Aegis Authenticator – Secure 2FA App for Android
getaegis.app
getaegis.app
1) I prefer to use OSS when possible
2) Aegis supports import/export/backup - so if I get a new phone, I don't have to spend days setting up my dozens of accounts again! This also means I can setup the same OTPs in both Keepass and my phone, so I can always get into my accounts
I'm really liking it, it does the same job as the Google and Microsoft Authenticator apps, but import/export/backup means it's more usable
Aegis gives me the actual seed, full control of the data so I can do with it as I please.
It's not clear to me if Aegis allows this somehow?
The other day I broke my phone. I was traveling and needed to do some 2FA level changes to a GH repo asap.
I didn't even know there was an Authy desktop app until then. It saved my ass, literally.
I don't add new keys particularily often, so it isn't that big of a hassle two manually sync the authenticators.
It's also a lot easier to wear around your neck.
Also easy enough to maintain a keepass[xc] vault for totp secrets, you could keep a separate one from your passwords if you were feeling paranoid. Great support on mobile and desktop for using a keepass db as a TOTP source - and easy to sync with dropbox/email/ssh/your web server/whatever
Anyways, people should think about these risks when dealing with 2FA: flood, fire, stolen, lost, (I) broke (Smartphone, yubikey, usb, etc), broke (itself), software bug, kids, washing machines, etc.
anyway I wouldn't but s Yubikey for TOTP. OTP sucks. Sure it's better than no 2FA and TOTP is better than SMS OTP still it's not grate.
WebAuthn-like auth can provide all the benefits of TOTP while being way more secure and in some cases even not convenient.
The main drawback is how to backup your 2FA which makes it less of a choice for a "casual" user.
I am currently carrying 2 tokens :(
https://support.yubico.com/hc/en-us/articles/4404456942738-F...
I guess I need a new one, but what I want to say is don't rely on a single Yubikey or even two. Do have backups.
The single-tap and long-tap don't produce expected output? Can you share more info on it?
I own many Yubikeys (due to research I've been doing in 2017.) and I had many Yubikeys to play with, for TOTP/HOTP/U2F purposes, even using it to unlock Windows and I haven't had a case of a Yubikey basically deprogram itself. I washed them in the washing machine, ran them over with my car, thew them in mud piles and they always worked without a fault so your case is a surprising one.
Judging by what you wrote, unless there's some weird NFC communication going on between your phone and Yubikey (are they in proximity?), I'd say it's faulty and you need a new one.
After adding a site or a computer it works a few days and then suddenly when I try to use it with my phone or computer I just get an error about no <something>.
So yes, probably defective.
Btw. this is the first time I've read on a public forum that someones Yubikey is defective, they are really well made and I didn't manage to break one via regular use and bad maintenance.
That's a really unexpected outcome - can you provide any details ?
I installed Authy desktop, logged in and it retrieved my tokens form the cloud. Not anything else to it.
That word changes the meaning of the phrase in front of it quite a bit.
I once lost my Authy app data and didn't have it installed on any other of my devices (silly requirement tbh). I don't know whether cloud or 2FA is the joke here but Authy slapped me with a 24hr wait time for a "device reset".
The exported file can be encrypted when you make it.
I need to do that every time and remember.
From my experience, you loose access when the last backup you made and synced was made before the key you need now was added.
I.e. this doesn't work in practice.
The first lets you back up your data to any folder on your device or to any storage provider (e.g. Nextcloud and other cloud storage providers) linked to your device. Turn this on at Settings > Backups > Automatically back up the vault. The storage provider's app needs to be installed. Changes are saved to the backup location automatically.
The second uses the OS's built-in backup feature. For Android devices with Google Play Services, the backup is saved on Google Drive. Some other Android distributions such as LineageOS use Seedvault, which can save the backup to any WebDAV provider or an external USB drive. This option is at Settings > Backups > Participate in Android's backup system.
Either or both options can be used in Aegis.
