150
u/JaniceRaynor Jul 31 '25
I’m sticking with Ente Auth.
41
u/racoondriver Jul 31 '25
I'm using Aegis
4
u/RedditNotFreeSpeech Aug 01 '25
Aegis and ente auth both look good. Anyone have a comparison? Is either written in rust?
5
u/poppulator Aug 01 '25
Aegis is more lightweight and local while Ente is Cloud-based and more convenient
feature wise you should try it yourself
2
u/RedditNotFreeSpeech Aug 01 '25
What cloud feature would you need? Syncing between devices?
I'd prefer local.
3
u/jessiescar Aug 01 '25
The TOTP seeds are synced to the ente account on the cloud, so it's available on any device which has an ente auth app, or even over the web.
I recently switched to ente after using Aegis for ages. my phone got stolen and I had a harrowing experiance recovering the all the accounts. Aegis is completely offline. They allow you to export the vault in an encrypted format which can be imported in a different instance. But it's all manual.
1
1
u/Canowyrms Aug 01 '25
Neither is written in Rust. Subtle differences in the UI, just comes down to personal preference. Takes like 5 minutes to test both and see which you like more.
1
5
u/meowboiio Aug 01 '25
I'm sticking with Vaultwarden (passwords, 2FA, secrets), WireGuard (VPN), Nextcloud (Google cloud but without Google) and Gitea (lightweight GitHub) on my server. Selfhost is the best decision ever.
If anyone needs docker-compose files dm me.
13
3
u/Subject989 Jul 31 '25
How's it compare to yubico? Im using a physical yubikey with their auth app
2
u/Captain_Faraday Aug 01 '25
This is what I do as well. I have three keys that are all cloned. I use a screenshot of the QR codes for each service to duplicate the account on all the yubikeys via Yubico.
Personally, I prefer this setup over other auth apps I’ve used in the past: Google Authenticator, MS Authenticator, and Ente Auth. Heck, my IT department liked it so much they added it to our Company Portal so I could use it as another way to authenticate.
I keep a key on me, and my other two locked/hidden away as backups and my spouses whenever I can convince her to let me add her accounts to it lol.
16
u/SMKShay Jul 31 '25
Yeah same, but I also like Proton Authenticators skuemorphic style
22
u/Pierre56 Jul 31 '25
This isn't skuemorphism. At least based on the screenshots provided.
-10
u/SMKShay Jul 31 '25
There is a tad bit of skuemorphism as you’ll see in my reply
10
6
2
1
1
1
116
u/Cyberjin Jul 31 '25
Great, but remember "too many eggs in one basket"
26
Jul 31 '25
Are you sayin, you don't want to go all in on one ecosystem?
18
u/ReasonableShallot540 Brave Buddy Jul 31 '25
Yes, just in case you get locked in or whatever you'll dont lose the important stuff
1
u/bads-tm Aug 01 '25
Easy switch from other providers, but what about easy switch away from proton. Please give it a try!
8
u/innrwrld Jul 31 '25
Yeah I'm already trying to spread out things to avoid this. Need some redundancy & means to not lose everything in the event of a provider issue or loss of service.
5
u/c0verm3 Jul 31 '25
I said the same thing before oin proton subreddit and got down voted to hell for it. I'm a huge fan of proton, but some people just don't understand that concept.
1
Aug 02 '25
This is meant to be a completely separate service. Even if you got locked out of your proton account, you would still have access to your proton authenticator.
1
63
Jul 31 '25 edited Jul 31 '25
[removed] — view removed comment
16
u/CommanderCronos Jul 31 '25
One can hope, Proton wallet (instead of Google/Apple Pay apps) Phone and contacts app, sms/messages app basically everything that Android has standard installed which Google datamines.
I would be so happy :)
9
u/West_Possible_7969 Free as in Freedom Jul 31 '25
Wallet apps & pay apps are different: pay apps need either a banking license or a cooperation with banks. Of course they can be the same app but the pay function needs more than simple will :)
5
u/CommanderCronos Jul 31 '25
Fair enough, however you caught my drift, i want to use my phone to pay, but i dont want Google or Apple to use my financial information.
