[HN Gopher] Ente Auth: open-source Authy alternative for 2FA
       ___________________________________________________________________
        
       Ente Auth: open-source Authy alternative for 2FA
        
       Author : memset
       Score  : 161 points
       Date   : 2024-07-05 15:57 UTC (7 hours ago)
        
 (HTM) web link (ente.io)
 (TXT) w3m dump (ente.io)
        
       | skinkestek wrote:
       | Isn't this the thing that fell victim to a hostile takeover a few
       | weeks ago?
       | 
       | Or am I just confused?
        
         | lukevp wrote:
         | Authy has been having security incidents. This is an OSS
         | competitor to Authy (Twilio).
        
         | andrei-akopian wrote:
         | I have heard only prise recently...
         | 
         | If you find the source or news article please share!
        
         | cendyne wrote:
         | You may be thinking of Rovio
         | 
         | https://blog.paranoidpenguin.net/2024/05/raivo-otp-breaks-us...
        
       | xrd wrote:
       | I'm worried that if my device fails I won't be able to recover
       | all the sites I've registered on my phone. Does anyone know if
       | this can enable backup quickly to another device in a secure way?
        
         | DavideNL wrote:
         | Yea, i was hoping for iCloud / Apple Watch support..but
         | unfortunately:
         | 
         | https://github.com/ente-io/ente/issues/182
        
           | evulhotdog wrote:
           | So basically there's no reason to use this over something
           | with a bit more trust, like Bitwarden's 2FA app.
        
         | andrei-akopian wrote:
         | You don't need regular backups, just every time you add a new
         | service.
         | 
         | Ente has free backups and it's own encrypted export format,
         | which sounds promissing.
        
         | memset wrote:
         | I think it has its own backup service. But it otherwise lets
         | you export/import your data. I feel like as long as I can do an
         | export in some way then that's good enough for me.
        
         | SparkyMcUnicorn wrote:
         | 1Password, Bitwarden, and Vaultwarden support 2fa and let you
         | view/export the secrets.
        
       | r0ckarong wrote:
       | I'm very happy with Aegis.
        
         | NelsonMinar wrote:
         | Aegis is great but it's Android only. I really like their
         | thoughtful export system. Ente has export as well, I wonder how
         | it compares.
        
           | andrei-akopian wrote:
           | Ente has built in backups and encrypted export options.
           | Export should be better than Aegis
        
           | freedomben wrote:
           | > Aegis is great but it's Android only.
           | 
           | Yes true, but the Aegis format is supported on Linux by Gnome
           | Authenticator: https://apps.gnome.org/en/Authenticator/
        
       | neoecos wrote:
       | This looks good, as I wanted to "escape" the Authy jail (you
       | cannot easly move out with your secrets), but moving a lot of
       | 2fa's to a "new thing". How to make sure they are a good project?
        
         | andrei-akopian wrote:
         | You can't but they should be better than Authy, at least they
         | have export options...
        
           | neoecos wrote:
           | I was hoping for allow importing Authy secrets, has anyone
           | sucessfully "taken" the backup out of the app and imported in
           | other tool. As security measure the secrets only live in
           | Authy, but thats when I cannot move out when I want.
        
             | andrei-akopian wrote:
             | Ente has an Authy export guide.
             | https://help.ente.io/auth/migration-guides/authy/
             | 
             | You don't even need to have Authy installed. The script
             | pretends to be a new device and gets the keys from your
             | backup. (You might need to run chmod +x for execute
             | permission)
        
         | vishnumohandas wrote:
         | Like a sibling comment mentioned, unlike Authy, you can easily
         | export your data[1] from Ente.
         | 
         | Also, Ente is fully open-source[2]. If you wish, you can self-
         | host the service and point the app your custom server[3].
         | 
         | [1]: https://help.ente.io/auth/migration-guides/export
         | 
         | [2]: https://github.com/ente-io/ente/
         | 
         | [3]: https://help.ente.io/self-hosting/guides/custom-server/
        
       | csdreamer7 wrote:
       | People complaining about an "Authy jail" and yet I have no issues
       | with Aegis. Which is also open source, available in the f-droid
       | store, and been around for years.
        
         | andrei-akopian wrote:
         | Am I misunderstanding your comment or do you think that Authy
         | is the same as Aegis?
         | 
         | Anyway, Aegis and Ente have export options, Aughy doesn't.
        
           | croes wrote:
           | More like, why do they complain if alternatives exist.
        
             | csdreamer7 wrote:
             | This^
             | 
             | It is a pain to switch over; but that is the way it is with
             | all sorts of proprietary programs. They just tighten the
             | noose regardless if you pay or not.
        
               | rangerelf wrote:
               | You're right, it's a pain to switch, BUT: you only have
               | to do it once, if you do it right. Switch to an
               | alternative that gives you the functionality you need
               | (TOTP, and that's it, for me at least) and allows you to
               | export your data to a format that can be reimported to
               | another application at another time (or restore from it
               | in case catastrophe hits).
               | 
               | Once you get rid of the noose, it's no longer a hassle.
               | 
               | For everyone going through this situation, please do a
               | little bit of homework and read up on the capabilities of
               | whatever alternative you're going to pick, and make sure
               | that your data is yours and under your control, and you
               | can back it up in a readable format.
        
             | roughly wrote:
             | Authy supports normal TOTP but also has its own proprietary
             | TOTP format for which alternatives do not exist.
        
         | uyzstvqs wrote:
         | Aegis, Bitwarden Authenticator, FreeOTP, and now Ente Auth.
         | These are the best ones.
        
           | m-p-3 wrote:
           | Add 2FAS to that.
        
           | neoecos wrote:
           | I use Bitwarden for passwords, so... i dont really like that
           | mucho having 2Fa there too... It losses the porpoise of the
           | 2fa.
        
         | neoecos wrote:
         | The "jail" is having ~100 secrets there that you cannot take
         | out, so moving out is adding new 2fa on each service.
        
       | tdubey wrote:
       | Throwing my own hat into the ring here:
       | https://apps.apple.com/ro/app/sesame-2fa/id6445877867
       | 
       | Similarly, I wrote this to get away from Authy, have the ability
       | to inspect codes, share them (sometimes you need to at work) and
       | export the data out in an agnostic format (JSON dump).
       | 
       | It uses the iCloud Keychain for syncing keys between your devices
       | and storing the data itself -- which seems to be the big
       | difference between Ente and what I'm shilling.
       | 
       | Source is available here:
       | 
       | https://github.com/tanishq-dubey/Sesame
       | 
       | If you see any problems, please make an issue and I'd be happy to
       | fix it!
       | 
       | (The app store requires a website, so if you want a quick
       | overview, DWS is me - Dubey Web Services) https://sesame.dws.rip
        
         | vishnumohandas wrote:
         | Screenshots look cool!
         | 
         | It'd be great if you could create a README.md with instructions
         | to build the project (and screenshots if possible!)
        
       | tw04 wrote:
       | How does this compare to duo? Is there anything beyond being open
       | source that differentiates it?
        
       | evolve2k wrote:
       | My hunt for an open source Authy took me to 2FAS, which has been
       | fine. Any opinions on this offering?
       | 
       | 2FAS -- the Internet's favorite open-source two-factor
       | authenticator
       | 
       | https://2fas.com
        
         | robxorb wrote:
         | > 2FAS syncs across your mobile devices.
         | 
         | [...]
         | 
         | > 2FAS works offline.
         | 
         | > 2FAS doesn't store any passwords or metadata.
         | 
         | Eh?
        
           | mcpeepants wrote:
           | this is storing/syncing the shared secret used to generate
           | the TOTP. generating the TOTP is fully offline.
        
