I don't fw TOTP now. There are other apps, but I'm done. I'll only use it if the iPhone Keychain has built-in support some day.
When a QR code is present on screen that resolves to a TOTP seed, an additional context menu option should be present to "Add Verification Code in Passwords" or "Set Up Verification Code" or similar.
Here's a screenshot I nabbed from a way-too-wordy article on the subject: https://tidbits.com/uploads/2021/10/Add-Verification-Code-15...
I've done it in Aegis multiple times. They even allow you to export the 'database' (which iirc is just an encrypted json file)
0: https://apps.apple.com/us/app/2fa-authenticator-2fas/id12177...
Also, your Yubikey is probably less likely to be stolen or break, but I figure it's much easier to lose it, which is why you might want to have two, just in case. And that's where it gets really inconvenient.
Half the time I choose for TOTP authentication over Yubikey because "Oh god it's in the living room I don't want to go get it."
I do have a backup key mind, but that's USB-C instead of A. Maybe I should make another USB A backup.
On the other hand, you know the second one works and haven't spontaneously bitrotted.
My nerdy preferred version would have been (pre-passkey) to have a hardware token where the root secret is generated out-of-device and exist on e.g a paper backup or something. Then I could just buy a new hardware token and inject the same token if the device dies.
Even if I do have keys, they are safe in my pocket, not sticking out the side of a fragile USB port.
There's then the whole mobile problem -- yubikeys are perhaps fine with my laptop, but how about when I'm using a mobile and my laptop is in my bag, or at home?
And OK, lets say I solve all that. How do I add a second key?
The beauty of SMS for 2FA is that my phone number sticks with me. If my phone is lost or stolen, a new sim card is sent to my home and I have access to all my 2FA authenticaitons. It also ties in well with my phone -- if I get an SMS with a number 123456, it appears as an automatic insert option on the form, no need to go to another app to copy a number and switch back to paste.
TOTP and Yubikeys do not match the usability of SMS.
Even if I do have keys, they are safe in my pocket, not sticking out the side of a fragile USB port.
It's difficult, though not impossible, to break your USB port with a Yubikey due to its shape. It's not a regular USB plug and will come out quite easily. but how about when I'm using a mobile and my laptop is in my bag, or at home?
USB-C and NFC variants are quite common. And OK, lets say I solve all that. How do I add a second key?
The same way you add the first--most of the time, you have to scan a QR code. You can scan it more than once. The beauty of SMS for 2FA is that my phone number sticks with me. If my phone is lost or stolen, a new sim card is sent to my home and I have access to all my 2FA authenticaitons.
I'm not giving you my phone number, and mobile providers are known to send replacement SIM cards to random strangers if they ask nicely.If I ever want to set up a TOTP app on a new device it is not hard to decrypt all my saved QR codes, open them all at the same time in Preview on my Mac, select the option to show one page at a time, and then get into a nice rhythm using one hand to scan on the new device and the other to hit "page down" on the Mac keyboard.
If the site also gives a text form of the shared secret from the QR code I save that too. Having the text form around is handy in case I need to login but for some reason don't have the devices where I have the TOTP apps. Given the text form of the code, this command, from the oathtool package, will give the current login code:
$ oathtool --totp -b "secret"
That's if the secret is encoded in base32, which they commonly are. If it is in hex leave off the -b.If the site doesn't give a text form of the shared secret I read the QR code to get it. If you do that be careful. Some QR code reader apps do the processing server side which you probably don't want...and they don't necessarily make that clear in the description. I had to try a couple of apps from the Mac app store before finding one that did it client side. (Then I found out that Mathematica's BarcodeRecognize function can do it, and deleted the QR code reader app. Now I just open Mathematica, type BarcodeRecognize[], drag and drop an image file that has the QR code between the brackets, and hit shift-return).
Personally, I email the backup codes to myself. Yes it's less secure in theory, but the only time I'm using totp is against my will.
The QR code is on the screen of my desktop Mac. The camera is right above the screen facing me and can't see what is on the screen.
I could read it with the built in camera app on my iPhone or iPad, but that just tells me it is a QR code for the TOTP authenticator app I use and opens that if I tap. I don't see a way to get it to tell me the content of the QR code in text form. Even if it had a way that would be on the phone and I want the text to save it on the Mac.