You can export from freeOTP+ Its great. You can back up to another password manager by simply copying the shared secret also. But I don't think it's available for iOS. Oh well, if you want more freedom and privacy, you'll have to move to android.
I use Bitwarden for everything, including my totp codes. I should probably use a separate app solely for Bitwarden's totp code, but the danger of losing it all gives me such a rush!
I have been using ProtonMail and Drive already so it was an easy decision to switch to Proton Pass when it came out. It's an all-in-one password manager which let's you store 2FA as well and also let's you make email aliases. It's synced everywhere, on Firefox on my linux desktop to my android phone to my iPad.
It's actually pretty good security-wise, the main issue is that it completely locks you into the Apple ecosystem, while other 2FA apps and password managers are all cross-platform.
Good security-wise, maybe. But who protects you from Apple? They have access to everything they so conveniently sync for you for free. That is neither secure nor private. The same goes for Google. People don't understand how much of your stuff they have access to.
Not on iOS but I like my yubikeys. Depending on your requirements (if you have less than 32 TOTP accounts per yubikey), they can handle your TOTP directly instead of just using them to unlock Bitwarden.
For security I don't like to keep my TOTP keys in my password manager, even if it is strongly protected. With a yubikey I can ensure that both access to the key AND a physical touch is necessary to generate any codes. So even if I leave it plugged in on a remotely compromised PC I'm mostly protected, because a touch is required.
yeah, when sites support it, that's definitely the best option, but many sites only barely do totp lol so I have to have to put the totp codes somewhere, and the yubikey handles it in a pretty nifty way
I am undecided btw 2FAS and Ente. 2FAS has an excellent UI, but there is no desktop app. Ente requires an account, but it’s not a problem considering that everything is E2EE and it’s a company with good reputation.
I’ve been using 1Password for years and love it. It’s multi-device support was one of the reasons I started using it, and now have a family subscription to share some things with my wife.
I rely on TOTP a lot for my IT job. With 1Password it’s easy to display them on my Apple Watch so I don’t need to keep opening the app on my phone or laptop.
They make it hard to export your seeds if you want to move to the other platform or new device + closed source.
On Android Aegis is the great alternative.
On iOS Raivo OTP used to be the main recommendation, but they just got bought by relatively unknown company, which is sketcy in on itself.
So I'm not on iOS but... the websites I need to use for various work things all require that you use a specific authenticator. But they all choose a different random one. It drives me insane. I have 4 different apps. Google Authenticator, Authy, Duo Mobile, and Onelogin Protect. I pray I change jobs before I get a new phone.
I realize there are exceptions to this, and you might fall into that category, but…
Most of the time when websites say they require a particular app, they actually don’t. Like if a website says to use Google Authenticator, you can actually use any TOTP app. There is even a workaround for using Steam’s TOTP without their app.
Don’t be scared to just try importing the QR or text based code into another app when you are signing up for a service. A functioning website won’t let you progress to the next screen without having the proper code in your app.
The password manager for iphone or ios has mfa built in - seems to work ok. Its a bit annoying if you use a desktop thats not mac though and have to search for the mfa code among the millions of passwords.
True but like someone else mentioned here it’s not the best having all eggs in the same basket. If for eggsample 🙂 the apple account gets compromised it’s going to be hard.
all 47 comments