One more step to unhitching from Google…

Right now the only option I see in F-Droid is Aegis.

I’m not sure what to actually look for side from checking for unexpected permissions and reasonably frequent updates.

Hopefully something I can sync with a GNOME app…

    • TedZanzibar@feddit.uk
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 days ago

      It’s niche but I like to point it out whenever I get the opportunity: if your workplace uses Bitwarden Enterprise, every licensed user gets a free family plan that can be linked to any account. I haven’t personally paid for BW for years.

    • HereIAm@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 days ago

      Same. Self hosting it sounds nice, and I self host a handful of services, but I don’t want to be stuck without passwords in another country with a dead server at home because a power cut happened at some point.

    • Lyra_Lycan@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      11 days ago

      As I’ve seen gaming server subscriptions go from £36/y to £23/m (Xbox) in a few years, and cloud CCTV storage from £40/y to £16/m (Google via acquisition of Nest) in a few months, I say we count our stars when a subscription cost remains fair.

      • Lucy :3@feddit.org
        link
        fedilink
        English
        arrow-up
        5
        ·
        edit-2
        11 days ago

        Tbh, if you’re using the same DB for PWs, you’ve successfully downgraded to 1FA now. Except maybe if you use a seperate KeyStick/Yubikey as secret bearer or smth

        • hikaru755@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          11 days ago

          More like 1.5FA, at least. It still protects against passwords being compromised in any way that doesn’t compromise full access to your password database, which is still a lot better than using just passwords without a second factor.

          • example@reddthat.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            11 days ago

            that’s like calling strong randomly generated passwords 1.5FA.

            with proper MFA, even if you steal my password (database), you won’t be able to steal my account, as you’re missing the second factor. with classic otp this is just a single use number you enter on the potentially compromised system, but if you get the seed (secret) stolen, valid numbers can be generated continuously.

            password managers (should) protect against reuse. MFA protects against logins on untrusted and potentially compromised systems/keyloggers if they’re not extracted live. password managers with auto fill and phishing resistant MFA can prevent phising, although the password manager variant is still easily bypassed when the user isn’t paying enough attention, as it’s not even that uncommon for login domains to change. obviously there are also other risks on compromised devices, like session cookie exfiltration, and there is a lot of bullshit info around from websites, especially the ones harvesting phone numbers while claiming to require it for 2FA just to gaslight users.

            • hikaru755@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              10 days ago

              even if you steal my password (database)

              That’s a big leap you’re doing there, equating stealing a password to stealing a password database. Those are very different. Stealing a password can be done through regular phishing, or a host of other methods that don’t require targeted effort. Stealing a password database, if properly set up, is a lot harder than that. It depends of course on what password manager you’re using, but it usually involves multiple factors itself. So equating that to just a password, no matter how strong and random, is just misleading.

              Mind you, I agree that it’s less secure than “proper” MFA, and I’m not saying that everybody should just use MFA through a PW manager. I am using physical security keys myself. But for a lot of regular people that otherwise just couldn’t be bothered, it’s absolutely a viable alternative that makes them a whole lot safer for comparatively little effort. Telling them they just shouldn’t bother at all is just going to create more victims. There is no such thing as perfect security, and everyone has a different risk profile.

    • BingBong@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      11 days ago

      Definitely this, especially if you’ll be sharing with a non techie. My wife was able to pick 1password up and use it immediately and she normally turns her nose up at any of my recommendations.

      For the 1password accounts 2FA, use a yubikey or aegis. Everything else to 1 password.

  • AMillionMonkeys@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    12 days ago

    Bitwarden Authenticator because Bitwarden seems to have a good reputation. I don’t use their password manager, though.
    It does seem faintly insecure that it displays all of the codes at once on one page, but I’m having trouble imagining a scenario where it’s actually a problem.

  • zingo@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    5
    ·
    11 days ago

    Aegis.

    I like the auto backup feature (encrypted) . Then the backup is synced to computer via Syncthing.

    Set and forget setup.

  • example@reddthat.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    12 days ago

    FreeOTP/FreeOTP+

    depending on your goal for this (real 2fa vs just simulated) you shouldn’t have sync in the first place.

    you could also look into security keys (hardware solution, webauthn/FIDO2) as an alternative that has strong security with good user experience (no typing anymore), but they’re not as widely accepted.