One more step to unhitching from Google…
Right now the only option I see in F-Droid is Aegis.
I’m not sure what to actually look for side from checking for unexpected permissions and reasonably frequent updates.
Hopefully something I can sync with a GNOME app…
Aegis
Yubikey. It supports TOTP as well as passkeys. Plus is a physical device separate from my phone. Recommend getting 2 to have 1 as backup
A combination of Yubikey and Enpass (I got Enpass back when it was $15 for perpetual).
Yubikeys. I think everyone should get a couple (need 2 in case 1 lost)
I use Aegis, automatically backed up every time a new key is added. Was using Authy for a while, but they’re going down the enshittification hole, so I dumped them.
Ente
Ente
Ente
Ente
Ente
Bitwarden
Bitwarden
I’m a little concerned about having OTP and passwords together in one system.
OTP is on my phone, Bitwarden is on my computer. I don’t use the OTP in Bitwarden.
This is the way. I use Bitwarden and Aegis.
The issue here is putting Bitwarden on your phone with OTP in Bitwarden.
Yah, I can’t see a point to have another app/extension when Bitwarden has it built in, and it’s a great password manager.
The point of 2FA is “something you have” and “something you know” to enter a secured system.
If you put both of those into one system that is accessible by one password, the whole concept is defeated.
My threat model isn’t having someone take my computer and log into stuff so my concern when using 2FA is more about them having gotten hold of a password remotely. But a TOTP makes that password pretty hard to use, no matter where it’s stored. And my BW is also protected by a Yubi/password combo, so I guess I’m just vulnerable to having that beaten out of me.
The other issue with this - If you lose access to that one system, you’re SOL. It’s a single point of failure.
Wait, it does? Including in the mobile app? I don’t see it.
Right under Password in the edit screen of an item: Authenticator Key. You put in the auth key the target site provides you when you enable TOTP and it will start generating timed tokens. Usually you’ll also get a one-time pad of backup keys, I usually toss those in the Notes of the edit screen there as well in case something goes wrong.
The browser extension also lets you scan the page for QR codes for the TOTP key.
Aegis.
I like the auto backup feature (encrypted) . Then the backup is synced to computer via Syncthing.
Set and forget setup.
For me aegis is by far the best. Simple. Encrypted. Backup. It’s saved to a syncthing folder. Passwords are in bitwarden for simpme stuff but keepassxc is great. And also synced via syncthing.
I also use aegis. Have been for years and it works great
I’ve been using Aegis for several years now without any problems. It replaced the Google Authenticator seamlessly.
FreeOTP+
If i remember correctly sone tokens it can’t read? Cant backup? Clunky interface? I looked at it, but decided against it.
I use Proton Authenticator on an iPhone without an account and I am satisfied
I use Aegis on my phone.
keepassxc and a yubikey. And syncthing to keep all devices in sync
I like Aegis.
Vaultwardwn/bitwarden + a yubikey for bitwarden itself and a few others