codes will protect against a simple keylogger. But if its on the same device, it will not protect you against a password database harvester.
- Aachen 1y ago> The second factor does not have to be a second device. Like everything security, it’s what you’re protecting against. It doesn't matter if you store your 2FA seed on a billboard or as a tattoo where the sun doesn't shine: 2FA means two factors. The definition doesn't change when your home setup's threat model doesn't call for 2FA and you thus decide to store two secrets in the same place (making a compromise of one necessarily a compromise of the other, thus 1FA)
- 1y ago
- StrLght 1y ago> negates the advantage of two factors authentication Like with all things it depends on your threat model. If your threat model includes risk of leaking all data from your password manager – then yeah, it worsens your security. Otherwise it still covers all other risks: 1. it makes bruteforce basically impossible 2. it makes phishing harder (assuming that your password manager supports autofill and that it checks domains correctly) 3. it lowers the risks if a single password leaks
- Aachen 1y agoAll of this is true without 2FA, just storing securely generated passwords in the manager. Whether it negates the benefits of 2FA (i.e. whether it's 1FA) doesn't depend on the threat model. The threat model is what makes an individual decide whether 2FA is worth it
- brnt 1y agoNo? Without TOTP in Keepass, an attacker still only requires a password (which may be brute forced or otherwise obtained from badly secured websites). If you have TOTP, they _also_ need a copy of your keepass-file, the password and any other factor to _it_, or have access to your machine during a session or so.
- Aachen 1y agoThink about how the attacker gets there: - "an attacker still only requires a password (which may be brute forced" Brute force? Then it wasn't generated securely. Use Keepass' built-in generator or another one that is meant to generate passwords with. You could make the same argument for the 2FA seed: that can also be generated insecurely or set manually by hand - "or otherwise obtained from badly secured websites" The attackers can obtain the 2FA seed in the same way. Furthermore, the 2FA seed is stored plaintext in the website's database whereas the password is typically stored in hashed form (which is unbruteforceable if you generated it securely) - "they _also_ need a copy of your keepass-file, the [main] password" The attacker either got the website's password from this same file (so they evidently have that file and the main password to unlock it), or if you imagine a scenario where the site got hacked and the stupid site stored your password in plain text, then they have access to the site (and the 2FA seed) anyway because they hacked it. So long as you don't re-use passwords (don't need 2FA for that, just a password manager), a site's breach has no impact beyond this one site that was hacked outside of your control - "and any other factor to _it_" Do you mean the key file here? Or what other factor? Either way, again: if they need that to open the vault then they can't get at the passwords either, so what benefit does {2FA when stored inside the password vault} have? I don't know of a scenario where an attacker can get the website's password from the vault, but not the website's 2FA seed, when you store both inside that same (encrypted) file
- hypeatei 1y agoIt doesn't negate the advantage of 2FA. There are so many scenarios that don't involve your entire password manager database being leaked in plaintext. In that case, you likely have much more to worry about considering the attacker has a bunch of places to pivot from (account recovery flows, recovery email accounts, etc..)
- graynk 1y agoI also store them in KeePass, except I have a separate DB for codes that exists only on my phone. I use Keepassium on iPhone, on Android I believe Keepass2Android is pretty good.
- eminemence 1y agoLiked the 'Written by human not by AI' bagde
- promiseofbeans 1y agoEnte auth is a great free option with sync and apps for every platform. https://ente.io/auth/ https://ente.io/auth/ They also have a good Google Photos alternative, which is how they make money.
- Arch-TK 1y agoI'd be more curious to know what the traffic data google maps alternative is.
- frizlab 1y agoHe’s asking for one, he does not have one. I use (Apple) Maps, personally.
- eek2121 1y agoI wish there was a way to export my codes from Microsoft authenticator on iOS. If anyone knows of a way to do this, please feel free to reply. I would like to move to an open source solution.
- riedel 1y agoI also have the same problem, however, I think Microsoft started to use some proprietary protocol wit some challenge / response scheme.
- Aachen 1y agoYes, Microsoft tries to get you to use their proprietary mechanism by default. You need to click on the "use a different method" link when doing the setup to get a code that is compatible with e.g. Google Authenticator, FreeOTP, and all the other ones
- riedel 1y agoThe last time I tried to that for an external MS Teams instance, the option to use another method was gone. Could have been a compliance thing of the 'owner' of the instance, however, I actually tried multiple times to circumvent installing their app, but failed.
