this post was submitted on 05 Jul 2024
208 points (99.1% liked)

Technology

59555 readers
4488 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Scrollone@feddit.it 40 points 4 months ago (3 children)

Companies need to stop using Authy. It's stupid and pointless when we have a open alternative such as the one used by Google Authenticator or Aegis.

[–] TheEighthDoctor@lemmy.world 12 points 4 months ago (4 children)

I started using Authy instead of GA because every time I changed the ROM on my phone I would lose all codes, because I would forget every time.

[–] Lem453@lemmy.ca 14 points 4 months ago

Use aegis, export the keys and then reimport them every time you switch. Trusting your second factor to a cloud is a disaster waiting to happen.

If you want to get fancy setup your own cloud server (nextcloud, Seafile, owncloud etc) and set the backup folder for aegis to the self hosted cloud for easy restore every time you switch ROMs.

[–] dev_null@lemmy.ml 3 points 4 months ago

GA now backups your codes in your Google account, so this doesn't happen anymore.

[–] I_Clean_Here@lemmy.world 3 points 4 months ago

This isn't about you and your silly follies

[–] laurelraven@lemmy.blahaj.zone 1 points 4 months ago (1 children)

I've started putting mine into my Bitwarden vault as well as Google auth, mainly because I'm a bit paranoid I'll wind up locked out of something by trusting a second factor too much

[–] Coreidan@lemmy.world 1 points 4 months ago

With password recovery you shouldn’t be getting locked out of anything. I don’t see this being a risk.

[–] iamericandre@lemmy.world 10 points 4 months ago

Call my job and tell them this please. I have to use this shite everyday and it sucks.

[–] lazynooblet@lazysoci.al 1 points 4 months ago

I expect most usage of authy was based on the open TOTP protocol that Google etc use. The additional benefit was backing up those codes to the authy account, hence the avenue of attack on those accounts.

I agree though, Authy, especially since it was bought out, should be avoided. They deprecated their desktop app which was the only semi useful part of their suite, but I stopped using it years ago.