You can export from freeOTP+ Its great. You can back up to another password manager by simply copying the shared secret also. But I don't think it's available for iOS. Oh well, if you want more freedom and privacy, you'll have to move to android.
The password manager for iphone or ios has mfa built in - seems to work ok. Its a bit annoying if you use a desktop thats not mac though and have to search for the mfa code among the millions of passwords.
True but like someone else mentioned here it’s not the best having all eggs in the same basket. If for eggsample 🙂 the apple account gets compromised it’s going to be hard.
I used to use them a while back but now I use Aegis. I prefer my 2fa offline and disconnected from the internet. I still keep my backups saved in safe spaces though. It served me well to get off of Authy too because last year, they got compromised.
Yeah this was something I considered when I moved over. But between the advanced data protection feature and my technical savvy I decided the convince was worth it because chances of my account getting compromised are very very very very low
They make it hard to export your seeds if you want to move to the other platform or new device + closed source.
On Android Aegis is the great alternative.
On iOS Raivo OTP used to be the main recommendation, but they just got bought by relatively unknown company, which is sketcy in on itself.
So I'm not on iOS but... the websites I need to use for various work things all require that you use a specific authenticator. But they all choose a different random one. It drives me insane. I have 4 different apps. Google Authenticator, Authy, Duo Mobile, and Onelogin Protect. I pray I change jobs before I get a new phone.
I realize there are exceptions to this, and you might fall into that category, but…
Most of the time when websites say they require a particular app, they actually don’t. Like if a website says to use Google Authenticator, you can actually use any TOTP app. There is even a workaround for using Steam’s TOTP without their app.
Don’t be scared to just try importing the QR or text based code into another app when you are signing up for a service. A functioning website won’t let you progress to the next screen without having the proper code in your app.
I have been using ProtonMail and Drive already so it was an easy decision to switch to Proton Pass when it came out. It's an all-in-one password manager which let's you store 2FA as well and also let's you make email aliases. It's synced everywhere, on Firefox on my linux desktop to my android phone to my iPad.
I use Bitwarden for everything, including my totp codes. I should probably use a separate app solely for Bitwarden's totp code, but the danger of losing it all gives me such a rush!
I'm curious. I know Bitwarden or keepass can handle TOTPs, but can't I unlock your Bitwarden vault and have access to your password and 2fa code? Or do they have protection against it? Otherwise I have everything I need.
yes, that's the downside of it. You can add additional password requests for some things, but not sure if it works for 2FA. (basically: if you want to use this resource, unlock the vault, but also additionally request the password again)
I’ve been using 1Password for years and love it. It’s multi-device support was one of the reasons I started using it, and now have a family subscription to share some things with my wife.
I rely on TOTP a lot for my IT job. With 1Password it’s easy to display them on my Apple Watch so I don’t need to keep opening the app on my phone or laptop.
I switched to 2FAS but im also looking into Proton Pass since im subscriber (password manager + 2FA) but i dont want to put all my eggs in one basket. Atm im using proton pass for unimportant stuff.
It's actually pretty good security-wise, the main issue is that it completely locks you into the Apple ecosystem, while other 2FA apps and password managers are all cross-platform.
I like Tofu, and I also quite like Authenticator, but so far 2FAS seems to be the only option that offers backups without an account and that isn't a full-blown password manager.
My recommendation is to stay away from the auth services that are account based such as ente or bitwarden UNLESS you have a 2nd method of authentication such as a yubikey. Why? Because you obviously can't store, for example, your bitwarden 2FA code in your bitwarden vault. Same with ente. That's why on android I use Authenticator Pro, as it isn't account based and has great backup options, such as backing up to cloud and file encryption. Not sure what an equivalent would be on iOS but I'd definitely want to find out! Bonus points if it's available on both iOS and Android.
Not on iOS but I like my yubikeys. Depending on your requirements (if you have less than 32 TOTP accounts per yubikey), they can handle your TOTP directly instead of just using them to unlock Bitwarden.
For security I don't like to keep my TOTP keys in my password manager, even if it is strongly protected. With a yubikey I can ensure that both access to the key AND a physical touch is necessary to generate any codes. So even if I leave it plugged in on a remotely compromised PC I'm mostly protected, because a touch is required.
yeah, when sites support it, that's definitely the best option, but many sites only barely do totp lol so I have to have to put the totp codes somewhere, and the yubikey handles it in a pretty nifty way
I am undecided btw 2FAS and Ente. 2FAS has an excellent UI, but there is no desktop app. Ente requires an account, but it’s not a problem considering that everything is E2EE and it’s a company with good reputation.