In fact, KeePassium on iOS works on this concept. I use it as my primary otp url storage app and then put limited stuff into aegis on my android tablet for anything I may need there. If a keepass based app with an otp generator (like KeePassium) existed for android, I wouldn’t even need that.
https://github.com/beemdevelopment/Aegis/blob/master/docs/de...
https://www.yubico.com/products/yubico-authenticator/
That avoids keeping the seeds somewhere a general attack could get (and requiring a tap complicates attacks) and works across all of my devices. The main drawback is that there isn’t an easy way to install a seed on multiple keys when first enrolling.
How well does it work on mobile? Totp via app, tap the nfc key to the phone?
And what does "no easy way" mean, how involved is that process? I’d prefer to have the keys on all 3 (or 4, not sure if the security key allows TOTP) sticks.
If you wish to have the same TOTPs on multiple YubiKeys, you are recommended to take a screenshot of the QR code you're given at the beginning (which contains the secret key), and manually add it to all the backup keys you prefer, and then securely erase the screenshot.
further reading: https://support.yubico.com/hc/en-us/articles/360013789259-Us...
I initially thought the codes were stored on my phone and the key was only required for access, but that's not the case.
That's either a benefit or a drawback, depending on your threat model, but it's definitely something people should understand.
"No easy way" basically means that you either have to save the seed and repeat the setup process for your backup key or enroll two separate devices if allowed. It feels like the authenticator app could have a useful addition where it'd automate that for you if you have two keys present.
With Syncthing, 'gopass' and 'Android Password Store', I have a fully open source, very easy to reason about fully in my control, password and totp storage, accessible on all my devices. All of which can only be accessed with my Yubikey that I keep in my pocket and my GPG PIN.
I hope what you meant to say is that you are switching to using WebAuthn with your yubikey on all sites that support it, and then using your yubikey for TOTP on sites that don't support WebAuthn yet. WebAuthn is the thing that gives you actual protection against phishing.
I wish F-Droid or Play Store had a feature like GitHub's 'Archived' to inform users.
Looking at Aegis, it appears to support importing from andOTP
Besides, if you dont have a physical and digital backup of your TOTP seeds you really like to live dangerously.
there is a base case somewhere in a backup strategy where TOTP is not feasible. The base case for me is "Keepass file backed up to multiple locations and my master key written down in an envelope in my house in case I hit my head".
Why would I lock my passwords away behind a TOTP that can get lost? My TOTP in Authy is protected by a long random key. Where do I store the key? In my password manager.
You can't use a password manager and TOTP to back each other up.
I treat my kdbx as a single password encrypted backup of my bitwarden vault on my computer and external hard-drive.
I care much less about second factor if it's something offline on my computer than something accessible by a web interface to anyone in the world.
If the individual site allows backup codes, I agree.
But you first need an app that hosts your TOTP that has exportable secrets.
This is because every access to Bitwarden requires two factors: a device I've already logged in with, and either the passphrase or a biometric unlock. Bootstrapping a new device requires the passphrase and a token.
Reconnected via the Storage Access Framework and backups are syncing!
Thank you, alexbakker
https://f-droid.org/docs/Inclusion_Policy/
Aegis Authenticator passed F-Droid's checks. It has no anti-features:
https://f-droid.org/en/packages/com.beemdevelopment.aegis/
Aegis doesn't even request the internet permission. Compare that with Authy, which logs users' IP addresses, login activity, phone numbers, and email addresses, and states that users' data and personal information will be shared with third parties for any reason Authy wants to:
https://www.twilio.com/legal/privacy/authy
Twilio has had 2 data breaches this year, and the second one involved Authy. Since Authy does not use end-to-end encryption, hackers were able to obtain 2FA credentials from any Authy account, and they compromised the accounts of 93 Authy users:
https://techcrunch.com/2022/08/26/twilio-breach-authy/
On top of that, Authy is closed source and its code has never been audited, not even by F-Droid. There is no way to use Authy without sending your personal information to a service that states it will not promise to keep it private.
