Password Managers?

I have been using an app called Authenticator Plus for 2FA purposes. As you can configure it to use Dropbox or Google Drive as the cloud backup, you can then use it across multiple devices.

My only concern right now though is that the app hasn't been updated since December 2018 so it's possible the developer has gone AWOL. I have yet to find a replacement app I like. Any suggestions?
Have you tried authy?
 
Have you tried authy?
I am pretty sure I looked at it previously but I think I didn't like the fact I needed to have an online Authy account which is basically where the backup is stored.

What I like about Authenticator Plus was that it runs locally in the device, and then you have the option to backup to Dropbox or Drive to have multi- device support.
 
Yeah its not the best, why I want to add the hardware U2F dongles

I got burnt before from google authenticator when my phone broke and it wasnt in the iCloud backup, and Authy is insecure from the sms/sim swap angle.

I have to use TFA on ssh etc and probably enter it 15 times an hour, so trying to balance security with ease of use
If you’re going to do hardware keys then you can store your TOTP secret on your Yubikey.
If you want to balance security with ease of use, maybe look at using SSH with a security key?
OpenSSH has made it adaptable so I was playing around with it using Windows Hello.

I am pretty sure I looked at it previously but I think I didn't like the fact I needed to have an online Authy account which is basically where the backup is stored.

What I like about Authenticator Plus was that it runs locally in the device, and then you have the option to backup to Dropbox or Drive to have multi- device support.
Depends on the risk you want, Authy doesn’t keep the secret, so you can’t export it if you want to migrate.
It’s actually a useful app if you’re using any other of the Twilio services.
 
Last edited:
I am pretty sure I looked at it previously but I think I didn't like the fact I needed to have an online Authy account which is basically where the backup is stored.

What I like about Authenticator Plus was that it runs locally in the device, and then you have the option to backup to Dropbox or Drive to have multi- device support.

Heh? I don’t have any account.
 
I have been using an app called Authenticator Plus for 2FA purposes. As you can configure it to use Dropbox or Google Drive as the cloud backup, you can then use it across multiple devices.

My only concern right now though is that the app hasn't been updated since December 2018 so it's possible the developer has gone AWOL. I have yet to find a replacement app I like. Any suggestions?
 
Heh? I don’t have any account.
You would, if you look at the services you’ve added. There’s Authy accounts and authenticator accounts.

SendGrid as an example would fall under an Authy account, the mechanism is slightly different.
Personal and work both use the same code because they’re associated to the same account, so no scanning you just turn on 2FA and that’s it.
 
How do you sync across multiple devices? Or where do you backup to?

I see it is linked to my email address or phone number yes but it’s not really an account in the username and password sense.

My impression was it’s purely a second verification layer and the backup happens between devices.
 
I see it is linked to my email address or phone number yes but it’s not really an account in the username and password sense.

My impression was it’s purely a second verification layer and the backup happens between devices.
 
A question for those running Bitwarden - how and where are you guys running it? Docker container on your local machine, a server (cloud or local network, ) using the hosted version or other?
 

Makes sense.

But I’m confused why someone would NOT want that?
 
My point too. I realised when using Google authenticator that losing my cellphone would be an unmitigated disaster (I have about 50 2FA accounts) and moved to authy precisely for the backup.
I am using LastPass Families for years and not wanting to go through the pain of switching it (regardless of what people say, its never that easy). Of course, tracker disabled and I guess perhaps my adblockers on home network and devices was doing that already. Over 800 things in there.

LastPass works great for us on win,Mac,Android and idevices. Regardless of where password is required.

The authenticator stuff is making me curious though.
Also went through the pain of switching phones recently and moving the Google Auth to new phone was easy but the Microsoft authenticator required me to do all again. I think for work, I am forced to use Microsoft authenticator. For those using Authy,. would I be able to load all 0365 accounts into Auth? If so, I could make Authy my only tool.
 
I am using LastPass Families for years and not wanting to go through the pain of switching it (regardless of what people say, its never that easy). Of course, tracker disabled and I guess perhaps my adblockers on home network and devices was doing that already. Over 800 things in there.

LastPass works great for us on win,Mac,Android and idevices. Regardless of where password is required.

The authenticator stuff is making me curious though.
Also went through the pain of switching phones recently and moving the Google Auth to new phone was easy but the Microsoft authenticator required me to do all again. I think for work, I am forced to use Microsoft authenticator. For those using Authy,. would I be able to load all 0365 accounts into Auth? If so, I could make Authy my only tool.

It’s very quick and painless to export from one password manager into another.

Haven’t done LastPass to Bitwarden specifically, but done a few others into Bitwarden without issue.

Couple of minutes of effort.

****

You can load Microsoft account, the only compromise is that you lose the prompt option.

But the Microsoft Authenticator also offers backups so you are sort of half way there.

Bitwarden actually has built-in 2FA support but I’m yet to try it out.

From a security point of view I’d prefer to keep them separated anyway.
 
KeepassXC because it runs on most operating systems. It's open source which makes it more transparent as far as the actual security implementation. And I can configure it etc all myself, without anyone else being involved.

I keep a double encrypted copy in the cloud, and synchronise all my devices from that.

I think this is one area where you need to control everything yourself, and not trust some cloud service - so I personally would not use LastPass etc.
 
Makes sense.

But I’m confused why someone would NOT want that?
My point too. I realised when using Google authenticator that losing my cellphone would be an unmitigated disaster (I have about 50 2FA accounts) and moved to authy precisely for the backup.
I prefer Authenticator Plus that offers choice of cloud storage providers for backup and syncing purposes. I have yet to find something else that offers this.
 
Top
Sign up to the MyBroadband newsletter
X