google-authenticator
gauth
google-authenticator | gauth | |
---|---|---|
24 | 5 | |
4,501 | 304 | |
- | - | |
0.8 | 3.4 | |
over 3 years ago | 2 months ago | |
Java | Go | |
Apache License 2.0 | ISC License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
google-authenticator
-
GitHub will disable non-2FA accounts?
otpauth:// is a de-factor standard, since Google Authenticator uses it: https://github.com/google/google-authenticator/wiki/Key-Uri-...
-
Creating 2fa with pyotp
Random question if you're using TOTP why not just give the user the secret when signing up as a Google Authenticator URI encoded in a QR code? Then you won't need to futz around with sending it to them afterwards. You can even use a library like qrcode.js so you don't generate the barcode server side either.
- why are all the totp secrets different styles?
-
Locker: Store secrets on your local file system.
Locker can generate Time Based OTP codes parsing TOTP urls stored under a special key named totp.
-
Does changing an email that has TOTP setup affect the "secret"?
(Examples> https://github.com/google/google-authenticator/wiki/Key-Uri-Format)
- Google Authenticator open source fork archived
- TOTP tokens on my wrist with the smartest dumb watch
- LastPass gehackt, Nutzerdaten aber anscheinend sicher
- Is google authenticator Private & Secure (Trustworthy) enough to be used for 2StepVerification?
-
Twilio, the people who own Authy, got hacked
If we're talking about the encrypted Authy TOTP secrets and IF they get cracked or guessed, Authy does store the email in the name of the item. Having the name, service and the secret within the QR code's URI is normal and the standard for TOTP. The only thing the hackers won't have is the password.
gauth
- Aegis Authenticator – Secure 2FA App for Android
-
TOTP tokens on my wrist with the smartest dumb watch
I use https://github.com/pcarrier/gauth
It relies on file permissions so is not exactly robustly secure (no idea about RAM vulnerabilities etc).
As per the author, I consider my laptop the fundamental point of vulnerability. If someone else gets access to it, I'll know and I'll hit the metaphorical panic button :)
- Ask HN: Does anyone else think this 2FA everywhere is getting out of hand?
-
Ask HN: Why is today's Internet experience so user hostile?
I was able to take a screenshot of GAuth backups on iPhone using the button hotkeys(IE: Power+Volume up). I setup a container that runs a go version of GAuth and used a python script to decrypt the (decrypted QR code) backup keys. Then I backed up the encrypted keyfile to offline disk, encrypted the container backup and deleted it from the hypervisor.
https://github.com/pcarrier/gauth
https://github.com/scito/extract_otp_secret_keys
-
A simpler and safer future – without passwords
> A future without passwords
No, thank you, especially if Google is going to be the gatekeeper.
https://github.com/pcarrier/gauth FTW
What are some alternatives?
Aegis - A free, secure and open source app for Android to manage your 2-step verification tokens.
ios-application - A native, lightweight and secure one-time-password (OTP) client built for iOS; Raivo OTP!
pyotp - Python One-Time Password Library
totp-cli - Authy/Google Authenticator like TOTP CLI tool written in Go.
keepassxc - KeePassXC is a cross-platform community-driven port of the Windows application “Keepass Password Safe”.
totp-cli - A cli-based pass-backed TOTP app.
tpm2-totp - Attest the trustworthiness of a device against a human using time-based one-time passwords
andOTP - [Unmaintained] Open source two-factor authentication for Android
extract_otp_secrets - Extract one time password (OTP) secrets from QR codes exported by two-factor authentication (2FA) apps such as "Google Authenticator". The exported QR codes from authentication apps can be captured by camera, read from images, or read from text files. The secrets can be exported to JSON or CSV, or printed as QR codes to console.
two-factor-auth - Two Factor Authentication Java code implementing the Time-based One-time Password Algorithm
otp-codegen - Takes your OTP secret in and spits out the 6 digit OTP code