             | robxorb wrote:
             | Ok, except that the secret _is_ the TOTP generator. Anyone
             | that has the secret can generate any TOTP for any point in
             | time, and own your 2FA. An attacker needs nothing else. So
             | if the secrets are stored online - ever - it 's nullifying
             | the "offline" claim.
             | 
             | Does anyone know a 2FA app that only stores secrets
             | offline? Eg without any networking code; as it's not only
             | not required, but IMO is required NOT to be there for it to
             | actually functionally be "two-factor authentication", and
             | therefore locally-isolated.
             | 
             | iCloud is the worst choice of a place to store them as it's
             | the same place the other factor may be routinely saved /
             | backed-up, especially if "across devices".
        
               | vishnumohandas wrote:
               | > Does anyone know a 2FA app that only stores secrets
               | offline?
               | 
               | Ente Auth works fully offline. E2EE backups are optional.
        
               | xp84 wrote:
               | You're not wrong, a hardware keychain gizmo with a camera
               | for scanning QRs would be the ultimate actually-secure
               | 2FA device (at least against remote attackers).
               | Personally though I view standards-based 2FA more as a
               | tool to reclaim my login abilities from the insane zoo of
               | "let us email or text you a code" confirmations various
               | sites force on you because they assume you must use a
               | stupid and reused password so that's not enough now.
               | 
               | When I store my passwords and their 2FA secrets in my
               | KeePass db, I'm arrogantly taking for granted that I
               | won't ever leak my whole secrets database, which is a
               | risk I'm willing to take because I know what I'm doing
               | (and don't have any secrets valuable to state-level
               | actors). I appreciate having the option to make this call
               | so I don't have to drop in to my email just to log into
               | frigging Patreon.
        
           | abhinavk wrote:
           | Syncing happens via files in your iCloud Drive.
        
         | DavideNL wrote:
         | 2FAS iCloud storage is not e2e encrypted:
         | https://github.com/twofas/2fas-ios/issues/43
        
       | pebblesun wrote:
       | Is there any problem using Password Manager's feature to get 2FA
       | codes? I use 1Password and it has this feature built in and
       | automatically fills after filling the password. Even iPhone's
       | latest Password app also has this built in.
        
         | ffpip wrote:
         | Storing passwords and 2FA in one place only protects you
         | against password reuse, password leaks, and some more common
         | threats that the large majority of people should be looking out
         | for.
         | 
         | It is still a lot better than no 2FA, and more than sufficient
         | for the average person.
         | 
         | For someone looking to improve their security a bit more and
         | for someone with a "don't trust anyone" model, having a
         | separate 2FA app has it's advantages. It protects them against
         | unencrypted password DB leaks, security vulnerabilities in the
         | password manager, or any intentional security threat induced by
         | the developer of the password manager
        
       | secstate wrote:
       | I feel like this misses the problem with Authy. There are
       | hundreds, possibly thousands of 2FA alternatives for Authy. But
       | when my 401K provider requires Authy to login in without
       | providing a generic 2FA option, THAT is the problem.
        
         | ezekg wrote:
         | If we're talking OTP/TOTP -- it's all the same. Even if a
         | provider instructs you to use a specific app, e.g. Google or
         | Authy, you can simply scan the QR code with whatever
         | authenticator app you're using. All the QR code does is encode
         | a URI containing the secret and issuer.
        
           | RockRobotRock wrote:
           | I don't think that's what they're saying. Authy supports TOTP
           | but they also have a proprietary format.
        
             | remuskaos wrote:
             | That is also supported by Aegis.
        
               | fffrantz wrote:
               | And it seems to be totally generic, just 7 digits, and
               | switching every 10 seconds instead of 30.
               | 
               | Bitwarden can import them too.
        
           | roughly wrote:
           | Authy supports TOTP, but also has its own proprietary TOTP-
           | esque format that a bunch of sites & companies use (Twitch
           | and my bank, among them) that can't be copied into another
           | site.
           | 
           | (Yes, it's bad, no, it shouldn't exist, no, I don't know why
           | they don't just <...>, etc.)
        
