▲ 267 ▼ Twilio kills off Authy for desktop, forcibly logs out all users (www.bleepingcomputer.com) submitted 2 years ago by fne8w2ah@lemmy.world to c/technology@lemmy.world 52 comments fedilink hide all child comments
[+] Boozilla@lemmy.world 21 points 2 years ago (10 children) [deleted] permalink fedilink source hideshow 20 child comments replies: [–] PatrickYaa@lemmy.one 65 points 2 years ago (1 child) I switched to Aegis permalink fedilink source parent hideshow 2 child comments replies: [–] beejjorgensen@lemmy.sdf.org 17 points 2 years ago (1 child) I switched to Aegis when google authenticator didn't allow exports. It's simple and it works. permalink fedilink source parent hideshow 2 child comments replies: [–] Estebiu@lemmy.dbzer0.com 0 points 2 years ago (2 children) Wait, google auth doesnt allow exports? For me it dies..? Am I missing something..? permalink fedilink source parent hideshow 4 child comments replies: [–] Scrollone@feddit.it 3 points 2 years ago (1 child) It allows exports but only is a stupid QR-code based format. permalink fedilink source parent hideshow 2 child comments replies: [–] Estebiu@lemmy.dbzer0.com 1 point 2 years ago Aaahh, you mean that. Yeah, it's annoying. permalink fedilink source parent [–] beejjorgensen@lemmy.sdf.org 1 point 2 years ago (1 child) It does now--it didn't in the past. permalink fedilink source parent hideshow 2 child comments replies: [–] desktop_user@lemmy.blahaj.zone 1 point 2 years ago It still does (last time I checked less than two weeks ago) it is just annoying and involves qr codes permalink fedilink source parent [–] fart_pickle@lemmy.world 30 points 2 years ago Bitwarden or Proton Pass. permalink fedilink source parent [–] mosiacmango@lemm.ee 16 points 2 years ago* Keepass. Standalone FOSS apps for desktop/phone. Has OTP support. Password/tokens are stored in a small encrypted db file you can copy/paste anywhere you need it. Has hundreds of plugins to do various things. Use something like syncthing/nextcloud/onedrive to keep the file in sync across devices. permalink fedilink source parent [–] freecloudgal@discuss.tchncs.de 12 points 2 years ago Duo, Aegis, Bitwarden, Proton. permalink fedilink source parent [–] Eezyville@sh.itjust.works 9 points 2 years ago I use KeePassXC and a Yubikey 5. You can store a certain number of 2fa on the key but i also back up the secret key and recovery codes on KeePassXC which is backed up on my Nextcloud. When using the Yubikey there is an app on desktop and mobile that reads they key but doesn't store the codes. Open the app, plug in the key, the TOTP appears, take the key out and the TOTP is gone. permalink fedilink source parent [–] BakedCatboy@lemmy.ml 8 points 2 years ago* I like using bitwarden, the selfhosted vaultwarden server stores it with passwords and makes codes available in the app / browser extension. I also keep them backed up on a nas and synced off-site just in case. permalink fedilink source parent [–] haulyard@lemmy.world 7 points 2 years ago (1 child) Along with others already mentioned, 1Password can support 2fa. permalink fedilink source parent hideshow 2 child comments replies: [–] batcheck@lemmy.world 2 points 2 years ago 1Password has impressed me. I’ve used KeePassXC, LastPass, Bitwarden (but not extensively and one of the early versions), and even CyberArk (🤮). 1Password is closed source but it’s one of those pieces of software that just works the way you expect it to. Hard to confirm a lot of their security claims. Just rolling with “Have not heard a lot about 1Password breaches” mentality. We got lucky at work and used it to replace an unmanageable long list of KeePass database files that were sprawling everywhere. With that everyone who uses 1Password at work gets an associate private family account. Made managing my kids passwords and share some of our common family passwords way easier and I still get to lock them out of my passwords I don’t want them using. I believe modern Bitwarden for enterprise has a similar licensing sweetener with a private family account for each corporate account. permalink fedilink source parent [–] kolorafa@lemmy.world 5 points 2 years ago (1 child) andOTP + bitwarden for me permalink fedilink source parent hideshow 2 child comments replies: [–] mosiacmango@lemm.ee 2 points 2 years ago* (1 child) AndOTP is great. Its free and had simple and easy encrypted backups. I love how its timer counts down, not up like some others and highlights the token in red so you know you need to hustle or wait. permalink fedilink source parent hideshow 2 child comments replies: [–] tja@sh.itjust.works 1 point 2 years ago (1 child) It seems I cannot install it because the app is too old for Android 14.. permalink fedilink source parent hideshow 2 child comments replies: [–] saiarcot895@programming.dev 1 point 2 years ago That's odd, I'm on Android 14 and have andOTP installed. permalink fedilink source parent [–] Damage@feddit.it 4 points 2 years ago (1 child) I switched to Ente Auth some time ago when bad news about authy started getting out permalink fedilink source parent hideshow 2 child comments replies: [–] anas@lemmy.world 1 point 2 years ago Same here, have no problems so far. permalink fedilink source parent [–] Fubarberry@sopuli.xyz 3 points 2 years ago (1 child) A lot of password managers support 2fa now. I use Enpass because I got a lifetime license a long time ago (it's also available to people with Google Play pass), but I know some other popular options have it too. permalink fedilink source parent hideshow 2 child comments replies: [–] BorgDrone@lemmy.one 13 points 2 years ago (3 children) The whole point of 2FA is to keep the second factor separate from the first. If you store both in the same password manager app that defeats the entire point of 2FA. permalink fedilink source parent hideshow 6 child comments replies: [–] hikaru755@lemmy.world 20 points 2 years ago It still protects you from your passwords being compromised in any way except through a compromise of the password manager itself. Yes, it's worse than keeping them separate, but it's also still much better than not having 2fa at all. permalink fedilink source parent [–] Pika@sh.itjust.works 1 point 2 years ago I only switched to keepass due to the fact that nothing seems to support a desktop application like authy did. Not everyone keeps a phone on them 24/7. If they don't want that risk they would allow desktop apps. least in my opinion permalink fedilink source parent [–] EngineerGaming@feddit.nl 1 point 2 years ago You can have a separate database for the TOTP. permalink fedilink source parent
[–] PatrickYaa@lemmy.one 65 points 2 years ago (1 child) I switched to Aegis permalink fedilink source parent hideshow 2 child comments replies: [–] beejjorgensen@lemmy.sdf.org 17 points 2 years ago (1 child) I switched to Aegis when google authenticator didn't allow exports. It's simple and it works. permalink fedilink source parent hideshow 2 child comments replies: [–] Estebiu@lemmy.dbzer0.com 0 points 2 years ago (2 children) Wait, google auth doesnt allow exports? For me it dies..? Am I missing something..? permalink fedilink source parent hideshow 4 child comments replies: [–] Scrollone@feddit.it 3 points 2 years ago (1 child) It allows exports but only is a stupid QR-code based format. permalink fedilink source parent hideshow 2 child comments replies: [–] Estebiu@lemmy.dbzer0.com 1 point 2 years ago Aaahh, you mean that. Yeah, it's annoying. permalink fedilink source parent [–] beejjorgensen@lemmy.sdf.org 1 point 2 years ago (1 child) It does now--it didn't in the past. permalink fedilink source parent hideshow 2 child comments replies: [–] desktop_user@lemmy.blahaj.zone 1 point 2 years ago It still does (last time I checked less than two weeks ago) it is just annoying and involves qr codes permalink fedilink source parent
[–] beejjorgensen@lemmy.sdf.org 17 points 2 years ago (1 child) I switched to Aegis when google authenticator didn't allow exports. It's simple and it works. permalink fedilink source parent hideshow 2 child comments replies: [–] Estebiu@lemmy.dbzer0.com 0 points 2 years ago (2 children) Wait, google auth doesnt allow exports? For me it dies..? Am I missing something..? permalink fedilink source parent hideshow 4 child comments replies: [–] Scrollone@feddit.it 3 points 2 years ago (1 child) It allows exports but only is a stupid QR-code based format. permalink fedilink source parent hideshow 2 child comments replies: [–] Estebiu@lemmy.dbzer0.com 1 point 2 years ago Aaahh, you mean that. Yeah, it's annoying. permalink fedilink source parent [–] beejjorgensen@lemmy.sdf.org 1 point 2 years ago (1 child) It does now--it didn't in the past. permalink fedilink source parent hideshow 2 child comments replies: [–] desktop_user@lemmy.blahaj.zone 1 point 2 years ago It still does (last time I checked less than two weeks ago) it is just annoying and involves qr codes permalink fedilink source parent
[–] Estebiu@lemmy.dbzer0.com 0 points 2 years ago (2 children) Wait, google auth doesnt allow exports? For me it dies..? Am I missing something..? permalink fedilink source parent hideshow 4 child comments replies: [–] Scrollone@feddit.it 3 points 2 years ago (1 child) It allows exports but only is a stupid QR-code based format. permalink fedilink source parent hideshow 2 child comments replies: [–] Estebiu@lemmy.dbzer0.com 1 point 2 years ago Aaahh, you mean that. Yeah, it's annoying. permalink fedilink source parent [–] beejjorgensen@lemmy.sdf.org 1 point 2 years ago (1 child) It does now--it didn't in the past. permalink fedilink source parent hideshow 2 child comments replies: [–] desktop_user@lemmy.blahaj.zone 1 point 2 years ago It still does (last time I checked less than two weeks ago) it is just annoying and involves qr codes permalink fedilink source parent