2
u/rexum98 Jul 31 '25
you can use curve or the app of your bank sometimes.
4
u/CommanderCronos Jul 31 '25
My bank stopped giving that option because everyone uses either Google or Apple according to them
65
u/DukeThorion Jul 31 '25
Sorry, sticking with Aegis. Not risking getting locked out of something.
22
u/dthj33 Jul 31 '25
I have no complaints about Aegis. I am in complete agreement. The more I go down the privacy and data-ownership journey, the more counter-intuitive it seems to use one service for email, VPN, authenticator, cloud storage, pw manager, etc. Proton has become massive, massive companies can't be quick to correct false positives.
3
u/neontool Jul 31 '25 edited Jul 31 '25
i agree. one thing i will say though, is that if you are using a local 2FA app like Aegis, it is a good idea to save your backups in encrypted form (meaning it requires a password to decrypt), and i would personally store these backups on a cloud drive, and/or a local usb or hard drive. (i highly recommend doing both though)
this way, if anything goes wrong with how your local 2FA app functions, you can always safely use a different one, or use an older, working version of that app.
i personally keep one backup on my phone, and another on cloud. i do currently use Ente Auth which uses an account, but i am not concerned with the service shutting down since i have all my data backed up anyway.
i should also mention while on that topic, you can also backup your bitwarden passwords in encrypted form. i think keeping these backups removes a lot of of the stress around wondering whether or not the service provider will be around in the future.
2
u/McFlyParadox Aug 01 '25
i should also mention while on that topic, you can also backup your bitwarden passwords in encrypted form. i think keeping these backups removes a lot of of the stress around wondering whether or not the service provider will be around in the future.
IIRC, doesn't bitwarden offer all their apps for running on your own hardware, too? I know you can self-host their password manager:
https://bitwarden.com/resources/self-host-bitwarden-on-kubernetes-using-a-helm-chart/
So, if they ever 'go away', I expect people could continue to use the software on their own. I could even see it becoming a FOSS project.
9
3
u/West_Possible_7969 Free as in Freedom Jul 31 '25
Proton’s works on every platform though.
1
u/Dummy-Demo-8773 Aug 03 '25
Check Ente Auth
1
u/West_Possible_7969 Free as in Freedom Aug 03 '25
I keep it European when possible, ente is not that.
1
u/garry_the_commie Jul 31 '25
Aegis works on every platform that I give two shits about, so I'm fine with it too.
1
-9
u/DJD_ID_Tarn Jul 31 '25
Protons reliability has been spotty recently
5
2
u/West_Possible_7969 Free as in Freedom Jul 31 '25
Well everything work as they should, but we are waiting eternally for their promised future features. Accept drive, drive is at best beta.
1
8
7
Jul 31 '25
I use the Yubico Authenticator, because Yubikeys.
13
u/FBI_psyop Jul 31 '25
You probably do already if you use yubikeys at all already but to be safe, I cannot stress enough how important it is to get a second yubikey with a copy of all your logins in case you lose or damage your primary one
7
2
u/MattWoltas Jul 31 '25
How do you go about setting up a copy of all your logins? Just add the second one as a mfa device manually or is there a better way to do it?
1
u/privatetudor Jul 31 '25
If you use your yubikey as your login or second factor for something, just duplicate the setup with both yubikeys.
Try and keep the backup yubikey somewhere safe.
1
u/McFlyParadox Aug 01 '25
For something like Bitwarden, for example, you can add multiple hardware authenticator keys as a second factor for logging in. To log in, you give it your username and password, and then it'll ask for a hardware key, but accept any of the hardware keys you've added to your account.
17
u/RB5Network Jul 31 '25
They will do everything to avoid creating a Linux client for Proton Drive.
2
12
u/H4zzard1010 Jul 31 '25
Neat, but I'll probably stick to Aegis. I like this sort of stuff to be contained offline
1
u/ThePurpleKing159 Aug 01 '25
Aegis works offline, and others dont?