- unethical_ban 1y agoIt's a setting of the app owner. I ran into the same thing. Though I admit a push based 2FA is more resistant to phishing.
- mrweasel 1y agoLearned that the hard way, never ever add ANYTHING to the Microsoft Authenticator app if you can avoid it. It is impossible to migrate to something else. I had a client where I got a new phone and forgot about the Microsoft Authenticator. Three months later I had to go on site with the client to reset my Authenticator as signups could only be done from their network.
- 44za12 1y agoShameless plug. I’ve been using a cli tool i had created for over 2 years now, it just works. I had more ideas but never got to incorporate those. https://github.com/44za12/horcrux https://github.com/44za12/horcrux
- cookiengineer 1y agoI actually built a tool that can do this from camera photos or screenshots. You know, for pentesting purposes :) https://github.com/cookiengineer/forensics-tools https://github.com/cookiengineer/forensics-tools
- Aachen 1y agoTo be clear, the point of storing a secret token on your phone and then typing over some codes that prove you have access to the secret still, is to provide 2FA. If you use oathtool on your laptop, and the password is stored there as well, you're back to 1FA That can be fine if that's what you want, but if you wanted 2FA: - FreeOTP: https://f-droid.org/packages/org.fedorahosted.freeotp https://f-droid.org/packages/org.fedorahosted.freeotp - someone forked that and called it FreeOTP+: https://f-droid.org/packages/org.liberty.android.freeotpplus https://f-droid.org/packages/org.liberty.android.freeotpplus - FreeOTP again but from the dark side of the internet: https://play.google.com/store/apps/details?id=org.fedorahosted.freeotp https://play.google.com/store/apps/details?id=org.fedorahost... - etc. It's a dead simple protocol so there'll be lots of options. Pick one that you trust Edit: Even with the PGP option shown at the end of the article, the secret is still accessible to any malware whenever you access it. Unless PGP-based 2FA becomes super widespread, this won't be something malware looks for and so you'll be fine unless you are targeted by intelligence agencies, but still, it's not quite 2FA because it's not something you "have" but something you "know" (the PGP data's unlock password)
- gear54rus 1y ago> you're back to 1FA Which might be exactly what I need if another dumb website wants me add 2fa where I don't want to. Considering just making a publicly accessible webpage for those codes at this point lol.
- littlecosmic 1y agoThe risk factor is mainly that someone got the password from a web application hack not that they logged into your computer and accessed your password manager. In the web app scenario it is still a second factor.
- Aachen 1y agoIf you use a password manager, or another mechanism that makes each password unique and unguessable, the password and the "2FA" seed token are both the same type of secret string, and both are stored on the same disk. There is no added benefit to 2FA if you store the 2FA secret next to the password when both are generated securely But I'm not saying you should care about this. Everyone can make their own risk assessment, especially if you know about common attacks like the data breaches that you mention
- daneel_w 1y agoGo for Aegis if you're on Android, 2FA Authenticator (2FAS) or Authenticator (by Matt Rubin) if you're on iOS.
- bramhaag 1y ago+1 for Aegis. Encrypted backups, easy to import/export multiple formats, and very customizable.
- fersarr 1y ago+1. I stopped using google authenticator when they randomly wiped the app for me and lost all the codes.
- radu_floricica 1y agoI get the feeling. Got a pretty bad experience with google when I migrated phones, and it messed up the data for a pretty important app (no damage, because I'm paranoid and have backups). I keep an offline phone with synced Authenticator because of this.
- ezst 1y agoSome time ago I realised how vulnerable I was keeping all my TOTPs in Authenticator __only__, in the event of losing/breaking my device (and no, there is no way I would sync them to Google cloud). This taught me few things: - there isn't much to Authenticator and TOTPs in general, it's just a secret, which can be shared across multiple TOTP managers and devices. I had solved the "single point of failure" concern - that opened a new need for "safe TOTP replication with offline access", and that's how I ended-up running my own vaultwarden instance and using the bitwarden clients across devices. I'm glad I did, and I can't recommend it more. IIRC, this¹ helped tremendously along the way. ¹: https://github.com/scito/extract_otp_secrets https://github.com/scito/extract_otp_secrets
- AstralStorm 1y agoAnd this is why Aegis has a working encrypted offline backup.
- NaomiLehman 1y agoYubikeys support Google and other TOTPs too
- Unirely01 1y ago[dead]
- akssri 1y agoIf you use Emacs on GNU-Linux, you can have it run oathtool and copy the code to the clipboard which you can straightaway middle-click-paste. https://gist.github.com/akssri/92a3b240c89212815a66e86c60eabde8 https://gist.github.com/akssri/92a3b240c89212815a66e86c60eab...
- tedk-42 1y agoMost people don't really know how these TOTP codes work but yeah for the longest time I've just put the plain text secret in a place where I can wrap it with my own golang utility https://github.com/edify42/otp-codegen https://github.com/edify42/otp-codegen Way easier to open a terminal on my computer and pipe to `pbcopy` and paste it onto the screen.
- zimpenfish 1y agoI did the same for a work code that I have to use multiple times a day - compiled up a standalone binary (with hardcoded TOTP code) using the `otp` crate. (One nice thing it does is wait for the next number if the expiry is within 5s before outputting the code.)
- 8cvor6j844qw_d6 1y agoThis reminds me of Steve Gibson storing his 2FA seeds by printing them out [1]. > "Steve: So in my drawer I have all of my QR codes printed." > "Steve: They're in a safe place. And if it ever comes to the point where I need to set up a new authenticator, not a problem. I just scan the QR codes once again, and we're back in business. So the other thing to look for is an authenticator that will allow you to do that because it is nice to have hard copy backup." --- I'm not sure what TOTP app he's using currently, since this was said 2 years ago [1]. > "Steve: OTP space Auth, and the logo is a simple gray padlock. Very modest logo. And it does all of this correctly." [1]: https://www.grc.com/sn/sn-921.htm https://www.grc.com/sn/sn-921.htm
- whartung 1y agoThis is actually an interesting idea. I have my e.g. GitHub recovery codes printed out. I have to assume that the recovery codes are more flexible, but rescanning the original QR code would be better UX in case of loss simply because GitHub is not involved, they're nevertheless wiser. But the recovery codes are process agnostic. I imagine they work whether you're using TOTP or any other 2FA mechanic. If GitHub deigns to discontinue support for TOTP, then the printer QR code won't be much help. In the end, however, I have a piece of paper (or other visual artifact) with security information to manage. I will keep the persistent QR code concept in my bonnet for potential consideration in the future.
- freehorse 1y agoWhat is the reasoning that google makes it so complicated to export the TOTPs? Is it just to make it harder to migrate to other authenticators (which does not make much sense because other authenticators just build their tool to import this anyway) or is it just a bad case of "security through obscurity"? I cannot imagine any minimally dedicated attacker that has already put the effort to get the export qr code not being able to actually read it, but it just makes it harder for "common" people to actually get their codes. I remember I had to go through what the article describes to access my TOTPs and migrate to another authenticator.
- patrakov 1y agoThere was a misguided line of reasoning that if you can back up a digital artifact, it is no longer eligible as a "something you have" type of security credential. Earlier versions of Google Authenticator did not have any export functionality at all, and the only way to transfer the codes to a new phone was to use a Google backup of the old phone, which is only possible during the initial setup.
- theshrike79 1y agoI'm just boring and use 1Password for this along with my passwords.
- anonymousiam 1y agoI've been waiting for this for years. I'll put this in a VM for some isolation, and I'll have more security and more convenience.
- chaz6 1y agoI have said time and time again, keep a copy of the QR code (or the text encoded within) before adding it to an authenticator app. You may find out too late that you cannot recover the keys. You can do this by simply taking a photo or screenshot of the QR code and storing it in a safe place. Even better, avoid any MFA mechanism that relies on short codes with low entropy. Instead you could use U2F which uses a hardware token in which the key material is designed to be extremely difficult to extract, and requires physical access to the device to even attempt.
- plumeria 1y agoThis is the nice thing about keeping it in Keepass XC. The seed is saved as an attribute in the database, you can easily add it to another app if needed.
- jqpabc123 1y agoIf it has a "Google" label, it's not in your best interests and best avoided. This is just another in a long list of examples and confirmations of this fact. The solution to most 2FA/TOTP issues (including the one described here) is Stratum. It offers a full array of import and exports features (with or without strong encryption) including the ability to import directly from Google's user-hostile abandon ware. https://stratumauth.com/ https://stratumauth.com/
- BallsInIt 1y agoAt least Google lets you export the keys. Authy removed that ability and now Twilio is forever on my shit-list.
