One more step to unhitching from Google…

Right now the only option I see in F-Droid is Aegis.

I’m not sure what to actually look for side from checking for unexpected permissions and reasonably frequent updates.

Hopefully something I can sync with a GNOME app…

    • HereIAm@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      22 days ago

      Same. Self hosting it sounds nice, and I self host a handful of services, but I don’t want to be stuck without passwords in another country with a dead server at home because a power cut happened at some point.

        • az04@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          21 days ago

          I had fault in my server this summer and my local bitwarden app wouldn’t work without the connection. Same in my laptop, if the connection is blocked by the firewall it doesn’t let me load the vault at all.

          • EpicStuff@lemmy.ca
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            20 days ago

            bitwarden works fine for me without connection, you just cant update/create passwords

        • HereIAm@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          21 days ago

          Oh, that’s actually good to know. I guess it makes sense for when you don’t have a good connection as well.

    • TedZanzibar@feddit.uk
      link
      fedilink
      English
      arrow-up
      6
      ·
      21 days ago

      It’s niche but I like to point it out whenever I get the opportunity: if your workplace uses Bitwarden Enterprise, every licensed user gets a free family plan that can be linked to any account. I haven’t personally paid for BW for years.

    • Lyra_Lycan@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      22 days ago

      As I’ve seen gaming server subscriptions go from £36/y to £23/m (Xbox) in a few years, and cloud CCTV storage from £40/y to £16/m (Google via acquisition of Nest) in a few months, I say we count our stars when a subscription cost remains fair.

    • pedroapero@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      14 days ago

      Yes, the only issue I have with it is that you can only have one TOTP for each site entry (need to create two separate entries if using two accounts).

  • zingo@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    22
    arrow-down
    1
    ·
    21 days ago

    Aegis.

    I like the auto backup feature (encrypted) . Then the backup is synced to computer via Syncthing.

    Set and forget setup.

    • Ohh@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      20 days ago

      For me aegis is by far the best. Simple. Encrypted. Backup. It’s saved to a syncthing folder. Passwords are in bitwarden for simpme stuff but keepassxc is great. And also synced via syncthing.

    • ikidd@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      21 days ago

      Yah, I can’t see a point to have another app/extension when Bitwarden has it built in, and it’s a great password manager.

        • ikidd@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          21 days ago

          Right under Password in the edit screen of an item: Authenticator Key. You put in the auth key the target site provides you when you enable TOTP and it will start generating timed tokens. Usually you’ll also get a one-time pad of backup keys, I usually toss those in the Notes of the edit screen there as well in case something goes wrong.

      • Lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        2
        ·
        20 days ago

        The point of 2FA is “something you have” and “something you know” to enter a secured system.

        If you put both of those into one system that is accessible by one password, the whole concept is defeated.

        • ikidd@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          20 days ago

          My threat model isn’t having someone take my computer and log into stuff so my concern when using 2FA is more about them having gotten hold of a password remotely. But a TOTP makes that password pretty hard to use, no matter where it’s stored. And my BW is also protected by a Yubi/password combo, so I guess I’m just vulnerable to having that beaten out of me.

      • waspentalive@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        18 days ago

        But if they get your Bitwarden vault and crack it - they have everything Throw a roadblock in their way - use a separate app for OTP.

  • Curious Canid@lemmy.ca
    link
    fedilink
    English
    arrow-up
    17
    ·
    21 days ago

    I’ve been using Aegis for several years now without any problems. It replaced the Google Authenticator seamlessly.

  • AMillionMonkeys@lemmy.world
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    2
    ·
    22 days ago

    Bitwarden Authenticator because Bitwarden seems to have a good reputation. I don’t use their password manager, though.
    It does seem faintly insecure that it displays all of the codes at once on one page, but I’m having trouble imagining a scenario where it’s actually a problem.