[–] Scrollone@feddit.it 3 points 2 years ago (1 child) It allows exports but only is a stupid QR-code based format. permalink fedilink source parent hideshow 2 child comments replies: [–] Estebiu@lemmy.dbzer0.com 1 point 2 years ago Aaahh, you mean that. Yeah, it's annoying. permalink fedilink source parent
[–] Estebiu@lemmy.dbzer0.com 1 point 2 years ago Aaahh, you mean that. Yeah, it's annoying. permalink fedilink source parent
[–] beejjorgensen@lemmy.sdf.org 1 point 2 years ago (1 child) It does now--it didn't in the past. permalink fedilink source parent hideshow 2 child comments replies: [–] desktop_user@lemmy.blahaj.zone 1 point 2 years ago It still does (last time I checked less than two weeks ago) it is just annoying and involves qr codes permalink fedilink source parent
[–] desktop_user@lemmy.blahaj.zone 1 point 2 years ago It still does (last time I checked less than two weeks ago) it is just annoying and involves qr codes permalink fedilink source parent
[–] fart_pickle@lemmy.world 30 points 2 years ago Bitwarden or Proton Pass. permalink fedilink source parent
[–] mosiacmango@lemm.ee 16 points 2 years ago* Keepass. Standalone FOSS apps for desktop/phone. Has OTP support. Password/tokens are stored in a small encrypted db file you can copy/paste anywhere you need it. Has hundreds of plugins to do various things. Use something like syncthing/nextcloud/onedrive to keep the file in sync across devices. permalink fedilink source parent
[–] freecloudgal@discuss.tchncs.de 12 points 2 years ago Duo, Aegis, Bitwarden, Proton. permalink fedilink source parent
[–] Eezyville@sh.itjust.works 9 points 2 years ago I use KeePassXC and a Yubikey 5. You can store a certain number of 2fa on the key but i also back up the secret key and recovery codes on KeePassXC which is backed up on my Nextcloud. When using the Yubikey there is an app on desktop and mobile that reads they key but doesn't store the codes. Open the app, plug in the key, the TOTP appears, take the key out and the TOTP is gone. permalink fedilink source parent
[–] BakedCatboy@lemmy.ml 8 points 2 years ago* I like using bitwarden, the selfhosted vaultwarden server stores it with passwords and makes codes available in the app / browser extension. I also keep them backed up on a nas and synced off-site just in case. permalink fedilink source parent
[–] haulyard@lemmy.world 7 points 2 years ago (1 child) Along with others already mentioned, 1Password can support 2fa. permalink fedilink source parent hideshow 2 child comments replies: [–] batcheck@lemmy.world 2 points 2 years ago 1Password has impressed me. I’ve used KeePassXC, LastPass, Bitwarden (but not extensively and one of the early versions), and even CyberArk (🤮). 1Password is closed source but it’s one of those pieces of software that just works the way you expect it to. Hard to confirm a lot of their security claims. Just rolling with “Have not heard a lot about 1Password breaches” mentality. We got lucky at work and used it to replace an unmanageable long list of KeePass database files that were sprawling everywhere. With that everyone who uses 1Password at work gets an associate private family account. Made managing my kids passwords and share some of our common family passwords way easier and I still get to lock them out of my passwords I don’t want them using. I believe modern Bitwarden for enterprise has a similar licensing sweetener with a private family account for each corporate account. permalink fedilink source parent
[–] batcheck@lemmy.world 2 points 2 years ago 1Password has impressed me. I’ve used KeePassXC, LastPass, Bitwarden (but not extensively and one of the early versions), and even CyberArk (🤮). 1Password is closed source but it’s one of those pieces of software that just works the way you expect it to. Hard to confirm a lot of their security claims. Just rolling with “Have not heard a lot about 1Password breaches” mentality. We got lucky at work and used it to replace an unmanageable long list of KeePass database files that were sprawling everywhere. With that everyone who uses 1Password at work gets an associate private family account. Made managing my kids passwords and share some of our common family passwords way easier and I still get to lock them out of my passwords I don’t want them using. I believe modern Bitwarden for enterprise has a similar licensing sweetener with a private family account for each corporate account. permalink fedilink source parent
[–] kolorafa@lemmy.world 5 points 2 years ago (1 child) andOTP + bitwarden for me permalink fedilink source parent hideshow 2 child comments replies: [–] mosiacmango@lemm.ee 2 points 2 years ago* (1 child) AndOTP is great. Its free and had simple and easy encrypted backups. I love how its timer counts down, not up like some others and highlights the token in red so you know you need to hustle or wait. permalink fedilink source parent hideshow 2 child comments replies: [–] tja@sh.itjust.works 1 point 2 years ago (1 child) It seems I cannot install it because the app is too old for Android 14.. permalink fedilink source parent hideshow 2 child comments replies: [–] saiarcot895@programming.dev 1 point 2 years ago That's odd, I'm on Android 14 and have andOTP installed. permalink fedilink source parent
