30
submitted 11 months ago by mxwarp@lemmy.world to c/privacy@lemmy.ml

What’s your prefer two-factor authentication app for iOS?

I'm looking for an app that offers the best combination of platform compatibility (preferably available on Mac OS, iPad OS, and iOS), security, usability, and reliability.

It would be great if the app is open source and has a backup feature as well.

I came across a recent Wirecutter article from The New York Timesthat recommends Cisco DUO Mobile as the top choice, followed by Authy and Google Authenticator.

I would greatly appreciate your insights and security perspectives.

Thank you!

top 21 comments
sorted by: hot top controversial new old
[-] inspxtr@lemmy.world 21 points 11 months ago* (last edited 11 months ago)

privacyguides recommends Raivo OTP, see https://www.privacyguides.org/en/multi-factor-authentication/

Raivo OTP is a native, lightweight and secure time-based (TOTP) & counter-based (HOTP) password client for iOS. Raivo OTP offers optional iCloud backup & sync. Raivo OTP is also available for macOS in the form of a status bar application, however the Mac app does not work independently of the iOS app.

Its Github repo is at https://github.com/raivo-otp

[-] Gorroth@lemmy.world 1 points 11 months ago

That looks great! Is there any chance to migrate my existing Google Authenticator OTPs to Raivo? Seems like there is no way to export as zip from Google Authenticator, only QR Code that Raivo tells me isn’t valid.

[-] jeanofthedead@lemmy.world 1 points 11 months ago

Still no Apple Watch app? Somebody seriously needs to get that going for them.

[-] SamsonSeinfelder@feddit.de 11 points 11 months ago

There is a OTP mechanism natively build into iOS that is backing up with your standard keychain to iCloud. No need for an external app actually. Just go to passwords and look up your service and if you have set it up correctly you will get your OTP from there.

[-] Charliebeans@slrpnk.net 0 points 11 months ago

The only question is how private the iCloud is? Can cloud sync disabled? Does Advanced data protection improves privacy here?

[-] somedude5@lemm.ee 6 points 11 months ago

This is a no brainier. Raivo all the way

[-] andruid@lemmy.ml 5 points 11 months ago

FreeOTP+ has been good to me

[-] Greatsell025@lemmy.world 3 points 11 months ago

I started using OTP Auth after Steve Gibson (SecurityNow podcast host) mentioned that he uses it.

[-] jeanofthedead@lemmy.world 2 points 11 months ago

Same. Fantastic app with an added Apple watch app.

[-] notjvb@lemmy.world 3 points 11 months ago

I really like 1Password as both my PW manager and OTP generator. PWs and OTPs get synced across devices so I never worry about losing my phone and getting locked out of any 2FA sites. On iOS as well as desktop, 1Password can auto-fill passwords and OTP codes. Highly recommend.

[-] remus@lemmy.world 4 points 11 months ago

Doesn’t this defeat the purpose of multi factor authentication though? If someone got access to 1Password, they could access both your password and secondary authentication code. I think it may be a better idea to keep them separate.

[-] Achird@sh.itjust.works 3 points 11 months ago

1Password has a blog post that talks about it here. https://blog.1password.com/1password-2fa-passwords-codes-together/

Ultimately it depends on your threat model and security vs convenience.

[-] notjvb@lemmy.world 2 points 11 months ago* (last edited 11 months ago)

Pretty big “if” since I’m the only one who knows the long password, I rotate it often, and I hold the keys to encrypt everything. You’re right it’s a single point of fail but a LOT would have to go wrong for it to fail.

Edit: plus 1P supports physical 2FAs to get into the vault itself, if that helps

[-] landordragen@lemmy.ml 2 points 11 months ago

2FAS on my iPhone with the browser extension on my MacBook.

https://2fas.com/

When I need to enter the code on my laptop, I just click the icon extension, which pings my phone, I accept the request and it auto-fills.

[-] prwnr@programming.dev 2 points 11 months ago

Any information on 2FA app? I’m using it, but I don’t know how secure and private it is. Maybe I should switch to Raivo?

[-] caglel@lemmy.world 1 points 11 months ago

I use Authy. It has an Apple Watch app

[-] pabloscloud@lemmy.world 1 points 11 months ago

I use my password manager. Better than not using totp but more convenient than another app and no sync between devices. I use a yubico for everything that has to do with money

[-] nomadjoanne@lemmy.world 1 points 11 months ago

I use FreeOTP+. I have no idea if it is "the best" but it does it's job and has served me well.

load more comments
view more: next ›
this post was submitted on 17 Jul 2023
30 points (89.5% liked)

Privacy

29814 readers
768 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 4 years ago
MODERATORS