One more step to unhitching from Google…

Right now the only option I see in F-Droid is Aegis.

I’m not sure what to actually look for side from checking for unexpected permissions and reasonably frequent updates.

Hopefully something I can sync with a GNOME app…

    • Landless2029
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      8 months ago

      I’m a little concerned about having OTP and passwords together in one system.

      • waspentalive
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 months ago

        OTP is on my phone, Bitwarden is on my computer. I don’t use the OTP in Bitwarden.

        • Landless2029
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 months ago

          This is the way. I use Bitwarden and Aegis.

          The issue here is putting Bitwarden on your phone with OTP in Bitwarden.

    • ikidd
      link
      fedilink
      English
      arrow-up
      1
      ·
      8 months ago

      Yah, I can’t see a point to have another app/extension when Bitwarden has it built in, and it’s a great password manager.

      • ripcord
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 months ago

        Wait, it does? Including in the mobile app? I don’t see it.

        • ikidd
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 months ago

          Right under Password in the edit screen of an item: Authenticator Key. You put in the auth key the target site provides you when you enable TOTP and it will start generating timed tokens. Usually you’ll also get a one-time pad of backup keys, I usually toss those in the Notes of the edit screen there as well in case something goes wrong.

      • Lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 months ago

        The point of 2FA is “something you have” and “something you know” to enter a secured system.

        If you put both of those into one system that is accessible by one password, the whole concept is defeated.

        • ikidd
          link
          fedilink
          English
          arrow-up
          3
          ·
          8 months ago

          My threat model isn’t having someone take my computer and log into stuff so my concern when using 2FA is more about them having gotten hold of a password remotely. But a TOTP makes that password pretty hard to use, no matter where it’s stored. And my BW is also protected by a Yubi/password combo, so I guess I’m just vulnerable to having that beaten out of me.

          • Lka1988@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            8 months ago

            The other issue with this - If you lose access to that one system, you’re SOL. It’s a single point of failure.

            • ikidd
              link
              fedilink
              English
              arrow-up
              2
              ·
              8 months ago

              That I could accept as a good reason.

      • waspentalive
        link
        fedilink
        English
        arrow-up
        1
        ·
        8 months ago

        But if they get your Bitwarden vault and crack it - they have everything Throw a roadblock in their way - use a separate app for OTP.