this post was submitted on 31 Jul 2025
272 points (95.3% liked)

Technology

73541 readers
2712 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
(page 2) 50 comments
sorted by: hot top controversial new old
[–] ABetterTomorrow@sh.itjust.works 6 points 2 days ago (12 children)

Is proton legit? I always see mix comments about them.

load more comments (12 replies)
[–] IllNess@infosec.pub 10 points 2 days ago (10 children)

Hmm... I'm not sure about having an authenticator app on a desktop computer.

Like you are putting all your eggs in one basket. Password managers, and your emails already go to one place for authentication. Adding an authenticator means if your computer is compromised, a person can have access to more accounts.

I always figured this is why desktop authenticator apps aren't a thing.

[–] MangoPenguin@lemmy.blahaj.zone 7 points 2 days ago* (last edited 2 days ago)

Well hopefully the 2FA data is encrypted and the app requires a pin or password to access.

Plus my password manager also needs a pin after it times out, and my computers all have their drives encrypted too.

It's plenty to stop casual thieves and such.

[–] pulsewidth@lemmy.world 5 points 2 days ago (2 children)

Absolutely. 2FA codes (and 2FA 'single use codes' / recovery codes) should not be stored in the same system that manages your usernames and passwords - it defeats the purpose of 2FA.

But most people will just breeze past advice and do whatever is most convenient.

[–] theherk@lemmy.world 6 points 2 days ago (1 children)

I don’t view it as simply compromised or not. How a password is compromised is relevant. The vast majority of issues aren’t somebody gaining access to your logged in machine. Passwords are nearly always compromised from a server mishandling data.

That means in most cases 2FA near a password is not likely to be an issue. I’m not saying I recommend it, but it does change the risk evaluation.

load more comments (1 replies)
[–] jjlinux@lemmy.zip 4 points 2 days ago (1 children)

I am (was?) one of those. Working on eliminating or changing the passwords and emails of my 550+ accounts. I'm creating a simplelogin email for each of the ones I'm keeping, setting up a randomly generated password for each as well (24+ characters long with every possible character available), trying to delete the accounts of services I don't want/need anymore, and then setting up 2fa on Aegis if they don't accept a hardware tokens.

But it's an intense and long process, though absolutely worth it. With work and personal life, I'm guessing I can be done in a couple of weeks.

load more comments (1 replies)
load more comments (8 replies)
[–] Eyekaytee@aussie.zone 6 points 2 days ago (1 children)
[–] Psiczar@aussie.zone 1 points 2 days ago (2 children)

Why? What’s wrong with Authy? I use it, Proton and Bitwarden. I could consolidate everything into Proton, but I’m concerned about having everything with one vendor.

[–] Eyekaytee@aussie.zone 3 points 2 days ago (1 children)

as above trying to get away from american services, it’s really, youtube, google maps and iphone are only things im stuck with

load more comments (1 replies)
[–] Humanius@lemmy.world 4 points 2 days ago* (last edited 2 days ago)

Not op, but for me the main problem with Authy is that it is owned by an American company.

It's not the worst offender, but any American company is subject to the whims of the current administration. As an example, we're currently seeing how American sanctions lock people out of their Microsoft accounts at the International Court.

I've slowly been moving over my 2FA codes to Aegis.

[–] just_another_person@lemmy.world 6 points 2 days ago (1 children)

I guess it's kinda nice. They already had this in Proton Pass, but I guess not all accounts have access to that as a bundle maybe?

[–] Ulrich@feddit.org 2 points 2 days ago

Proton Pass is a password manager designed to securely generate and store strong passwords, and protect your digital identity with features like email alises and dark web monitoring. It also includes an integrated authenticator that can store and autofill 2FA codes - but not the ones used to log in to your Proton account. Proton Authenticator is a standalone 2FA app that allows users to enable 2FA protection for their Proton account, it also allows users to store their 2FA codes separate from their passwords if they wish to do so.

Seems like basically an ad platform/gateway to Pass.

[–] Bluebaloon@leminal.space 4 points 2 days ago

That’s amazing

[–] Modest_Toxic@feddit.uk 3 points 2 days ago

Netflix doesn’t have 2FA

[–] akilou@sh.itjust.works 3 points 2 days ago

I currently have all of my 2FA codes in Pass except for my Proton account itself, which I have in Aegis, backing up to my home server.

It looks like you can easily export from Aegis to Proton Authenticator and you can use PA without a Proton account, which I think I might do. I don't want to use my PA app with my Proton account to hold my Proton account 2FA code. I'll end up locked out of the house with the keys inside.

[–] homesweethomeMrL@lemmy.world 0 points 2 days ago

Wow an OTP app.

Maybe a QR creation app is next?

load more comments
view more: ‹ prev next ›