Comment on What’s the currently best way to manage TOTP tokens?
vegetaaaaaaa@lemmy.world 2 weeks ago
No, I’m not interested in a password manager, thank you
Ok. But since you already use a password manager (right?), why not use its built-in TOTP management (I use KeepassXC on desktop and KeepassDX on Android). Why do you need yet-another-separate app?
If I really had to, I’d recommend Aegis.
But I’ll still recommend using a password manager.
Coleslaw4145@lemmy.world 2 weeks ago
To keep your two factor codes and passwords separate in the event that your password manager is breached.
Also if you need a 2FA code to log into your password manager, how are you going to get it if its in the password manager that you can’t log into without the 2FA code inside it?
fizzle@quokk.au 2 weeks ago
This question comes up all the time with KeepassXC… like its not a 2nd factor if the TOTP is in the same app as the password.
Factor 1 is knowing the master password, and
Factor 2 is having the password file.
Im not trying to suggest the KeepassXC is the best for all uses, but its sufficient for me in this context.
QuizzaciousOtter@lemmy.dbzer0.com 2 weeks ago
You can have a separate KeePass DB just for your TOTPs.
fizzle@quokk.au 2 weeks ago
Seems s bit extra but ok.
vegetaaaaaaa@lemmy.world 2 weeks ago
Fair enough.
I decided against web/network-based password managers for my personal needs since the additional attack surface is a concern. A Keepass database file synced across machines strikes a good balance for me (requires password + keyfile to open). It’s also simple to backup and protect.
So yeah, for you use case, I’d recommend Aegis Authenticator.