Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
I use the Authenticator feature in Apple's Keychain. It syncs between iOS/iPadOS and MacOS and I keep the verification codes in the Notes/Comments field. iOS backup acts as insurance. And (for now) I trust Apple more than Google (Authenticator) or Microsoft (Authenticator). I did consider BitWarden, but why bother when Keychain is ubiquitous?

Hopefully you have a strong (20-30 character) passphrase on your apple ID, and are never a victim of passcode shoulder surfing. The problem with putting this passwords in an ecosystem with other data (especially email) is that you're reliant on the least secure fallback authentication method. Even Apple's recovery key's are now being abused to lock out accounts.

No thanks, I'll stick with 1Password.
 
For something as important as 2FA, you'd think Google would pay more attention to this critical app.
 
LOL. Storing your codes on a google server is just asking to be pwned, all online services get breached eventually

The entire point of OTP's/authenticators is that it happens ON YOUR DEVICE where nobody else can access it
 
LOL everyone is complaining about storing stuff on Google's server.

The first mistake is using any Google product in the first place.
 
It's great that Google finally added a backup feature to Google Authenticator after all these years, but it's too late, and are the backups encrypted with a different password? What about a recovery key?
 
Good thought but about 4-5 years too late. Got tired of losing all my 2FA keys when I restored my iPhone, got a new one, etc. and moved to Authy instead.
 
I've avoided Google Authenticator ever since I set it up to authenticate an important work account and one day it just stopped authenticating. I won't say I'm a Duo fan, but at least that actually works reliably.
I'm really disappointed in what Microsoft Authenticator is doing to their product so I am trying Google's for awhile on a few users accounts. So far I kind of like it, escially the capability of transferring an account between phones when you get a new one. Microsoft's one can't transfer from an iPhone to an android phone, no matter how much you want it to.
 
I use the Authenticator feature in Apple's Keychain. It syncs between iOS/iPadOS and MacOS and I keep the verification codes in the Notes/Comments field. iOS backup acts as insurance. And (for now) I trust Apple more than Google (Authenticator) or Microsoft (Authenticator). I did consider BitWarden, but why bother when Keychain is ubiquitous?

Yes, I'd use the macOS/iOS/iPadOS/iCloud Keychain too if I wanted automated syncing or cloud backup for my OTP code generation. But my privacy and security preferences lead me to go with storage that is under my full control at all times and to not use any outside services to transfer critical information.
 
Do you guys honestly think Google employees will be using your 2FA keys to login to your accounts?

I mean... if you want to completely disregard the fact that hackers exist and that Google would happily hand over your keys to a government for whatever reason they come up with, then yeah... I guess you're safe letting Google store your 2FA keys.
 
I use the Authenticator feature in Apple's Keychain. It syncs between iOS/iPadOS and MacOS and I keep the verification codes in the Notes/Comments field. iOS backup acts as insurance. And (for now) I trust Apple more than Google (Authenticator) or Microsoft (Authenticator). I did consider BitWarden, but why bother when Keychain is ubiquitous?
Came here to write the same.

Except never would use a 3rd party authenticator or p/w manager.

Everywhere Authy or goog authenticator works so does iCloud Keychain’s authenticator.
 
Most people don't trust Google and for good reason.
Google is still tracking people using their fonts. :rolleyes:
 
I have used Authy ever since I had an issue with my phone and had to reset all my Authenticator codes.

Also like how it works cross-platform.

I use 1Password for storing usernames/passwords. Is there an advantage to using Authy for OTPs, and 1Pass for credential storage? I feel like having OTPs in 1P, means if 1P ever gets breached (bound to happen someday), then the OTPs get breached also.

Thoughts?
 
I have used Authy ever since I had an issue with my phone and had to reset all my Authenticator codes.

Also like how it works cross-platform.

I use 1Password for storing usernames/passwords. Is there an advantage to using Authy for OTPs, and 1Pass for credential storage? I feel like having OTPs in 1P, means if 1P ever gets breached (bound to happen someday), then the OTPs get breached also.

Thoughts?
I use Raivo for 1Password. I’ve been trying out ente Authenticator and that is cross platform, and looks promising.
 
Bitwarden started to offer TOTP in their app and I think its time I start to migrate from Authenticator to them.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.