Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why not use an open TOTP app like AndOTP. I use it all the time for sites that claim to require Google Authenticator, it works, and its easy to backup the secrets as plain text or encrypted with a password. I keep it current on my primary phone and a cheap offline backup, in addition to backing up the encrypted secrets file.


I use Authy on iPhone and Mac. I am looking for an OSS replacement but would not want to setup everything from scratch after I change device reinstall the app like Google Authenticator.


https://freeotp.github.io/

iPhone backups back up its data correctly—my codes survive new phone restores where they do not with Google Authenticator.


Thanks for sharing this link.

I've wanted to get off Google Authenticator for awhile now, mostly because of the backup-restore problem, also a general trend of limiting my involvement with the company.


Bitwarden does a decent job of storing and syncing TOTP codes. Make sure you always use a long password with Bitwarden though, to avoid a known and unpatched issue with their password-based key derivation.


Oh, didn’t know BitWarden did it. That’s my password manager :)


What issue is that?





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: