Hacker News new | ask | show | jobs
by stygiansonic 2728 days ago
Sorry to go off on a tangent, but do you recommend Authy instead/because of this?
3 comments

Jumping in to reply because I made the switch to Authy about two years ago and haven't looked back. You get the ability to sync MFA across devices and desktop without a hitch. Add in the backup (with encryption) and you can onboard a device quickly and it fits every use case I need.
Couldn't you just use Yubikeys to hold your TOTP secrets? If you want redundancy, just set up 2 or 3 and keep the extras safe.
I actually just completed a migration from Authenticator to Authy. I don’t have much to say except that it was pretty seamless. Sync between multiple devices works very well. I’m not a fan of the Authy UI but it does what I need.

If you use a password manager that supports OTP tokens (lastpass with their authenticator app, 1password, bitwarden) you could just use that and remove Authy out of the picture.

You really shouldn't be storing OTP tokens in your password manager. Yes it's better than nothing, but if your password manager vault gets compromised your 2FA does nothing to stop it.
If my password manager vault gets compromised I have bigger problems than my OTP codes.
I full throatedly recommend authy.