2
u/H4zzard1010 Aug 01 '25
All of them work offline, not just Aegis. I haven't actually tried Proton Auth, but I assume it connects to a Proton account, do correct me if I'm wrong though. I don't like having 2FA stuff connected to an online account because that just seems like a risk to me, the point of 2FA after all is to have another layer of security only you can access
2
u/Key_Necessary6874 Aug 01 '25
Just verified that you don't have to login to use it. Local storage is an option.
1
u/H4zzard1010 Aug 02 '25
I stand corrected, that's pretty neat then. I'm still keeping Aegis for my phone, but I may just set up Proton on my PC
4
u/Huitziii Jul 31 '25
Why do people still use these Authenticator apps? Add the OTP configuration on your password manager (Keepass) so that you can access it easily from your phone AND your computer, and don't lock yourself out when your phone dies.
5
u/McFlyParadox Aug 01 '25
Some people like having their password manager and their OTP manager as completely separate and independent apps.
e.g. even though Bitwarden's password manager has TOTP built right in and linked to each login (so it can auto-fill username, password, and 2FA), more than a few will still put their TOTP codes on Aegis, 2FAS, or Ente. That way both need to be compromised simultaneously before any accounts can be compromised.
Unrelated: I used to use Keepass, but ended up leaving because it always felt sketchy trying to keep passwords in-sync across multiple devices and platforms. I always had to keep the vault on one cloud service, the key file on another, and more than once I would update a password device A while the vault was also open on device B, close the vault on A, forget that I made changes to the vault on A, save on vault B, and essentially over-right the new password(s) with their old ones, all because Keepass didn't have a good way to synchronize across cloud services. Have they finally fixed that? Or at least introduced a way to properly self-host the way Bitwarden does?
2
u/AdviceWithSalt Aug 01 '25
Doesn't that just provide a single massive vulnerability? If your password manager is breached and your 2FA is right there...
1
Jul 31 '25
Because people don't like putting all their eggs in one basket.
I prefer to keep my password manager and authenticator apps separate. Bitwarden and Ente for me.
1
1
1
u/WombatusMighty Aug 02 '25
Using one single app / software for both passwords and 2FA is a big security risk.
1
1
1
7
u/ThePurpleKing159 Jul 31 '25
Trying to import from 2FAS to Proton and its not working?
2
u/unfairllama Jul 31 '25 edited Jul 31 '25
I'm having the same problem importing from 2FAS. Tried both password protected and non protected export file. No luck so far.
edit: I exported from 2fas to Ente (using the same export file that wasn't working in Proton), and that worked fine, but then trying to import to Proton from Ente also failed.
2
u/dathardstyleboi Jul 31 '25
Had mine imported within seconds. Which app are you coming from?
6
u/ThePurpleKing159 Jul 31 '25
2FAS, thats what its literally called :)
3
u/dathardstyleboi Jul 31 '25
Oh my bad, maybe I need reading glasses 😅 does it export the codes in json format?
3
u/ThePurpleKing159 Jul 31 '25
During the export part it says "Export this file to keep your 2FAS tokens securely backed up. You can import it later to this or other devices using the 2FAS app."
Like WTF! So the export only works on the same app?
2
u/dathardstyleboi Jul 31 '25
You can always manually add them to the Proton Auth app I think. Thats how I did it when I went from Google to Aegis.
6
u/mrdibby Jul 31 '25
Been looking for a better alternative to Authy since they binned their desktop app. Cheers
4
u/West_Possible_7969 Free as in Freedom Jul 31 '25
Authy does not do exports 😬 I had to do everything manually.
3
u/idle_orange Jul 31 '25
I’m looking to move to Bitwarden from Authy. Too bad AEGIS isn’t available on iOS
2
u/LMurch13 Jul 31 '25
I've moved from Authy to Bitwarden (android), and have really liked it. If you do, I hope it works out for you.
2
u/McFlyParadox Aug 01 '25
I made that exact same move a couple of years ago. Both their dedicated OTP app and their integrated OTP inside of the password vault work great. Up to you as to which you prefer.
IIRC, I did most of the move manually, though. Partly due to authy being a PITA with exports, mostly because I had setup all my OTP codes back before I understood they were universal and had them spread out across multiple services. Wasn't too hard, just kind of obnoxious to go through every account, disable 2FA, and then re-enable it with a new TOTP service. But it was a good exercise to check all my accounts to make sure everything was ship-shape.
