As we all know, Ravio has been removed from the recommended multi-factor authentication apps for iOS on PrivacyGuides.

As I want to export all my TOTP codes out of Ravio ASAP, what apps are you migrating towards? I know a few were mentioned such as:

• Tofu • Ente • 2FAS • FreeOTP • Bitwarden TOTP + Yubikey

all 47 comments

sorted by: hot top controversial new old
[–] 4 points 3 years ago* (last edited 3 years ago)

Edit: After digging into 2FAS, I think it is now my top choice. Seems like more of a drop in replacement for Raivo. https://2fas.com/

My second choice is (as of this edit) Owky. I’ve not seen anyone talking about it, but it’s FOSS and has the ability to export your TOTP codes.

Im a little worried about it not being maintained though, since it’s a single developer.

https://apps.apple.com/us/app/owky-two-factor-authenticator/id1602245257

Other options I’ve considered:

Tofu Authenticator. Unfortunately it’s basic though and lacks the ability to export.

ente Authenticator. Account required, and I’m a little undecided on the company. Might be a serious option though.

  • source
  • [–] 3 points 3 years ago* (last edited 3 years ago)

    Why are people switching away from Raivo?

    /c/outoftheloop

    Edit: Looks like it's been bought by a generic app developer about which there are few details to be found: https://discuss.techlore.tech/t/raivo-otp-authenticator-has-been-acquired/4962/2

  • source
  • [–] 3 points 3 years ago (1 child)
  • [–] 3 points 3 years ago (2 children)

    I used to use them a while back but now I use Aegis. I prefer my 2fa offline and disconnected from the internet. I still keep my backups saved in safe spaces though. It served me well to get off of Authy too because last year, they got compromised.

    https://techcrunch.com/2022/08/26/twilio-breach-authy/

  • source
  • parent
  • hideshow 4 child comments
  • [–] 0 points 3 years ago (1 child)

    I prefer my 2fa offline and disconnected from the internet.

    That's great until you lose your phone or something...

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 years ago

    Well, that's what backups are for. I sync my Aegis backups between phone, tablet and PC via syncthing. It's convenient to have authy handle bwckups for me, but if I use 2fa I don't want to water down its usefulness right away.

  • source
  • parent
  • [–] 3 points 3 years ago* (last edited 2 years ago) (3 children)

    I switched to 2FAS.

    You can’t export from FreeOTP. Ente doesn’t appear to be open source. Tofu is an option but I’m afraid it might not be maintained.

    Edit: Use Ente. It’s the best option.

  • source
  • hideshow 6 child comments
  • [–] 1 point 3 years ago*

    You can export from freeOTP+ Its great. You can back up to another password manager by simply copying the shared secret also. But I don't think it's available for iOS. Oh well, if you want more freedom and privacy, you'll have to move to android.

  • source
  • parent
  • [–] 3 points 3 years ago (1 child)

    I use Bitwarden for everything, including my totp codes. I should probably use a separate app solely for Bitwarden's totp code, but the danger of losing it all gives me such a rush!

  • source
  • hideshow 2 child comments
  • [–] 3 points 3 years ago (1 child)
  • [–] 3 points 3 years ago (1 child)

    I'm currently enjoying ProtonPass' built-in 2FA. You gotta be on a paid plan, however, but it's worth it imo.

  • source
  • hideshow 2 child comments
  • [–] 2 points 3 years ago*

    I have been using ProtonMail and Drive already so it was an easy decision to switch to Proton Pass when it came out. It's an all-in-one password manager which let's you store 2FA as well and also let's you make email aliases. It's synced everywhere, on Firefox on my linux desktop to my android phone to my iPad.

  • source
  • [–] 1 point 3 years ago (1 child)

    I was in the middle of switching 2FA over to Raivo from Apple Keychain and you drop this aaaaa-

  • source
  • hideshow 2 child comments
  • [–] 1 point 3 years ago

    Fan of OTP Auth

  • source
  • [–] 1 point 3 years ago

    I’m a fan of OTP Auth.

    It’s been reliable, supports local and cloud backup / exporting, is simplistic in use and has a strong privacy policy.

  • source
  • [+] 1 point 3 years ago* (last edited 3 years ago) (1 child)
  • [–] 2 points 3 years ago (1 child)

    Recommending iCloud keychain in a privacy forum??

