[0] https://authy.com/download/ (scroll down to see Desktop version for download)
[0] https://authy.com/download/ (scroll down to see Desktop version for download)
I remember when Authy refused to delete my account, prior to their acquisition, despite promising to do so upon request in their terms of service. I wasn't the only one: https://news.ycombinator.com/item?id=9100525
There are plenty of free and open source TOTP authenticators (that don't require you to provide your phone number), and I don't see a good reason to use Authy over them.
You've got a strange definition of "backup" if you think it won't work after the subject of the backup has been destroyed. What would be the point of a backup that stopped working whenever you needed it?
I've been using Authy for a few years, but switched to Aegis about three years ago and couldn't be happier. Since Authy doesn't support direct export of the secrets, I've had to use a workaround [2].
[1] https://getaegis.app/ [2] https://gist.github.com/JacobJohansen/5f688d45049be440b8ee87...
It's "supported" but only via accesing the Authenticator's files (or by havitng root access) which in my celphone is not possible (OnePlus Nord).
Weirdly enough, Aegis does not support bulk importing keys from a QR code, which is how you can migrate from one Authenticator instance to another (e.g. to a new phone).
And I am too lazy to go over each key, reset it and load it up again in Aegis.
Hooefully they'll add this feature at some point in the future.
Aegis does support importing from Google authenticator, it just doesn't make that very clear. You do it the same way you add any other code. The hard part for me was getting the QR code into scannable form. This issue explains one way, but you can also just take a picture of the phone with another device.
To counter this I recommend disabling device sync in Authy, and only enabling it temporarily when you add a new device.
Libraries for a couple of other languages:
#!/usr/bin/env python3
import time, hmac, base64, struct
def totp(seed,curtime,period,len):
k = base64.b32decode(seed)
mac = hmac.new(k, struct.pack('>Q', int(curtime/period)), 'sha1').digest()
offset=mac[-1] & 0x0f
otp=struct.unpack('>L', mac[offset:offset+4])[0] & 0x7fffffff
return str(otp)[-len:].zfill(len)
myseed='KRUGS4ZANFZSAYJAOJQW4ZDPNUQHG5DS' # use gpg or similar to store
print(totp(myseed,time.time(),60,6))https://github.com/tadfisher/pass-otp
Like others have mentioned, it unlike Authy this doesn't use your phone number as identity
Spelling it out usually works: "open A U T H Y".
Pronouncing "au" like the "ou" in "ouch" seems to be about the best, but then it tends to mess up the other end, thinking I want "authi". Sometimes it even think "alfie". Somehow it even occasionally hears "elsewise" or "offline". I have no idea how it gets those.
I now use Aegis on phone and the otp plugin of pass on my Linux desktops (+ a ulauncher plugin).