It's not clear to me if Aegis allows this somehow?
The other day I broke my phone. I was traveling and needed to do some 2FA level changes to a GH repo asap.
I didn't even know there was an Authy desktop app until then. It saved my ass, literally.
It's not clear to me if Aegis allows this somehow?
The other day I broke my phone. I was traveling and needed to do some 2FA level changes to a GH repo asap.
I didn't even know there was an Authy desktop app until then. It saved my ass, literally.
The first lets you back up your data to any folder on your device or to any storage provider (e.g. Nextcloud and other cloud storage providers) linked to your device. Turn this on at Settings > Backups > Automatically back up the vault. The storage provider's app needs to be installed. Changes are saved to the backup location automatically.
The second uses the OS's built-in backup feature. For Android devices with Google Play Services, the backup is saved on Google Drive. Some other Android distributions such as LineageOS use Seedvault, which can save the backup to any WebDAV provider or an external USB drive. This option is at Settings > Backups > Participate in Android's backup system.
Either or both options can be used in Aegis.
It's also a lot easier to wear around your neck.
Also easy enough to maintain a keepass[xc] vault for totp secrets, you could keep a separate one from your passwords if you were feeling paranoid. Great support on mobile and desktop for using a keepass db as a TOTP source - and easy to sync with dropbox/email/ssh/your web server/whatever
Anyways, people should think about these risks when dealing with 2FA: flood, fire, stolen, lost, (I) broke (Smartphone, yubikey, usb, etc), broke (itself), software bug, kids, washing machines, etc.
anyway I wouldn't but s Yubikey for TOTP. OTP sucks. Sure it's better than no 2FA and TOTP is better than SMS OTP still it's not grate.
WebAuthn-like auth can provide all the benefits of TOTP while being way more secure and in some cases even not convenient.
The main drawback is how to backup your 2FA which makes it less of a choice for a "casual" user.
I am currently carrying 2 tokens :(
https://support.yubico.com/hc/en-us/articles/4404456942738-F...
I guess I need a new one, but what I want to say is don't rely on a single Yubikey or even two. Do have backups.
The single-tap and long-tap don't produce expected output? Can you share more info on it?
I own many Yubikeys (due to research I've been doing in 2017.) and I had many Yubikeys to play with, for TOTP/HOTP/U2F purposes, even using it to unlock Windows and I haven't had a case of a Yubikey basically deprogram itself. I washed them in the washing machine, ran them over with my car, thew them in mud piles and they always worked without a fault so your case is a surprising one.
Judging by what you wrote, unless there's some weird NFC communication going on between your phone and Yubikey (are they in proximity?), I'd say it's faulty and you need a new one.
After adding a site or a computer it works a few days and then suddenly when I try to use it with my phone or computer I just get an error about no <something>.
So yes, probably defective.
Btw. this is the first time I've read on a public forum that someones Yubikey is defective, they are really well made and I didn't manage to break one via regular use and bad maintenance.
That's a really unexpected outcome - can you provide any details ?
I installed Authy desktop, logged in and it retrieved my tokens form the cloud. Not anything else to it.
That word changes the meaning of the phrase in front of it quite a bit.
I don't add new keys particularily often, so it isn't that big of a hassle two manually sync the authenticators.
In fact, KeePassium on iOS works on this concept. I use it as my primary otp url storage app and then put limited stuff into aegis on my android tablet for anything I may need there. If a keepass based app with an otp generator (like KeePassium) existed for android, I wouldn’t even need that.
https://github.com/beemdevelopment/Aegis/blob/master/docs/de...
I once lost my Authy app data and didn't have it installed on any other of my devices (silly requirement tbh). I don't know whether cloud or 2FA is the joke here but Authy slapped me with a 24hr wait time for a "device reset".
The exported file can be encrypted when you make it.
I need to do that every time and remember.
From my experience, you loose access when the last backup you made and synced was made before the key you need now was added.
I.e. this doesn't work in practice.