             | 77pt77 wrote:
             | Is it standardized?
        
           | dethmetaljeff wrote:
           | Authy (the app) does support generic TOTP which as you
           | mentioned, so do hundreds of others. Unfortunately, the authy
           | app (and some well meaning but not so well versed companies)
           | opt to use Authy's proprietary OTP which isnt compatible with
           | other clients.
        
         | remuskaos wrote:
         | Authy has this 7 digit TOTP, which seems kind of proprietary.
         | But Aegis supports that too, and is open source.
        
           | politelemon wrote:
           | Is it possible to 'transfer' the 7 digit account from Authy
           | over or best to start over?
        
         | xp84 wrote:
         | THE problem with Authy in my humble opinion isn't just that
         | it's an obnoxious proprietary app I shouldn't need -- it's that
         | it forces you to accept SMS as a get-out-of-security-free card.
         | Being able to get a reset text to your registered number (and
         | you MUST register a number, of course) unlocks all your OTPs
         | for the attacker (who slipped some teenaged phone salesman $50
         | or a fake ID to swap your sims.)
         | 
         | SMS is cancer to security and I won't use any system that
         | forces me to accept something so easy to exploit as proof of my
         | consent.
        
           | nextos wrote:
           | Regulators should mandate 2FA with an OTP standard, such as
           | OATH TOTP. Here in EU, lots of banks use their own
           | proprietary OTP-like standard or SMS.
           | 
           | I never understood why SMS are preferred to OTPs generated
           | offline using credit cards and a card reader, which were
           | fairly popular.
           | 
           | Actually, EU regulations state SMS should be phased out, but
           | banks largely ignore that. SIM cloning is fairly easy...
        
             | benoliver999 wrote:
             | The readers cost money and people lose them. I still have
             | one for one bank but otherwise it's SMS everywhere.
             | 
             | They clearly just don't see it as a realistic threat, on
             | top of all the other security measures in place (for me
             | it's a password, and also a memorable word that isn't typed
             | on the keyboard, then SMS OTP). It's not a great defence of
             | SMS but perfect is the enemy of good, and SMS is just about
             | ok.
             | 
             | Most hacking stories I hear about seem to happen through
             | social engineering, where people go to great lengths to
             | authenticate themselves for someone over the phone.
             | 
             | One thing that is starting to take hold is banking apps,
             | which once installed can be used to authenticate payment.
             | Again not perfect but better than SMS, and users are
             | increasingly likely to have them installed because of ease
             | of use.
        
         | wesapien wrote:
         | Is there a list of services that have a specific 2FA provider
         | requirement? In my experience, my when my service ask for 2FA
         | it usually says Google Authenticator and use Authy. I'm looking
         | to migrate out of Authy in the near future.
        
       | nicpottier wrote:
       | This looks quite nice, thank you for releasing it open source.
       | Also neat to see a real Flutter app in the wild, this seems like
       | a great use case for it. Would love to read your experience
       | building something polished across ios/android on Flutter.
       | 
       | One note as I signed up for an account is that the email
       | verification went to gmails spam. Probably nothing to be done
       | about that but mentioning it.
       | 
       | I would also add an "authy" option when importing that just goes
       | to an explanation of why it isn't possible and steps you can take
       | to create new tokens etc.
       | 
       | In any case, well done and thank you!
        
         | vishnumohandas wrote:
         | Thank you!
         | 
         | Apps like Auth are a great fit for Flutter, where desktop
         | support is nice to have. We're also using Flutter for our
         | Photos[1] app, and it has served us well so far. Wherever
         | necessary (cryptography, ML, transcoding, ...), we use a bridge
         | to communicate with the native layer, and Flutter becomes a
         | presentation layer of sorts.
         | 
         | Reg. Gmail marking our verification emails going to spam, we
         | aren't sure what the issue is. We migrated from Zoho to SES
         | recently hoping to fix this, but that has not helped. If anyone
         | here understands email deliverability, please do share your
         | thoughts, we'd be grateful!
         | 
         | We've a migration guide from Authy here[2]. They make it
         | difficult, but it's possible.
         | 
         | [1]: https://ente.io
         | 
         | [2]: https://help.ente.io/auth/migration-guides/authy/
        
           | chillydawg wrote:
           | The migration guides dont work as of the hack as they all
           | rely on desktop tools which used the api that script kiddies
           | used to dump that list of 33m phone numbers. Any updated
           | guides?
        
