Aegis v3.0 – a free, secure and open source 2FA app for Android
github.com
github.com
If you use Aegis on Android and use a Gnome-based Linux distro, I highly recommend complementing with Gnome Authenticator[1][2][3][4].
flatpak install flathub com.belmoussaoui.Authenticator
Gnome Authenticator is still a little early and buggy (mainly performance issues when you have lots of tokens), but it can import and export Aegis format (and a few others). It's been downright luxurious having my seeds on my phone and my laptop and desktop.[1] https://gitlab.gnome.org/World/Authenticator
[2] https://flathub.org/apps/com.belmoussaoui.Authenticator
[3] I think (I hope) that Gnome Authenticator will be distributed as part of Gnome at some point in the future, but it isn't yet
[4] It's also super easy to build and run from source using Gnome Builder[5]. Just open Builder and clone the source from gitlab, and click the "Build" button and it will do its thing
The same is possible for my iOS tool of choice (called "OTP auth"). It can also synchronize to iCloud (passphrase encrypted) and make use of that on macOS.
I've resisted the temptation of that comfort so far (and of just putting the TOTP seeds into Bitwarden or 1Password), because it does seem a lot like collapsing what's now definitely two or maybe three factors into two or sometimes only one.
I still can't bring myself to put them into bitwarden, though. I suspect that will be a line I refuse to cross for quite some time, even though the convenience and luxury of doing so is tempting. Having my seeds in the cloud to me definitely reduces a factor
If this were my concern, I would just build from source as it is quite easy to do with this project.
2FA protects you mainly from password leaks, not from people phisically accessing your devices.
To each their own though, and everyone has a different level of risk, and a different level of risk tolerance. With all security, it comes down to an evaluation of that. I know some people in a very safe area who don't even lock their car or their house. They have not had any issues, and it can be very convenient not to have locks. That security posture is not for me, but it works for them.
I'm going to probably gnome authenticator on top of WSL2, because I like monstrosities.
2FA traditionally means relying on one thing you know (i.e. a password) plus one thing you have, or one thing you are (biometrics).
Every single one of my passwords is unique and randomly generated and at least 32 characters, none of them are getting brute forced unless there is a sudden gigantic leap in quantum computing. And if that happens, the world has bigger problems than my passwords.
Having a separate identity factor, something that I own, is not to save me from myself. It's to save me if someone steals my phone or laptop and is able to get into it.
Now we all face different threat models and if your threat model doesn't call for having a totally separate identity factor, great! There's nothing wrong with that. But we don't all face your threat model, and some of us do indeed need a second identity factor that's not stored in the same place as the password.
One of the threat models that I consider is there being a bug in the particular RNG/encryption algorithm implementation used to get that encrypted password. In that case, my password can possibly be brute forced much faster than purely random guessing.
What if that second factor is physical and stolen along with the things it was supposed to protect? What if your biometrics are cloned in some way?
Having TOTP synchronized across devices, but protected by passwords mitigates those risks as well as the risk that you lock yourself out by loss of a physical token.
Nearly all of my 2FA are in Bitwarden, because it's just so damn convenient. But my Bitwarden itself uses YubiKey as 2FA.
Since I adopted this setup last year, it's been the best if both worlds for me.
I want to do the same but haven't switch yet.
- Is the YubiKey USB-C? Is the connector type an issue when plugging it into various computers?
- Where do you keep your YubiKey (plugged into your laptop, on a keychain, somewhere else).
- How do you open your vault on mobile?
- Do you have a backup YubiKey somewhere in case you lost the main one?
- 2fa is still good for stopping someone who steals your password but not your whole vault - 2fa blocks people from guessing your password (through brute force etc)
So there is still quite a bit of benefit.
Anyway, I do (involuntarily) use 2FA for two services, and managed to set myself up with Google Authenticator on my Android phone. Both services that onboarded me for this explained it really poorly, but at least got me hooked up and I now routinely (and reluctantly) login to those services this way. Reading this I suddenly realised, whoaaa, if I lose my phone do I lose access to those (important) services? Well no, I hope not at least, when I look at the Authenticator app it has the green "your codes are being saved to your google account" cloud icon. That's kind of reassuring. I suppose.
I'm not really sure what my point is, other than online security is an ever more important issue, it's a swamp and even many technical people who might know everything there is to know about some arcane corner of the technology universe don't necessarily properly understand it. Although I suspect most would not be prepared to admit it like I just did. Actual normal people (like my wife for example) have absolutely no chance of getting on top of the details and navigating their way to a best practice solution. I hope Google (or Apple) don't either give up on this or go full evil, that would be really bad.
I think I will check out whether my two services can give me recovery codes. I am confident I can manage vital username/password combinations and recovery codes, that's the level of sophistication (or not) I'm comfortable with in this space.
