Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This might defeat the purpose of MFA but I use an authenticator like Ente that works on the desktop and syncs to and from your phone.


It does not defeat the purpose as your MFA code/prompt as you are still protected even if someone has your password. The only slightly lesser protection is that if someone gains local access to your machine/password manager then everything is compromised vs. having your codes on your phone, but this should be very, very far down the list of security concerns for the majority of people.

The most realistic security threat for OTP's is that they can be phished in a few ways which is the same problem if you're using MFA stored on your desktop or phone. Hence the preference for physical security keys / passkeys which are impossible to phish.


Thank you, I really appreciate this. I've been looking for something exactly like this for ages, whilst trying to toss my current solution.


It's a great app, open source as well and works everywhere, even on the web. I migrated all my MFA to Ente Auth.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: