3 ms·
I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to reg
by gorgmah 17d ago
I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to regenerate the seed from every provider one by one.
As other commenters said, rooting my main phone would lock me out of banking apps.
I suppose I could find an old phone, sync from authy cloud, root it, and then migrate, but then generating new seeds is probably both safer and faster at that point.
- throwa356262 17d agoImporting is usually not an issue, as you can always enter the secret manually. It is the exporting that is the problem. The secret looks something like this: JBSW Y3DPF QQHO .... (usually fairly short unless its google)
- shocks 17d agoYou can extract keys out of Authy using mitm-proxy. I have done it and switched to Bitwarden.
- gorgmah 17d agoGood point, sadly ios only, I'm on android: https://ente.com/help/auth/migration/authy/ https://ente.com/help/auth/migration/authy/ Or do you mean it also works on android but not documented?
- ForHackernews 17d agoIt's not quick, but you can submit a GDPR/Subject Access Request to Twilio and after a month or two they will send you all your Authy TOTP seeds. Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate https://github.com/uiltondutra/authy-migrate
- gorgmah 17d agoSo there is a real solution to that problem! Thanks a lot for sharing it
- fc417fc802 17d agoThat is alarming. They have access to the plaintext? And they will hand auth secrets out? That seems extremely wrong to me.
- LoganDark 17d agoThey always had access to the plaintext, they could do better to hand them out
- ForHackernews 17d ago>...data arrives as a CSV in which every token is encrypted with your backup password...
- fc417fc802 17d agoFair enough. That seems reasonable.