this post was submitted on 13 Oct 2025
125 points (97.7% liked)

Selfhosted

62050 readers
1238 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

One more step to unhitching from Google...

Right now the only option I see in F-Droid is Aegis.

I'm not sure what to actually look for side from checking for unexpected permissions and reasonably frequent updates.

Hopefully something I can sync with a GNOME app...

(page 2) 50 comments
sorted by: hot top controversial new old
[–] NotMyOldRedditName@lemmy.world 3 points 11 months ago

Yubikeys. I think everyone should get a couple (need 2 in case 1 lost)

[–] nickiam2@aussie.zone 3 points 11 months ago

Yubikey. It supports TOTP as well as passkeys. Plus is a physical device separate from my phone. Recommend getting 2 to have 1 as backup

[–] BruisedMoose@piefed.social 3 points 11 months ago

Adding to the Aegis chorus.

I also use Proton Pass for some sites that aren't as critical for me / don't have a bunch of PII. It's easy.

[–] Lettuceeatlettuce@lemmy.ml 3 points 11 months ago

Aegis for time codes, Nitrokey for physical 2FA tokens.

[–] arox@lemmy.frozeninferno.xyz 3 points 11 months ago

What you mean syncing with Gnome app?

[–] ceiphas@piefed.social 3 points 11 months ago

i use Mauth

IIRC it can sync by storing the Data in a file you can sync with a tool of your choice

[–] Redex68@lemmy.world 3 points 11 months ago* (last edited 11 months ago)

I personally use Ente Auth and quite like it, don't use syncing and save an encrypted copy to my PC. I really like that you can see what the next code will be.

[–] maxwellfire@lemmy.world 3 points 11 months ago (2 children)

I use bitwaarden and stratum since it has a wearos app as well and it's nice to use that for 2fa codes

[–] StopSpazzing@lemmy.world 1 points 11 months ago

Started testing out stratum recently...

[–] magguzu@midwest.social 1 points 11 months ago

Had to scroll too far for Stratum! The watch app is also why I use it so that I can keep my phone far away from me while I work. Game changer. Surprised more don't use it.

[–] MrSulu@lemmy.ml 2 points 11 months ago
[–] Smash@lemmy.self-hosted.site 2 points 11 months ago
[–] jcolag@lemmy.sdf.org 2 points 11 months ago

I primarily use GNOME Authenticator, but after an inopportune crash, I now also run 2FAuth on my home server as a backup, and now just hope that I remember to do the export/import dance going forward.

[–] Jayjader@jlai.lu 2 points 11 months ago (1 children)

I use pass for my passwords, and it has an otp extension that I've been using more and more. I used to use aegis but I have needed to switch phones one too many times without having access to the previous phone to be comfortable with phones for 2fa.

Of course, this isn't as secure as a truly separate OTP solution, but it's still better than no OTP/2FA. And I can easily enough back up and restore my 2fa access over the internet, even on a new computer (albeit I need to also backup a PGP key that can decrypt the password store to truly be portable).

[–] erock@lemmy.ml 1 points 11 months ago (1 children)

This is what I do. If someone can figure out pass with my password protected gpg, plus my passwords are partials (I salt them), and otp then they can have my access

[–] Jayjader@jlai.lu 1 points 11 months ago (1 children)

plus my passwords are partials (I salt them)

I'm curious how you make that work - do you just remember the salts, store them separately, or what? I have like 50-70 passwords in my store currently, there's no way I'm remembering a (true random) salt for each one.

[–] erock@lemmy.ml 2 points 10 months ago

My salt is just a memorized password I put in addition to the one stored in pass

[–] ayyo@sh.itjust.works 2 points 11 months ago

I used aegis for a long time, switched to protons after they introduced it. Ideally I'd be using something physical though like a yubikey

[–] sternecker@infosec.exchange 1 points 11 months ago

@BonkTheAnnoyed Proton makes one, Bitwarden makes one

[–] pjusk@lemmy.dbzer0.com 1 points 11 months ago

Woahhh defo not enough love for Ente Auth in tgese comments. Highly recommend! Its got a beautiful and intuitive UI, completely open-source and is back by super active devs and community 💚

[–] jbk@discuss.tchncs.de 1 points 11 months ago (1 children)

since no one mentioned andotp i might have to move away from it…

[–] sfjvvssss@lemmy.world 2 points 11 months ago (1 children)
[–] jbk@discuss.tchncs.de 1 points 11 months ago
load more comments
view more: ‹ prev next ›