[–] mosiacmango@lemm.ee 2 points 2 years ago* (1 child) AndOTP is great. Its free and had simple and easy encrypted backups. I love how its timer counts down, not up like some others and highlights the token in red so you know you need to hustle or wait. permalink fedilink source parent hideshow 2 child comments replies: [–] tja@sh.itjust.works 1 point 2 years ago (1 child) It seems I cannot install it because the app is too old for Android 14.. permalink fedilink source parent hideshow 2 child comments replies: [–] saiarcot895@programming.dev 1 point 2 years ago That's odd, I'm on Android 14 and have andOTP installed. permalink fedilink source parent
[–] tja@sh.itjust.works 1 point 2 years ago (1 child) It seems I cannot install it because the app is too old for Android 14.. permalink fedilink source parent hideshow 2 child comments replies: [–] saiarcot895@programming.dev 1 point 2 years ago That's odd, I'm on Android 14 and have andOTP installed. permalink fedilink source parent
[–] saiarcot895@programming.dev 1 point 2 years ago That's odd, I'm on Android 14 and have andOTP installed. permalink fedilink source parent
[–] Damage@feddit.it 4 points 2 years ago (1 child) I switched to Ente Auth some time ago when bad news about authy started getting out permalink fedilink source parent hideshow 2 child comments replies: [–] anas@lemmy.world 1 point 2 years ago Same here, have no problems so far. permalink fedilink source parent
[–] anas@lemmy.world 1 point 2 years ago Same here, have no problems so far. permalink fedilink source parent
[–] Fubarberry@sopuli.xyz 3 points 2 years ago (1 child) A lot of password managers support 2fa now. I use Enpass because I got a lifetime license a long time ago (it's also available to people with Google Play pass), but I know some other popular options have it too. permalink fedilink source parent hideshow 2 child comments replies: [–] BorgDrone@lemmy.one 13 points 2 years ago (3 children) The whole point of 2FA is to keep the second factor separate from the first. If you store both in the same password manager app that defeats the entire point of 2FA. permalink fedilink source parent hideshow 6 child comments replies: [–] hikaru755@lemmy.world 20 points 2 years ago It still protects you from your passwords being compromised in any way except through a compromise of the password manager itself. Yes, it's worse than keeping them separate, but it's also still much better than not having 2fa at all. permalink fedilink source parent [–] Pika@sh.itjust.works 1 point 2 years ago I only switched to keepass due to the fact that nothing seems to support a desktop application like authy did. Not everyone keeps a phone on them 24/7. If they don't want that risk they would allow desktop apps. least in my opinion permalink fedilink source parent [–] EngineerGaming@feddit.nl 1 point 2 years ago You can have a separate database for the TOTP. permalink fedilink source parent
[–] BorgDrone@lemmy.one 13 points 2 years ago (3 children) The whole point of 2FA is to keep the second factor separate from the first. If you store both in the same password manager app that defeats the entire point of 2FA. permalink fedilink source parent hideshow 6 child comments replies: [–] hikaru755@lemmy.world 20 points 2 years ago It still protects you from your passwords being compromised in any way except through a compromise of the password manager itself. Yes, it's worse than keeping them separate, but it's also still much better than not having 2fa at all. permalink fedilink source parent [–] Pika@sh.itjust.works 1 point 2 years ago I only switched to keepass due to the fact that nothing seems to support a desktop application like authy did. Not everyone keeps a phone on them 24/7. If they don't want that risk they would allow desktop apps. least in my opinion permalink fedilink source parent [–] EngineerGaming@feddit.nl 1 point 2 years ago You can have a separate database for the TOTP. permalink fedilink source parent
[–] hikaru755@lemmy.world 20 points 2 years ago It still protects you from your passwords being compromised in any way except through a compromise of the password manager itself. Yes, it's worse than keeping them separate, but it's also still much better than not having 2fa at all. permalink fedilink source parent
[–] Pika@sh.itjust.works 1 point 2 years ago I only switched to keepass due to the fact that nothing seems to support a desktop application like authy did. Not everyone keeps a phone on them 24/7. If they don't want that risk they would allow desktop apps. least in my opinion permalink fedilink source parent
[–] EngineerGaming@feddit.nl 1 point 2 years ago You can have a separate database for the TOTP. permalink fedilink source parent