Going to give this a try...
Going to give this a try...
Does this seem sound?
Here’s where it was added to PrivacyGuides - https://github.com/privacyguides/privacyguides.org/issues/36.... The person opening the issue is the CEO of ente. So the CEO of ente gets his company mentioned in PrivacyGuides back when it was new and that makes it more legit?
The discussion is not all that relevant as PrivacyGuides does not rely solely on community input. The core team pretty much generates content and lists recommendations based on (what they claim is) their own research (which isn't saying much).
The forum and community really give us a lot of external insights, with the voting system letting us poll how popular something is.
While we put a very heavy importance on the community consensus, it is mostly up to the team to decide what comes and goes, where more heavy decisions require more votes...
A reason why it has never really been written out is that policies can be gamed, and the team really wants to be able to veto decisions...
As far as "evaluating"/reviewing tools the methods to do so are not documented...
https://discuss.privacyguides.net/t/32774this seems self-contradictory
https://en.wikipedia.org/wiki/Comparison_of_OTP_applications
Valid concerns. In the case of Ente Auth though, it is used by folks working at CERN [0], who also sponsored a recent security audit: https://ente.com/blog/cern-audit/
[0] https://cern.service-now.com/service-portal?id=kb_article&n=... / https://auth.docs.cern.ch/trouble-shooting/2fa-tips/
They just store tokens, without other FA at "worst" you get locked of your account but nobody else has access either. You're also supposed to, as good practice, not be limited to token generation and typically have a dozen or so of recovery tokens. Also if they were somewhat not working at doing the 1 task they should do, namely generate tokens, then you won't be able to use them so it won't even be added.
So... I might be missing something, can you please explain what worries you and why I should thus worry too?
What I'm missing is a way to create and use Passkeys across devices. My use case does not support creating a new Passkey on every device, I need to sync them via servers I control. The system that supports that will be the system that I migrate to.
Expressly harvesting creds through a 2FA app seems a little more direct.