Microsoft is trying to make the untrue. If your job uses office 365 you are forced to use Microsoft authenticator by default.
Embrace, extend, extinguish is etched in their company DNA I guess.
It is a shame how the industry seems to think that security is some single dimension along which things are more or less secure. Denial of service for personal accounts is often times more damning and common than account compromise. 2FA makes me less secure in some cases.
I have only one, and its frustrating. I know it's probably breakable with rooted Android or something but haven't had much time to look into it (or fight it)
[0] Vaultwarden
Just a different kind of insecure.
It is more than a bonus. This is the only kind of project you know that tomorrow, the day after or a year from now there wouldn't have profit incentives or a pending IPO to completely abuse your experience as a user and extract as much profit as possible.
I hope others don't follow Microsoft Authenticators footsteps in creating their own Authenticator, saying others are insecure, and not allowing Authenticators like Aegis.
Can you do an encrypted backup on demand (protected with a password you supply)? Is there any desktop app such backup can be opened/read with (or even eg. read with something like sqlite db browser)? Can the app be configured to save an encrypted copy to eg. Dropbox whenever changes are made?
Is it recommended to install from Play store, or the APK off GitHub?
> Can you do an encrypted backup on demand (protected with a password you supply)?
Yes!
> Is there any desktop app such backup can be opened/read with (or even eg. read with something like sqlite db browser)?
It's just plain JSON once decrypted, so it's always readable; I do know the GNOME Circle app "Authenticator" can natively import Aegis backups as well, since it's what I use on my desktop machine, but I don't know what other apps exist.
> Can the app be configured to save an encrypted copy to eg. Dropbox whenever changes are made?
It does have some facilities for automatic and cloud backups judging from the settings page, but I've never tried them
> Is it recommended to install from Play store, or the APK off GitHub?
If you do the latter you'd lose automatic updates. I used F-Droid.
Obtainium[1] will give you automatic updates from most sources, including Github/Gitlab/Codeberg and F-Droid repos. Especially relevant to this discussion, since Aegis 3.0 hasn't hit F-Droid yet, as at the writing of this comment.
Apples UI design was never my cup of tea, but I love the consistency of UI design in most iOS apps, compared to the wild UI inconsistencies on Android.
That being said, I feel like the main complaint about Android apps design is the fact that a lot of apps are just horrible half-assed implementations of old Material UI slapped together on a drag and drop editor like the Android Studio widget system. Offering an incentive for people to build anything and make money off data collection and ads without the corporate tyranny of Apple results in just that. So apps that are on FOSS repositories such as F-Droid are usually much cleaner to use, despite their UI/UX being just as diverse.
Though I only use FOSS apps so I can't speak for the playstore apps.
[1]: https://2fas.com/
I hope it's possible to import my otps from andotp into aegis. Also the backup encryption with gpg (openkeychain) is welcomed.
The good news is that migrating to Aegis is quite simple. Export from andOTP, in Aegis go to Settings -> Import & Export -> Import from File, & choose andOTP. Pick your file and away you go.
It doesn't seem to have a database of icons like andOTP does though; none of my imported items show an icon though several did in andOTP. (Could this be because of the method they were added?)
[0] https://xdaforums.com/t/unmaintained-app-4-4-open-source-and...
When I lost the app data to a phone reset, I also lost my 2FA tokens. Got lucky I didn't have many tokens saved at the time and was able to restore all the important accounts despite losing the tokens. Even though it was my fault for not reading the T&C of the Google Authenticator app, I cursed Google for creating an inferior product on an OS they controlled. What was the use of requiring login with a Google account on the Android device if you are not going to persist this kind of data.
Then I moved to Authy which syncs and stores your tokens online to their cloud, allaying all the fears I had from previous experience. Incidentally another phone reset happened.
Now Authy allows you to access your tokens "locally" to any device that can install their app or browser extension. Using more than one "device" locally gives you data redundancy.
I cannot just trust a browser extension with my 2FA tokens (yikes), so at the time I only had my Android device with the tokens locally. When this "trusted device" (read app data) was lost I had to request support for a reset to gain back my data from Authy. That process takes 48 hours after initiating the reset.
(The app data counts as a device, not the other way around; this is the crux of my problem with 2FA application design.)
As soon as I got my tokens back I moved to Aegis and never looked back. I can export backups, save them encrypted on any location and import them anytime without fear of losing app data aka device.
I use it for nextcloud, github and my microsoft account (it was really buried in the settings but it is possible to avoid using MS auth something app).
Using the phone to authenticate every login seems very inefficient.
Some of us do not like using the phone.