             | vishnumohandas wrote:
             | That's unfortunate, thanks for letting me know.
             | 
             | I'm currently unable to find a straight forward way of
             | getting data out of Authy, will bump up this thread when I
             | do.
        
           | QasimK wrote:
           | Ah, so _that's_ why the ente photos app feels so "off" - it's
           | using flutter.
           | 
           | I've tried the app a few times over the last couple of years
           | and had a dislike of the UI because it did not _feel_ right,
           | like it was slow or something. I can't say exactly what.
           | 
           | It is almost certainly because it is using flutter rather
           | than native DOM elements.
           | 
           | (I've been keeping track of ente but never quite made the
           | jump - not solely due to the UI though!)
        
       | mrbluecoat wrote:
       | Ente Auth is awesome - I've been using it ever since Authy
       | discontinued their desktop app:
       | https://mrbluecoat.blogspot.com/2024/03/bah-authy-discontinu...
        
       | ploum wrote:
       | It should be highlighted that the flagship app from ente is not
       | their 2FA but their wonderful encrypted photo app. It is a fully
       | encrypted alternative to Google Photo.
       | 
       | It is far from perfect but already very usable. There's also a
       | Linux desktop client that allows me to sync all my photos on my
       | computer.
       | 
       | I really recommend them (nice team)
        
       | BonusPlay wrote:
       | What's the point of having your 2FA codes synchronized across all
       | your devices?
       | 
       | Isn't it in the name "TWO FACTOR"? It's supposed to be a separate
       | device and ability to "across devices" comes as an anti-feature
       | for me.
       | 
       | 1) If you're not using password manager, then you're probably
       | using same password everywhere, including your 2FA app.
       | 
       | 2) If you're storing your 2FA codes in your password manager,
       | then it's not really a 2nd factor. It helps against password
       | leaks from services, not from a password manager leak.
       | 
       | Ability to synchronize encrypted backup is a different story.
        
         | Spooky23 wrote:
         | It's really two step auth. Basically the point is that it
         | defeats password spray attacks.
         | 
         | Higher assurance authenticators need more than TOTP. Usually
         | that means adding a knowledge component (ie pin),
         | challenge/response, a physical token, biometric or all of the
         | above.
        
         | kstrauser wrote:
         | I mentioned all this in another story, but:
         | 
         | Having it integrated with a password manager is less secure
         | than having it as a separate app in a separate device, but it
         | makes it so much easier for the average person that they're
         | more likely to actually use it.
         | 
         | In a vacuum, yes, you're right. It's not as secure this way. I
         | wouldn't use that for something hyper-sensitive like classified
         | systems. But as a system, "less secure but widely used" beats
         | "more secure but most people avoid using it whenever possible".
         | 
         | It's like with the NIST recommendation _against_ regularly
         | rotating passwords. In an ideal world, it 's a great ideal to
         | require new passwords frequently. In this world, it only makes
         | people pick bad passwords and append the date or serial number
         | to it. _As a system_ , it's more secure to require strong
         | passwords and then leave them alone until/unless you suspect
         | they've been compromised.
        
         | rangerelf wrote:
         | It's "Two Factor Authentication", not "Second Factor On A
         | Single Device You Always Have On Your Person Authentication".
         | 
         | That second factor needs to be separate from the originating
         | authenticating service, not that it has to be on a single
         | device hidden away kept in a safe, or on your wrist, or in your
         | pocket. It could be a single device [a server] running
         | bitwarden and you're viewing it through a browser on your
         | <whatever>.
         | 
         | Not everyone wants to follow every single recommendation from a
         | data security perspective, and it becomes an anti-pattern when
         | laymen start using workarounds to not have to comply with the
         | safety recommendation of the week.
        
