this post was submitted on 01 Aug 2023
1 points (100.0% liked)

Privacy Guides

16263 readers
18 users here now

In the digital age, protecting your personal information might seem like an impossible task. We’re here to help.

This is a community for sharing news about privacy, posting information about cool privacy tools and services, and getting advice about your privacy journey.


You can subscribe to this community from any Kbin or Lemmy instance:

Learn more...


Check out our website at privacyguides.org before asking your questions here. We've tried answering the common questions and recommendations there!

Want to get involved? The website is open-source on GitHub, and your help would be appreciated!


This community is the "official" Privacy Guides community on Lemmy, which can be verified here. Other "Privacy Guides" communities on other Lemmy servers are not moderated by this team or associated with the website.


Moderation Rules:

  1. We prefer posting about open-source software whenever possible.
  2. This is not the place for self-promotion if you are not listed on privacyguides.org. If you want to be listed, make a suggestion on our forum first.
  3. No soliciting engagement: Don't ask for upvotes, follows, etc.
  4. Surveys, Fundraising, and Petitions must be pre-approved by the mod team.
  5. Be civil, no violence, hate speech. Assume people here are posting in good faith.
  6. Don't repost topics which have already been covered here.
  7. News posts must be related to privacy and security, and your post title must match the article headline exactly. Do not editorialize titles, you can post your opinions in the post body or a comment.
  8. Memes/images/video posts that could be summarized as text explanations should not be posted. Infographics and conference talks from reputable sources are acceptable.
  9. No help vampires: This is not a tech support subreddit, don't abuse our community's willingness to help. Questions related to privacy, security or privacy/security related software and their configurations are acceptable.
  10. No misinformation: Extraordinary claims must be matched with evidence.
  11. Do not post about VPNs or cryptocurrencies which are not listed on privacyguides.org. See Rule 2 for info on adding new recommendations to the website.
  12. General guides or software lists are not permitted. Original sources and research about specific topics are allowed as long as they are high quality and factual. We are not providing a platform for poorly-vetted, out-of-date or conflicting recommendations.

Additional Resources:

founded 1 year ago
MODERATORS
 

As we all know, Ravio has been removed from the recommended multi-factor authentication apps for iOS on PrivacyGuides.

As I want to export all my TOTP codes out of Ravio ASAP, what apps are you migrating towards? I know a few were mentioned such as:

• Tofu • Ente • 2FAS • FreeOTP • Bitwarden TOTP + Yubikey

top 14 comments
sorted by: hot top controversial new old
[–] unbuckled@lemm.ee 2 points 1 year ago* (last edited 3 months ago) (1 children)

I switched to 2FAS.

You can’t export from FreeOTP. Ente doesn’t appear to be open source. Tofu is an option but I’m afraid it might not be maintained.

Edit: Use Ente. It’s the best option.

[–] humuhumu@lemm.ee 1 points 3 months ago

Tofu is an option but I’m afraid it might not be maintained.

They made an annoucement 2 weeks ago about switching maintainer.

https://github.com/iKenndac/Tofu

2FAS

They only support iOS/iPadOS 16.4 or later.. no go for me

[–] NightAuthor@beehaw.org 1 points 1 year ago (1 children)
[–] pineapplelover@lemm.ee 1 points 1 year ago

I used to use them a while back but now I use Aegis. I prefer my 2fa offline and disconnected from the internet. I still keep my backups saved in safe spaces though. It served me well to get off of Authy too because last year, they got compromised.

https://techcrunch.com/2022/08/26/twilio-breach-authy/

[–] gogosempai@programming.dev 1 points 1 year ago* (last edited 1 year ago)

I have been using ProtonMail and Drive already so it was an easy decision to switch to Proton Pass when it came out. It's an all-in-one password manager which let's you store 2FA as well and also let's you make email aliases. It's synced everywhere, on Firefox on my linux desktop to my android phone to my iPad.

[–] YearOfTheCommieDesktop@hexbear.net 1 points 1 year ago* (last edited 1 year ago) (1 children)

Not on iOS but I like my yubikeys. Depending on your requirements (if you have less than 32 TOTP accounts per yubikey), they can handle your TOTP directly instead of just using them to unlock Bitwarden.

For security I don't like to keep my TOTP keys in my password manager, even if it is strongly protected. With a yubikey I can ensure that both access to the key AND a physical touch is necessary to generate any codes. So even if I leave it plugged in on a remotely compromised PC I'm mostly protected, because a touch is required.

[–] Senjutsu@lemmy.one 1 points 1 year ago (1 children)

I guess why not use the yubikey for webauth instead of totp?

[–] YearOfTheCommieDesktop@hexbear.net 2 points 1 year ago (1 children)

yeah, when sites support it, that's definitely the best option, but many sites only barely do totp lol so I have to have to put the totp codes somewhere, and the yubikey handles it in a pretty nifty way

[–] Senjutsu@lemmy.one 2 points 1 year ago (1 children)

Gotcha. And I guess what backup method do you use? (Like a second YubiKey, recovery codes somewhere safe, a 2fa app discretely hidden)

mostly recovery codes. I have multiple yubikeys but that's mostly for work

[–] poring@lemm.ee 1 points 1 year ago

I'll be using BitWarden as my 2FA app. I use KeePass as my password manager so it would still be two different services/apps.

I was planning on using Tofu but it has no FaceID which is mandatory IMO.

[–] Thief@lemmy.myserv.one 0 points 1 year ago (1 children)

The password manager for iphone or ios has mfa built in - seems to work ok. Its a bit annoying if you use a desktop thats not mac though and have to search for the mfa code among the millions of passwords.

[–] Milarepa_07@lemmy.one 0 points 1 year ago (1 children)

True but like someone else mentioned here it’s not the best having all eggs in the same basket. If for eggsample 🙂 the apple account gets compromised it’s going to be hard.

Check this video from techlore.

https://www.youtube.com/watch?v=25wG173PL3U

[–] PipedLinkBot@feddit.rocks 1 points 1 year ago

Here is an alternative Piped link(s): https://piped.video/watch?v=25wG173PL3U

Piped is a privacy-respecting open-source alternative frontend to YouTube.

I'm open-source, check me out at GitHub.