The Best Two-Factor Authentication App? (iOS)

https://lemmy.world/post/1607715

The Best Two-Factor Authentication App? (iOS) - Lemmy.world

What’s your prefer two-factor authentication app for iOS? I’m looking for an app that offers the best combination of platform compatibility (preferably available on Mac OS, iPad OS, and iOS), security, usability, and reliability. It would be great if the app is open source and has a backup feature as well. I came across a recent Wirecutter article from The New York Times [https://www.nytimes.com/wirecutter/reviews/best-two-factor-authentication-app/]that recommends Cisco DUO Mobile as the top choice, followed by Authy and Google Authenticator. I would greatly appreciate your insights and security perspectives. Thank you!

I really like 1Password as both my PW manager and OTP generator. PWs and OTPs get synced across devices so I never worry about losing my phone and getting locked out of any 2FA sites. On iOS as well as desktop, 1Password can auto-fill passwords and OTP codes. Highly recommend.
Doesn’t this defeat the purpose of multi factor authentication though? If someone got access to 1Password, they could access both your password and secondary authentication code. I think it may be a better idea to keep them separate.
Pretty big “if” since I’m the only one who knows the long password, I rotate it often, and I hold the keys to encrypt everything. You’re right it’s a single point of fail but a LOT would have to go wrong for it to fail.
Whats the point of rotating your masterpassword? Seems kinda like a disaster waiting to happen since you will have trouble memorizing it unless you’re updating/creating an emergency sheet each time. A high entropy passphrase + a hardware security key (the best choice) or totp should be more then enough for years unless technology skyrockets no?
Paranoia, mostly 😅

It could be useful if somebody somehow finds out their password, e.g. by shoulder surfing or perhas some other way.

Then their attack window is much more limited.

1Password has a blog post that talks about it here. blog.1password.com/1password-2fa-passwords-codes-…

Ultimately it depends on your threat model and security vs convenience.

1Password and 2FA: Is it wrong to store passwords and one-time codes together? | 1Password

Many sites support two-factor authentication (2FA). Learn why it’s safe to store your one-time codes in 1Password, and the differences between 2FA and 2SV.

1Password Blog