         | W3cUYxYwmXb5c wrote:
         | It means you are providing two factors, not necessarily that
         | you only have two factors.
         | 
         | There are benefits to this. I've left my phone at work, and
         | would have been SOL, except I have a tablet that never leaves
         | my home which can also provide my second factor.
        
           | dotancohen wrote:
           | I recently had this experience when my phone had issues. I
           | was foresighted enough to have Aegis installed on my E-Ink
           | reader.
        
       | bdcravens wrote:
       | Do any of the many TOTP options have the ability to organize, or
       | put codes into vaults? One you have more than a couple of dozen
       | saved, it starts to get tedious.
        
         | jorams wrote:
         | Aegis allows you to create groups and put codes into them, and
         | then you can filter the list to any number of groups. Works
         | quite well for me.
        
         | vishnumohandas wrote:
         | With Ente Auth you can assign tags to a code, and use them as a
         | filter.
         | 
         | You can also pin your favorite codes to the top.
        
       | mikepollard_dev wrote:
       | Security platforms should be open source by default. It provides
       | assurance that nothing weird is occurring behind the covers and
       | also shows confidence in the implementation and the cryptography
       | behind it all.
       | 
       | I will also never forgive Authy for removing desktop support with
       | near immediate deprecation and no way to export off their
       | platform.
       | 
       | I will never use another Twilio product again after that.
        
       | benbristow wrote:
       | I've been using Authy as a backup for 1Password (previously
       | BitWarden/LastPass)'s 2FA since in a worst-case scenario I can
       | get a replacement SIM card from my phone network's store and get
       | back into my 1Password account via recovery. This has had to be
       | tested once when my phone got pickpocketed in Amsterdam.
       | 
       | Is there a better alternative? Authy is fine for this use, the
       | rest of my 2FA tokens are in 1Password itself.
        
         | 9dev wrote:
         | If you're on a Mac and use Safari, it has a neat 2FA
         | integration built in, which saves and autofills OTPs from
         | iCloud Keychain.
        
         | dotancohen wrote:
         | If _I_ can get a replacement SIM card from your phone network's
         | store, can I get into your 1Password account via recovery?
        
           | benbristow wrote:
           | You'd need ID to get one. And you'd need the security key
           | also.
           | 
           | I guess there has to be a vulnerability _somewhere_ to make
           | it possible to get back in again in an emergency.
        
             | dotancohen wrote:
             | ID can easily be social engineered. What is the security
             | key?
        
               | benbristow wrote:
               | 1Password accounts have a password and a security
               | key/token you need to login.
        
       | andrewmcwatters wrote:
       | I don't see people mention this enough, but iCloud Keychain
       | generates TOTPs. I've been migrating all of my accounts slowly to
       | just use the built-in Apple Passwords functionality.
       | 
       | In Safari, right click on TOTP QR codes.
        
         | andrewinardeer wrote:
         | And when Apple's automated systems disable your account you're
         | locked out of your accounts.
        
           | freedomben wrote:
           | Indeed, I don't understand why people's reactions to not
           | liking and being trapped by a lock-in walled garden strategy
           | (Authy) is to switch to another lock-in walled garden
           | strategy (Apple).
        
             | 0cf8612b2e1e wrote:
             | I trust no corporate entities, and try to minimize my
             | exposure, but I agree it makes some sense. Apple is too
             | big/public to screw around with making a quick buck by
             | changing terms. They are also likely to have significantly
             | better security posture on every aspect of application
             | development and distribution.
             | 
             | How much stringency does a code/platform change get at
             | Authy vs Apple? However, once you are in the Apple walls,
             | they are just as ruthless at keeping you locked inside,
             | which is why I try to minimize my dependencies where
             | possible.
        