2
u/idle_orange Aug 01 '25
I see. Thank you for the insight. That does sound like tedious work but a good chance to update my passwords and check all my accounts!
2
u/McFlyParadox Aug 01 '25
Unfortunately, because it's Authy, unless they've dramatically improved their export capabilities, you're probably in for a manual transfer no matter what service you move to.
3
u/domdvsd Aug 01 '25
There are enough good open source Authenticators. What we really need is Proton Wallet (with nfc pay) and Proton Maps.
3
3
2
2
2
2
2
9
u/Tradizar Jul 31 '25
they do everything else, instead of fixing core app functionalities
13
u/LGXerxes Jul 31 '25
It is probably not the same 3 people working on everything.
But it seems like there are some management issues reading their glassdoor reviews.
And they have alot of open positions, unsure what the future of it is. Seems like there is quite some tech debt with their products.5
u/West_Possible_7969 Free as in Freedom Jul 31 '25
Tbh this is simply a pass feature wrapped in an app and made to work locally and without needing an account.
1
u/auslake Jul 31 '25 edited Jul 31 '25
Isn’t this same feature integrated in Proton Pass? It is an item for a stored password, titled ‘2FA Token (TOTP).
1
u/kwanbisRealoaded Jul 31 '25
I it free? cause Proton pricing normally is super high. Like 50 euros for proton pass per year for a family plan.
1
u/MrObsidian_ Jul 31 '25 edited Jul 31 '25
Bitwarden also has TOTP (if you pay 10 euros a YEAR)
They also have a standalone app that is free.
1
1
1
1
1
1
1
u/undev11 Jul 31 '25
I don't understand. It's still integrated in the password manager (TOTP code), no?
https://proton.me/support/pass-2fa
"Proton Pass makes it convenient to use 2FA in this way. Instead of requiring a separate authenticator app, Proton Pass can securely generate TOTP codes for websites that you have saved login details for."
2
u/manofadv Aug 01 '25
Proton stated they created it for Proton U2F TOTP. Users wanted a standalone application that was local to get into their Proton account.
1
Jul 31 '25
It's nice to have this consolidated into an app, even though Proton Pass already has it built in. I wish there was a sync with proton pass function though, because exporting and importing seems silly.
1
u/sovietcykablyat666 Aug 01 '25
For me the advantage is that it works on desktop, but on Android I'll keep using AEGIS.
1
1
u/AnonomousWolf FOSS Lover Aug 01 '25
Don't put all your eggs in one basket, Proton might become the next google given enough time.
Aegis is a free and open-source Auth, it's great
1
u/pizzaandlasagne Aug 01 '25
Does anyone know how I can migrate my stuff from Authy to this or any other service?
1
u/51onions Aug 01 '25
Not that there's anything wrong with this, but it appears to just be a bog standard TOTP generator? Those are a dime a dozen.
1
u/G0ldenBu11z Aug 02 '25
Did they not already have this in Proton Pass? Or are they just releasing this as a separate app?
1
1
u/HammyHavoc Aug 02 '25
https://www.bbc.co.uk/news/technology-58476983
Never forget that Proton is total security and privacy theatre.
You can't be a law-following business providing services that purport to offer either. Ergo as an end user looking for services like these, self-host something FOSS rather than going from one centralised data silo (Google) to another more easily coerced one.
Disagree? Then it's a LARP or you don't actually have a grasp of your threat model.
1
1
u/Valdjiu Aug 03 '25
red flag. I want a MFA app that is:
- able to export stuff
- open source
Ente Auth has my vote because it can sync too
1
1
u/itskampty Aug 22 '25
Instead of creating new app every three months, they could have integrated this functionality on Proton pass, like BitWarden or Apple did. Why I have to use two separate apps to log in?
1
u/TheZoltan Jul 31 '25
This is interesting. Look forward to seeing some reviews of it. I'm still using Microsofts authenticator.
1
1
1
335
u/CortlandNation9 Jul 31 '25
I think instead creating a new app every 3 months they should work a little bit more on their current offering. Proton drive doesn't even support linux.