- catlikesshrimp 1y agoI love the post. I know this is not the topic: There is a google-auth replacement which has appropiate qr scanning and doesn't require any connection permission, in f-droid. I don't know why freeOTP is more popular since it asks for full network permission. https://fxedel.gitlab.io/fdroid-website/en/packages/org.shadowice.flocke.andotp/ https://fxedel.gitlab.io/fdroid-website/en/packages/org.shad... andOTP.
- butz 1y agoThe worst offender in 2FA business is Steam, as it uses custom 2FA and you must install their app - no way to use 3rd party OTP without jumping through hoops and risking security.
- wahlis 1y agoI believe Aegis has you sorted with Steam as well
- FinnKuhn 1y agoCouldn't Steam break this any second though?
- butz 1y agoOr one could run into some edge case, e.g. when Steam asks for different code when trying to change Steam password - https://github.com/beemdevelopment/Aegis/issues/1613 https://github.com/beemdevelopment/Aegis/issues/1613 .
- mdaniel 1y agohttps://github.com/beemdevelopment/Aegis/blob/v3.4.1/app/src/main/java/com/beemdevelopment/aegis/importers/SteamImporter.java#L36 https://github.com/beemdevelopment/Aegis/blob/v3.4.1/app/src... > // NOTE: this assumes that a global root shell has already been obtained by the caller :-/ My recollection when I last tried this stunt is that it's a boatload of nonsense to try and exfiltrate the Steam credential material, and I wasn't able to find any supporting docs in the Aegis nor on their site about any alternative they have to "root your phone and sniff the keys out of the sibling app"
- mid-kid 1y agoAt work we use OneLogin, set to require the app. However, it stores a regular TOTP code in the app, it's just encrypted with the android keystore. I had to hook the base64 decoding function on my rooted phone to extract it, and put it in my password manager instead. I've been unable to figure out how to decrypt keystore-encrypted secrets in any other way.
- henriks 1y agoI've been storing TOTP codes in on my Yubikeys for many years now, it works pretty decently. They have an app for it (https://www.yubico.com/products/yubico-authenticator https://www.yubico.com/products/yubico-authenticator) which has gotten better over the years. For redundancy I've stored keys on two devices.
- mid-kid 1y agoI've been storing OTP secrets using `pass`[0] with `pass-otp`[1]. This does the whole symmetric encryption for me using `gpg`, decodes the URL for me to pass it into oathtool, and allows me to share the codes with my phone using Android Password Store[2]. This is all deceptively simple to set up, assuming you have a git server you trust to synchronize the codes with, or some kind of other method using maybe tailscale or syncthing? As long as you don't need the codes on Windows, where the QtPass app is unmaintained and can't generate OTP codes on Windows, you're mostly good. Oh and I use `zbarimg` to decode the QR, as I've integrated it with my screenshot script and it can decode more than just QR codes. [0]: https://www.passwordstore.org/ https://www.passwordstore.org/ [1]: https://github.com/tadfisher/pass-otp https://github.com/tadfisher/pass-otp [2]: https://f-droid.org/packages/app.passwordstore.agrahn/ https://f-droid.org/packages/app.passwordstore.agrahn/
- geoka9 1y ago> This does the whole symmetric encryption for me using `gpg` gpg actually uses a public/secret key pair with pass which has a pretty cool effect that you don't need to enter your passphrase when adding an entry to the store, because it uses the public key to encrypt.
- mid-kid 1y agoYou're right, gpg does asymmetric encryption. Don't know how I got that wrong, lol. But yeah the asymmetric part isn't really used in this context.
- tripdout 1y ago> The tool outputs the current date and time, so you can double-check that your code won't expire (at :00 seconds) before you get a chance to type it in A lot of TOTP verifiers often check within ±1 time interval, so you can often just use the first code you see, no need e.g. to wait for it to roll over.
- felishiagreen12 1y ago[dead]
- WhyNotHugo 1y agoI’ve been using a Yubikey for TOTP codes for years. When it’s plugged into my laptop, I use a fuzzy-search UI to pick the right credential, tap the Yubikey, and it writes the TOTP code into the focused text field. There are iPhone and Android apps to generate codes. On iPhone, it works with nfc. The same device also works for webauthn and for gpg. It has no network capabilities.
- catchafish 1y agoCan I put a recommendation out there for andOTP? https://github.com/andOTP https://github.com/andOTP * Open source * Support for encrypted backups * It allows you to peek at the previous 30 seconds code (so it doesn't just vanish if you're halfway through typing it) * Lockable via pin or pass etc * Filterable views
- nabogh 1y agoI actually write down the secret for all my totp codes in a notebook as a backup