           | andrewmcwatters wrote:
           | I mean the same happens with GMail, sure.
        
         | kernal wrote:
         | Additionally, iOS 18 will introduce a Password app making the
         | functionality easier to discover. People are still surprised to
         | learn that iOS has built in TOTP support, but it's just buried
         | deep in the settings.
         | 
         | BTW, there's a hack you can do to create an iOS Password app in
         | iOS 17 and below by using Shortcuts to launch the deep linked
         | setting directly.
        
       | jamesralph8555 wrote:
       | I've had a really poor experience with the (open source) 2FA app
       | Raivo on ios. Developer got bought out. Ads got added, and a bug
       | was introduced where users lost 2fa backup. Losing 2fa access was
       | not as bad as I expected since I stored 2fa backup codes in
       | bitwarden notes. A lot of sites also feature email recovery. I
       | ended up migrating totp 2fa to bitwarden and its been very
       | convenient.
        
       | ackyshake wrote:
       | Last week, I started to explore `pass`[1], to move away from my
       | current Authy + iCloud Keychain ecosystems. It's pretty barebones
       | but that's what I like about it. I like it so much that one week
       | later, I've fully migrated away and couldn't be happier.
       | 
       | And the news about the Authy leak yesterday validated my move, if
       | anything.
       | 
       | I don't really care for ente; it's more complicated than what I
       | need from a password manager. And the fact that pass is so much
       | more customizable (being as it's only 700 or so lines of shell
       | script), I don't feel like I need anything more _personally_.
       | 
       | [1]: https://www.passwordstore.org/
        
         | stevekemp wrote:
         | I use the same thing, and put together a "distribution" of
         | pass, with a couple of plugins including the OTP extension:
         | 
         | https://github.com/skx/pass
         | 
         | Just clone beneath /opt/pass and configure with the standard
         | environmental variables, or use the default password-store
         | location, and you're good to go. I use this to ensure all my
         | systems have access to the same passwords (which are stored in
         | a private git repository).
        
       | vishnumohandas wrote:
       | Hello, one of the folks working on Ente Auth here. Thanks for
       | putting us on the frontpage!
       | 
       | To give some context, we built Auth for ourselves because we
       | wanted a product that was cross-platform, open source[1] and
       | offered end-to-end encrypted backups[2].
       | 
       | Since launch[3], the product has undergone iterations[4][5].
       | 
       | Auth is now available on Android, iOS, Linux, Mac and Windows[6].
       | We also have a read-only companion app for the web[7].
       | 
       | Backups are end-to-end encrypted, optional and free. You can use
       | all our apps (minus the web) without an account.
       | 
       | You can also self-host[8] if you wish.
       | 
       | Please let me know if you have any questions!
       | 
       | [1]: https://github.com/ente-io/ente
       | 
       | [2]: https://ente.io/architecture
       | 
       | [3]: https://ente.io/blog/auth/
       | 
       | [4]: https://ente.io/blog/auth-v2/
       | 
       | [5]: https://ente.io/blog/auth-v3/
       | 
       | [6]: https://github.com/ente-io/ente/releases?q=tag%3Aauth-v3
       | 
       | [7]: https://auth.ente.io
       | 
       | [8]: https://help.ente.io/self-hosting/
        
         | smcleod wrote:
         | That's fantastic you can optionally self host. Well done!
        
         | jeanofthedead wrote:
         | Any plans to release an Apple Watch app? That's my one
         | requirement for a 2FA app.
        
           | vishnumohandas wrote:
           | Yes, this is on our roadmap: https://github.com/ente-
           | io/ente/discussions/485
        
         | ecesena wrote:
         | Out of curiosity, have you tested what happens if you buy a new
         | iPhone and upgrade from old to new one? (Preferably no backup,
         | just the new/standard upgrade procedure where you bring the new
         | device close to the old one, and Apple does its magic.)
         | 
         | The only reason why I use (and recommend) Authy is that when I
         | get a new phone it just works, while other apps require to
         | somehow open them and do some operation between old and new
         | phone.
         | 
         | If it works, happy to switch to an open alternative! (Asking
         | about iPhone, but I assume Android folks would also be
         | interested.)
        