There should be desktop authenticator software. If I can have one on Linux I'm sure all the other desktop OSs have at least 1.
The users that are left behind in the browser extension approach are those who need TOTP for non-web things like SSH.
Happy user of https://authenticator.cc/
FreeOTP: https://freeotp.github.io/
Does anyone know the history of this project? It seems legit but an authenticator is a pretty sensitive application so making sure this app is trustworthy is a little more important than for other apps.
You should use separate services.
If your password manager is breached, at least the infiltrator cannot pass 2FA.
https://github.com/dlenski/python-vipaccess https://gist.github.com/jarbro/ca7c9d3eebba1396d53b4a7228575...
I use both plus Syncthing to automatically backup my vault to the pc. Great combo!
Any particular reason/benefit(/con or breach of Authy), other than being FOSS (which I do see as a benefit)?
Support Steam authenticator (if you follow the guide how to get the key).
You can group the MFA provider in groups that make sense to you.
You're in full control and the keys never leave your device unless you want to.
You can see the keys whenever you decide.
And the list goes on. I've been using it for years and it's the best MFA app on the market.
There are unofficial solutions for backup, but who knows when those will stop working.
[1]: https://twitter.com/RaivoOTP/status/1683372954002808833
Authy is discontinuing their desktop app...
From then on I started moving my company's team and contractors (as well as family and friends) off of Google Auth and onto Aegis. The app is clean, easy to use, open source, has all the options we could dream off. (and its privacy policy isn't tens-of-pages-long like some other apps, where privacy seemed to be part of the marketing strategy but not the product itself)
I've been a very happy user.
[0]: https://news.ycombinator.com/item?id=35690398
It looks like Google didn't make clear what was happening... There are almost no settings in Authenticator and there is no place to turn "cloud backup" on or off. I found this article that described the feature when it rolled out.
https://www.bleepingcomputer.com/news/google/google-authenti...
If the screenshot is accurate, they blocked access to the tool until "consent" was given to backup codes to Google. The text itself is clear in retrospect but, in my opinion, implies that there will be a choice to backup to Google and that choice was never presented.
"Google Authenticator is Upgrading... You can now sign into your Google Account and backup your Google Authenticator codes to the cloud."
A button is presented labeled "Get Started" and, if you click it, Authenticator will backup all of your codes to the cloud.
I don't remember being presented with this screen but I don't remember a lot of things. I suspect I needed to get a code and simply clicked the button to get to the list of codes. If I read it, I likely thought there was a new setting and I could manage this "backing up" from there. Clearly this was not the case and I "consented" to let Google have all of by 2FA codes.
I remember getting tripped up by this, because I also have work credentials in there that by policy I'm not supposed to store in a synchronizing TOTP client, and Google Authenticator didn't even allow reviewing the TOTP seeds for the longest time, so this seemed like quite the departure from their previous security stance.
Retool points out the "attacker was able to navigate through multiple layers of security" [0], i.e.:
1. "through a SMS-based phishing attack" on "Several employees"
2. "one employee logged into the [SMS phishing] link", "logging into the fake portal"
3. "attacker called the [phished] employee" "and deepfaked our [IT team] employee’s actual voice"
4. "the [phished] employee grew more and more suspicious, but unfortunately did provide the attacker one ... (MFA) code" (over the call)
5. "The additional OTP token shared over the call was critical, because it allowed the attacker to add their own personal device to the employee’s Okta account, which allowed them to produce their own Okta MFA from that point forward."
6. "This enabled them to have an active GSuite session on that device." With "Google Authenticator synchronization feature that syncs MFA codes to the cloud", "if your Google account is compromised, so now are your MFA codes".
By #5, I'm thinking GA sync is about as blameworthy as Okta for allowing a device to be added with just a single additional OTP token shared over a phone call?
Here's a different perspective (tptacek) [1]:
>> We use OTPs extensively at Retool: it’s how we authenticate into [Google, Okta, internal VPN and Retool]
> They should stop using OTPs. OTPs are obsolete. For the past decade, the industry has been migrating from OTPs to phishing-proof authenticators: U2F, then WebAuthn, and now Passkeys†. The entire motivation for these new 2FA schemes is that OTPs are susceptible to phishing, and it is practically impossible to prevent phishing attacks with real user populations
> TOTP is dead. SMS is whatever "past dead" is. Whatever your system of record is for authentication (Okta, Google, what have you), it needs to require phishing-resistant authentication.
> My only concern is the present tense in this post about OTPs, and the diagnosis of the problem this post reached. The problem here isn't software custody of secrets. It's authenticators that only authenticate one way, from the user to the service.
I don't think anyone would seriously claim that, but I think it's fair to call it an unfortunate additional hole in the swiss cheese.
