Google authenticator app /lost phone
InceptionHosting
Retired
in Technical
Has anyone found a way to make this portable yet?
I really need to stop using it, 1 phone crashed and it is impossible to get back into it without wiping it first, lost access to half a bitcoin (can probably recover that through security phrases set up in addition to 2fa) and now I went and lost my (flat) phone on a 6-acre field of long grass so am having to contact lots of payment gateways to start the reset process.
All of which could be avoided with an alternative to googles authenticator app that is portable between devices, anyone got any suggestions on alternatives?
https://inceptionhosting.com
Please do not use the PM system here for Inception Hosting support issues.
Comments
Hmm not sure about this.
I use Symantec VIP where I have 3 devices added, both my iPhones and my laptop.
"The imitator dooms himself to hopeless mediocrity." — Ralph Waldo Emerson
Authy is much much better than GA, it used to be my primary 2FA app, before I moved everything to my self hosted BitWarden instance, as it makes entering and organising 2FA codes quite a bit easier. Authy is great, it has a desktop app too.
AndOTP is pretty sweet.
Google Authenticator will be updated soon with the cross device functionality. Not exactly sure when the update is due however
For iOS, OTP Auth works great for this. I’ve lost quite some accounts with Google Authenticator too.
You can use an Yubikey and store your OTP on it
1Password works.
I use the LastPass Authenticator. It’s synced across multiple devices through my LastPass account.
wow lots of suggestions thanks, will go through them when making a decision, new phone en route.
https://inceptionhosting.com
Please do not use the PM system here for Inception Hosting support issues.
Authy is awesome. Use it for over year and a half
blog archives
Yep, Authy.
Holding passwords in Bitwarden and using it for 2FA isn't as secure as it sounds.
+1 for Authy. Super convenient and easy to use.
Authy! I'm using it on all kind of device (iOS, Android, Windows, Mac) and sync perfectly
Switched to Authy from Google in the last month. Very noice. Comes up with logos/favicons too which makes it all that prettier.
Also, what about some dodgy remote access software to access your phone in a very limited number of scenarios with it being turned on?
Is such a thing even possible. I'll take my meds now.
Michael from DragonWebHost & OnePoundEmail
I stay away 2FA so that I don't have to carry a specific device. If some service must have 2FA, I use the Google Voice number, and setup an Asterisk server to automatically answer the call and press the button on the keypad.
We accept Karma donations for the last flan. 🍮 affbrr
Care to expand? Having a password manager and 2FA in the same device is not secure either.
Solved this with Authy.
Free turnkey solution.
Authy's encrypted backup password stored in my regular store :keepassxc
I think andotp is the best choice. It is 100% open source and it can export backup with encryption.
1password.
I used to use Authy but didn't like how on android it would seem to cache the last OTP and show it prior to prompting for the pincode/password to access the app. Yes, it's only an OTP, but annoyed me that the developers never seemed to rectify it. Whether that's changed in later versions, I don't know...
+1 for Authy
Of course its closed source. So depends on your trust level. AFAIK it's an offering of Twilio. I do not see it going anywhere in the near future.
Good luck!
Not fond of Authy being closed source. I've used FreeOTP for a while but it's ancient. Many password managers nowadays have TOTP built-in; e.g., KeePassDX on Android.
Even with good old Google Authenticator, root the phone and use Titanium Backup to backup GA's database.
@seanho yep.
That's my go to.
Keep a backupof Google authenticator with titanium is the easiest. And keep backups encrypted.
Enjoy meditation without religion for one month.
Aegis is open source and has a straightforward backup option.
https://github.com/beemdevelopment/Aegis
I use 1password for all my 2FA, along with my 4 digits amount of logins.. works really well
Seems nice. Will check it out.
.
Enjoy meditation without religion for one month.
Well aegis seems to be able to import Google authenticator, authy and other vaults, very easily.
Can export and keep a backup.
Can put fingerprint authenticator on top.
Oper source.
So it looks like aegis is the best.
Not sure whether the code is audited..
@AnthonySmith
Thanks @jaden . Didn't know about this.
Enjoy meditation without religion for one month.
Oh ffs, phone is ‘was’ rooted, could have done that. I know now at least
https://inceptionhosting.com
Please do not use the PM system here for Inception Hosting support issues.
Authy:
https://io.bikegremlin.com/12428/2fa-explained/#5
🔧 BikeGremlin guides & resources
+1 for Aegis, it's simple and does the job well.
