i'm torn on the google authenticator sync thing because, on the one hand i don't like google having access to 2fa codes, on the other hand i think 2fa that google can peep into, while not good, is better than 2fa that you have vowed never to use again after losing your phone and with it permanent access to a lot of your accounts

@codl would it be so bad to at least communicate that it's being stored without encryption and/or offer to encrypt it with a simple passphrase? Apple seems to manage syncing 2FA without sending it in cleartext

@noiob oh sure yeah both of those things would be an improvement

@codl tbh I've been using a second installation of the app on my tablet as a backup of sorts, I guess you could also store the QR code somewhere safely but my new app just lets me export to a (passphrase-encrypted) file that I store via Nextcloud

@noiob wait does goog authenticator not have export capability? i havent used it in years

Follow

@codl it can export to a large QR code only meant for changing devices, that's it. It used to be a very basic app

· · Web · 1 · 0 · 0

@noiob huh. i have no idea how i got all my stuff out of it back then

Sign in to participate in the conversation
Awoo Space

Awoo.space is a Mastodon instance where members can rely on a team of moderators to help resolve conflict, and limits federation with other instances using a specific access list to minimize abuse.

While mature content is allowed here, we strongly believe in being able to choose to engage with content on your own terms, so please make sure to put mature and potentially sensitive content behind the CW feature with enough description that people know what it's about.

Before signing up, please read our community guidelines. While it's a very broad swath of topics it covers, please do your best! We believe that as long as you're putting forth genuine effort to limit harm you might cause – even if you haven't read the document – you'll be okay!