> Google Authenticator started syncing secrets to the cloud[0] which means that those secrets can now be accessed in new ways outside of the user's control[1], which resulted in a huge breach at a startup called Retool[2].
An important question on this, if you don't mind:
If the phone, where Aegis was installed, is dead/lost/stolen, which options are available to make sure that access to the accounts linked to that phone wouldn't be lost either?
[1]: https://support.google.com/googleone/answer/9149304?hl=en&co...
At that point, I might as well store the TOTP seed there and rely on its multifactor authentication – which is probably fair for many use cases, but suffers from the problem outlined by GP.
I think sites should treat TOTPs effectively equivalent to Passkeys, i.e. as maybe synced, maybe backed up, but maybe neither – and then the user needs an alternative login method, just like for all 2FA methods.
The rest are generally more sophisticated users, and are willing to risk loss of the entire account if they lose their credentials. That's the price for an overall increase in account security. From this perspective, it makes sense to provide backup codes as another tool in the DIY account-management toolbox.
These buckets oversimplify the situation, but they help explain why backup codes are offered as last-ditch authentication for 2FA.
It would have been so much more comfortable if we flipped this around a little - the website would present a QR code, you would open the phone and scan the code, the phone would make a request signed with your key to a URL, and the website would authenticate you because by making this signed request you proved that "something you have" part is done.
It feels like when the 2FA thing started no one considered that sooner or later all services will require it, and the UX will be terrible.
Passkeys could be coupled with Web Push somehow, for a "confirm action x" type of experience pushed to your (networked) authenticator even when you're not at the website of the relying party that owns it.
I believe Steam Guard already added the scan QR code flow a while ago?
if you run safari and store all your passwords using icloud “passwords”, safari will automatically prefill the 2fa code. i assume this is the case for other browsers as well?
I just click search and type 2-3 characters and most of the time I can see what I need right away. I'm using way over 20 services with 2FA and that's really the least of my concern.
And I actually don't use search that much since Aegis also has a feature of sorting by the usage so whatever I'm using regularly are already at the top for me.
This has two things about it that make me actively not want it:
1. Does not work offline (requires an internet connection to work). The current design for TOTP is super flexible as they only require time syncronization, which doesn't require an internet connection.
2. It means I have to install an app for each service, which I absoulutely do not want to do. I would prefer to only use native apps for things that actually need to be native. PWAs and web UIs are strongly preferred for me. A comprehensive and robust way to manage permissions would mitigate my dislike for native apps somewhat, but this is getting harder and harder (though praise be unto GrapheneOS for their efforts!)
From an engineering perspective, it also feels like unnecesary bloat/complexity and coupling.
As for the 2nd point - I definitely don't think it has to be a separate app for each service. Why would it? Imagine an app that holds a private key, the website showing a QR code, you scan it with the app, the app sends the public key to the service using a URL provided in the QR code, and the service stores your public key. From now on, every time you want to login you're asked to scan a QR code, which makes the app send a signed request to the a URL encoded in it. The service gets the request and proceeds with the login. One app, all services.
There's plenty of other reasons not to use SMS 2FA, but it might suddenly not work one day right when you need it, and totally out of your control, is perhaps the most universally compelling?
There are so many problems with SMS.
What if the website presented a QR you can scan with Aegis and then Aegis would make a request with your one time code? You could still type it manually - there would be an input and a QR code next to it.
If you ever encountered a TOTP form in your browser that the LastPass browser extension recognised it would send a push notification to the aunthenticator app on your phone which if approved would send the TOTP code to your browser and submit the form on your behalf.
Unfortunately it only ever worked on the handful of websites Lastpass had implemented bespoke support for, but it was magic when it worked. It would be nice to have a universal standard for push notification 2FA.
WebAuthN essentially gives you that behavior, with the addition of making it MITM-resistant (which TOTP isn't). It even works cross-platform these days (I think both devices need Bluetooth as a proof-of-proximity, to make sure an adversary isn't relaying you a QR code).
Unfortunately both iOS and Android absolutely insist on syncing these credentials to the cloud, but both now have APIs that would allow a third party to provide a local-only backend.
exactly :(
I wish passkeys get rolled out quickly across all sites, most people use just 2 or 3 trusted devices 99% of the time.
for those edge cases where you are working on an untrusted device, the passkey on your trusted mobile can help with authentication via Bluetooth or some QR code etc,...
working airgapped / offline is a great quality speaking in favor of TOTP
Sure the ui isn't great. And it takes a couple extra clicks to the groups. But given the stupid shit that sites do like disabling paste for two factor codes or passwords, i just would never trust them to not fuck up a more streamlined solution. I like a bit more manual control sometimes, at the expense of convenience.
And it also runs and is backed up completely offline, which is nice.