           | radicality wrote:
           | If you're in the Apple/iOS ecosystem and want the syncing to
           | happen via iCloud, you might as well use Apple's built-in
           | password manager which has support for 2FA codes.
        
             | birdman3131 wrote:
             | Just because your in the Apple ecosystem does not mean your
             | not outside it as well and want the crossplatform side.
        
               | AdamJacobMuller wrote:
               | Exactly. I use BitWarden for this reason.
        
           | vishnumohandas wrote:
           | We have intentionally opted out of this[1][2] for now, since
           | we did not want to create a dependency on iCloud for backups.
           | 
           | So if you purchase a new device, you will either have to sign
           | in to Ente Auth again (for E2EE sync), or export your codes
           | from the older device, and import it to the newer device.
           | 
           | [1]: https://github.com/ente-
           | io/ente/blob/8b696b1242bce2f166ddd6a...
           | 
           | [2]: https://github.com/mogol/flutter_secure_storage/blob/cb3
           | 0953...
        
       | LorenzoGood wrote:
       | I'm waiting for bitwarden or aegis export capability before
       | trying this out.
       | 
       | You cant easily export your codes into a different format using
       | this app, meaning that it is difficult to migrate away once you
       | have already moved your codes over.
       | 
       | Other than the (hopefully temporary) lock-in, this is a great
       | app.
        
         | vishnumohandas wrote:
         | Hey, you can migrate your data in bulk to a plain text /
         | encrypted[1] file.
         | 
         | There is also an option to view / export individual QR codes.
         | 
         | Let me know what we could do better, would love to do better.
         | 
         | [1]: https://help.ente.io/auth/migration-guides/export#how-to-
         | use...
        
       | charlietango592 wrote:
       | This makes me want to restart working on Owky - my 2FA open-
       | source pet project.
       | 
       | Owky is short for "Own your keys". Therefore the user owns the
       | data - can easily be exported, and there's no server sync (on
       | purpose). No iCloud sync, nothing.
       | 
       | The app needs some love indeed, but it's in a usable state.
        
         | out-of-ideas wrote:
         | sounds more simple than Ente's Auth; for instance I can see
         | having a simple totp record-keeping app on an internet-less rpi
         | or similar (or highly restricted networking where an auth'd
         | user can only webui interface with some backup/restore feature
         | when blue-green'ing the device), integrated with some built in
         | (touch)?screen to select/search service-account to read totp
         | from and adding-new via screen as well.
         | 
         | edit: simple in terms of only ever needing to compile/validate
         | the thing for linux (arm + intel)
        
           | vishnumohandas wrote:
           | fwiw, Ente's Auth works fully offline. E2EE backups / account
           | creation is optional.
           | 
           | If you have an RPi that is accessible over a network, you
           | could self host it as well: https://help.ente.io/self-
           | hosting/
        
             | out-of-ideas wrote:
             | yep i did check all that; i however did not check Owky and
             | only now realize it is an apple app; i was implying dont
             | giveup on simple-apps just because another has similar
             | features - sometimes simple things can have huge benifits
             | (all subjective though)
        
               | vishnumohandas wrote:
               | Understood :)
        
       | SSchick wrote:
       | Tangentially: I just got rid of Authy, it took me 2h to to
       | migrate everything, moved to apple passwords (yea yea, still
       | propriatary) which has a so far solid export feature.
       | 
       | I will never forgive Authy/Twillio for deliberately making
       | exports impossible.
        
         | vishnumohandas wrote:
         | Hey, would you mind sharing how you exported your codes out of
         | Authy?
        
       ___________________________________________________________________
       (page generated 2024-07-05 23:00 UTC)