Rather than fret about losing one device, I restore the Aegis backup onto a couple of home based devices (i.e. tablets) so I have an immediate alternative if I can't be bothered locating the phone when I need a 2FA login. That assumes you're disciplined to only enter new codes to one device and backup [off device] immediately.
Edit: grammar
I'm using Authy and sync between iPhone, MAC and Windows. Switched from Google Authenticator a few years ago and never looked back.
+1 for Authy, have been using it for a few years after dropping Google Authenticator and have switched phones a few times, no issue at all.
Owned-Networks | VPS and Web Hosting for every project size and budget
DAL - LEN - LA - SEA - NYC - MIA - AMS - LON
I've been using WatchGuard AuthPoint as a replacement for my Google Auth 2FA. Works great for me.
Cheap dedis are my drug, and I'm too far gone to turn back.
I had similar issues a while ago so I tested a lot of solutions, but landed on Authy.
The only thing that bugs me a little is that it is not open source, but I feel that the company behind it is solid enough to be trusted as much as anything else (which depending on the size of your tinfoil hat may be nothing or a lot).
If it's a google account be sure to save the recovery codes somewhere safe too
Too flat huh? Should have gone with one of these.
I use Authy. I have Authy on phone and multiple computers, including one set up on a VM and I keep a backup of the VM in multiple places as my worst case scenario. If everything else crashes, I can just download and spin up the VM to add new devices.
Deals and Reviews: LowEndBoxes Review | Avoid dodgy providers with The LEBRE Whitelist | Free hosting (with conditions): Evolution-Host, NanoKVM, FreeMach, ServedEZ | Get expert copyediting and copywriting help at The Write Flow
>
hehe, it was a galaxy S2 with a massive battery extender on it, so not far off.
I hung my coat over a fence at one point next to a trench I was filling in, I am thinking I probably buried it
https://inceptionhosting.com
Please do not use the PM system here for Inception Hosting support issues.
You just need to save 2fa token to a safe place first, then put it into GA or w/e.
I used to use Authy and ended up moving to one called "Authenticator Pro" on Android which is open source and seems to working really nicely so far. Encrypted backups too.
piximg image and gallery hosting · fa.to client-side encrypted storage
Android only though.
All of your eggs in one basket. Password manager gets hacked, and everything is there. Versus having to break into two systems, a password manager and a 2FA device. Bitwarden, 1password, LastPass, etc. are SaaS systems which are always on and available. Attackers have a open window to attack them, and on a long enough time line, everyone's survivability drops to zero. LastPass has had breaches in the past, for example.
Yes, a hardware token is better as it is separate from everything, but convenience. Hardware tokens are still pretty new, but they are catching up.
There is no truly secure system, and the goal is to make attackers lives as hard as possible. We make tradeoffs everyday, and its tough to find the balance between ease of use and security.
+1 for Authy, after it happened twice with google, I decided not to take risks anymore.
Readydedis, LLC - Managed Dedicated Servers | KVM SSD VPS | Hypervisor KVM Control Panel
Authenticator roundup over at arstechnica. They like Authy as well:
https://arstechnica.com/information-technology/2020/05/choosing-2fa-authenticator-apps-can-be-hard-ars-did-it-so-you-dont-have-to/
I'm using DUO (https://duo.com) for most of my 2FA and they introduced DUO Restore, where you can reconnect your old accounts https://guide.duo.com/duo-restore
I haven't tried it myself, yet.
“Technology is best when it brings people together.” – Matt Mullenweg
Didn't notice until now that my Google Authenticator was updated with the transfer accounts feature. Thought it wasn't released yet.
Now they just need a backup feature.
ExtraVM - KVM NVMe VPS in USA, EU, APAC -|- RackColo - Find Colo
Metal detector around the trench?
Ya Authy the best
No.
oathtoolis the best, Authy can be a close second thoughI'm late to the party but I highly recommend an open-source solution such as KeePassXC.
Bitwarden is recommended all over the web, but I'm not too fond of it. Yes it looks nice and has all the features you could possibly want from a password manager, but everything comes down to just one developer... There is just one guy doing front-end, back-end, mobile-apps, basically everything, so the under the bus factor is quite high if you ask me.
LinuxFreek.com — Thank you for your attention to this matter
He has been hiring other people recently. About 6 months or so IIRC
That is good to know. I do indeed see quite some (recent) commits from a second guy.
LinuxFreek.com — Thank you for your attention to this matter
He also expanded on Reddit that he has a plan in case he dies or something of the sorts, so the servers won't get abandoned.
And as always, backup your data!
I use Bitwarden CLI (There's also PortWarden) to export my vault, then encrypt the csv/json file and upload/store it somewhere safe.