Comment by pnw

2 years ago

Has anyone found a single open-source app that supports both mobile and desktop though? That was the attraction of Authy before they killed their desktop apps.

i've switched to keepass right after first breach. it's not convenient to store the db on eg gdrive and sometimes it doesn't work, but that is way better than another SaaS app that will eventually leak my passwords/2fa codes.

The desktop version somewhat contradicts the purpose of 2FA.

  • In this case what if you use 2FA while browsing with your phone. Wouldn't that also contradict the purpose?

    The main purpose is that people won't get phished as easily or if they reuse passwords it can't be abused. Or if password was to leak for any reason.

  • Not really, 2FA is literally just that: a second factor.

    It makes it unlikely someone has access to both your password and the TOTP URI. So, if you leak your password on a public forum (for example), the person who gets that is not likely to also have your TOTP info.