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 years ago (1 child)

    It's actually pretty good security-wise, the main issue is that it completely locks you into the Apple ecosystem, while other 2FA apps and password managers are all cross-platform.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 years ago

    Good security-wise, maybe. But who protects you from Apple? They have access to everything they so conveniently sync for you for free. That is neither secure nor private. The same goes for Google. People don't understand how much of your stuff they have access to.

  • source
  • parent
  • [–] 1 point 3 years ago* (1 child)

    Not on iOS but I like my yubikeys. Depending on your requirements (if you have less than 32 TOTP accounts per yubikey), they can handle your TOTP directly instead of just using them to unlock Bitwarden.

    For security I don't like to keep my TOTP keys in my password manager, even if it is strongly protected. With a yubikey I can ensure that both access to the key AND a physical touch is necessary to generate any codes. So even if I leave it plugged in on a remotely compromised PC I'm mostly protected, because a touch is required.

  • source
  • hideshow 2 child comments
  • [–] [S] 1 point 3 years ago (1 child)

    I guess why not use the yubikey for webauth instead of totp?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 years ago (1 child)

    yeah, when sites support it, that's definitely the best option, but many sites only barely do totp lol so I have to have to put the totp codes somewhere, and the yubikey handles it in a pretty nifty way

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 years ago

    I'll be using BitWarden as my 2FA app. I use KeePass as my password manager so it would still be two different services/apps.

    I was planning on using Tofu but it has no FaceID which is mandatory IMO.

  • source
  • [–] 1 point 3 years ago

    I am undecided btw 2FAS and Ente. 2FAS has an excellent UI, but there is no desktop app. Ente requires an account, but it’s not a problem considering that everything is E2EE and it’s a company with good reputation.

  • source
  • [–] 1 point 3 years ago

    I’ve been using 1Password for years and love it. It’s multi-device support was one of the reasons I started using it, and now have a family subscription to share some things with my wife.

    I rely on TOTP a lot for my IT job. With 1Password it’s easy to display them on my Apple Watch so I don’t need to keep opening the app on my phone or laptop.

  • source
  • [–] 1 point 3 years ago (1 child)

    I’m a fan of 1Password. Makes it easy to keep all my secrets in one place, behind a yubikey.

  • source
  • hideshow 2 child comments
  • [–] 1 point 3 years ago (1 child)

    I‘m using Google Authenticator, but so far nobody else here seems to, am I doing it wrong??

  • source
  • hideshow 2 child comments
  • [–] 2 points 3 years ago

    They make it hard to export your seeds if you want to move to the other platform or new device + closed source.

    On Android Aegis is the great alternative. On iOS Raivo OTP used to be the main recommendation, but they just got bought by relatively unknown company, which is sketcy in on itself.

  • source
  • parent
  • [–] 1 point 3 years ago (1 child)

    So I'm not on iOS but... the websites I need to use for various work things all require that you use a specific authenticator. But they all choose a different random one. It drives me insane. I have 4 different apps. Google Authenticator, Authy, Duo Mobile, and Onelogin Protect. I pray I change jobs before I get a new phone.

  • source
  • hideshow 2 child comments
  • [–] 1 point 3 years ago*

    I realize there are exceptions to this, and you might fall into that category, but…

    Most of the time when websites say they require a particular app, they actually don’t. Like if a website says to use Google Authenticator, you can actually use any TOTP app. There is even a workaround for using Steam’s TOTP without their app.

    Don’t be scared to just try importing the QR or text based code into another app when you are signing up for a service. A functioning website won’t let you progress to the next screen without having the proper code in your app.

  • source
  • parent
  • [–] 1 point 3 years ago (1 child)

    The password manager for iphone or ios has mfa built in - seems to work ok. Its a bit annoying if you use a desktop thats not mac though and have to search for the mfa code among the millions of passwords.

  • source
  • hideshow 2 child comments
  • [–] 1 point 3 years ago (1 child)

    True but like someone else mentioned here it’s not the best having all eggs in the same basket. If for eggsample 🙂 the apple account gets compromised it’s going to be hard.

    Check this video from techlore.

    https://www.youtube.com/watch?v=25wG173PL3U

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 3 years ago (1 child)

    I recommend Raivo or Tofu both open source and I believe you can save and export it somewhere else to backup.

  • source
  • hideshow 2 child comments