There is no good reason to trust Authy over Aegis.
> When you use our app we collect: Your phone number, device information, and email address.
> When you use an Authy token to log into an account, whether the token was generated on the app or one sent to you via your phone number, we collect and keep information associated with your login activity including information like your IP address, what application or program you logged in to, that you logged in, and when. If you change your phone number or email associated with your Authy account, we will also keep a log of that. We collect this information to monitor for suspicious activity and also as another piece of information that could be used to verify your identity if your account is compromised or may be compromised.
> We also share your information with our third party service providers as necessary for them to provide their services to us. We may also have to share your information with third parties if required to do so by law.
> Your information will be transferred to the U.S.
> Your personal information may be transferred to the United States, and possibly other countries where we or our service providers operate.
> In addition, we may share your information with third parties as follows: Compliance with Laws. We may disclose your personal information to a third party if (i) we reasonably believe that disclosure is compelled by applicable law, regulation, legal process or a government request (including to meet national security or law enforcement requirements), (ii) to enforce our agreements and policies, (iii) to protect the security or integrity of our services and products, (iv) to protect ourselves, our other customers, or the public from harm or illegal activities, or (v) to respond to an emergency which we believe in good faith requires us to disclose personal information to assist in preventing a death or serious bodily injury.
> Business transfers. If we go through a corporate sale, merger, reorganization, dissolution or similar event, personal information we gather from you may be part of the assets transferred or shared in connection with the due diligence for any such transaction. Any acquirer or successor may continue to use the personal information as described in this notice.
https://www.twilio.com/legal/privacy/authy
I would trust Aegis over Authy any day. As you can see from the source code, Aegis does not expose users to these privacy risks. Even though Aegis has automatic encrypted backup features, Aegis itself does not request the internet access permission.
https://docs.sendgrid.com/ui/account-and-settings/two-factor...
For anyone shopping for an email provider, this would be one reason to choose a provider other than SendGrid.
Recently moved all of my TOTPs to it. Encrypted iCloud sync and local backup if desired.
I believe I discovered a bug in the app: if you long press a secret > edit > leave an empty string as the comment, and then export a QR code containing this secret, your other device will fail to import ("QR code cannot be interpreted.").
I've only seen this happen with secrets where the comment is put in parentheses and appended to the regular, immutable name of the secret. There's another type of secret where the entire name can be edited, this I did not test. But if you try the import/export flow on a secret whose name contains `()` I bet you'll hit the bug.
I briefly tried Aegis but you must have Aegis+Authenticatior installed, and be root, or you can exfiltrate Authenticator's database file from private storage, which best as I can tell, also requires root. Shouldn't have gone with Authenticator at all, I've learned.
It seems optimal to simply retain the original secret (QR code or whichever medium) you are given when 2FA is initially enabled.
Later found this equivalent: https://mattscodecave.com/posts/how-to-move-from-google-auth...
Since I have emacs on everything, including my phone, it's not a bad solution for my purposes.
I recommend it everytime I see someone popping out a Google authenticator or alike.
The only thing Aegis lacks is a donate button or a paid version just for supporting its development.
I'm anticipating this tool will soon be ripped apart with ads, data leakage, an acquisition, or a premium version that will just break what it does very well until now.
I'm enjoying it while it lasts :)
Yubikeys, Ledgers, Trezors, Nitrokeys, Mooltipass, Precursor, QubesOS Vault... There are so many solutions that avoid exposing your 2FA secrets in plaintext to the system memory of an internet connected device.
The more exciting thing I learned here is that I can backup my entire GrapheneOS phone to my Nextcloud server for recovery. I just go into Android settings->Backup to get started. This will save me a lot of time the next time I lose my phone. Thank you!
edit: Also, it allows (after checking the "I know what I’m doing" warning) plaintext secret export, if you want that for some reason.
Importing to Aegis afterwards was quite straight-forward.
[1]: https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d...
So neither your injury nor account access would be in you priority list.