logoalt Hacker News

_factortoday at 1:41 PM7 repliesview on HN

You presumably had a working 2fa app already, but off the cuff decide to switch to new unvetted variant X; basically unknown auth system after reading a few paragraphs of text in an afternoon?

Does this seem sound?


Replies

yolo_420today at 1:55 PM

Ente is extremely well known in the privacy circles, so this is not just some random company with a random app out of nowhere. Check PrivacyGuides for example.

show 2 replies
ahofmanntoday at 1:48 PM

While I would have the same reaction, in this case I think it is a sane decision. Ente is cornering the privacy market and I think they're doing a great job. They have a lot to lose (trust) and it would be stupid if they did something shady with the data entered in the 2FA app.

show 3 replies
utopiahtoday at 3:31 PM

What's the risk?

They just store tokens, without other FA at "worst" you get locked of your account but nobody else has access either. You're also supposed to, as good practice, not be limited to token generation and typically have a dozen or so of recovery tokens. Also if they were somewhat not working at doing the 1 task they should do, namely generate tokens, then you won't be able to use them so it won't even be added.

So... I might be missing something, can you please explain what worries you and why I should thus worry too?

deltoidmaximustoday at 2:38 PM

I ended up picking them because they were the only open source one that worked on all my devices IIRC.

https://en.wikipedia.org/wiki/Comparison_of_OTP_applications

testdelacc1today at 4:20 PM

Not saying they’re a paid promoter. But if I paid someone to speak about my newly launched product, they’d say something exactly like that. “Never heard of these guys before, but I loved their other product you’ve never heard of. I’m super excited to try this one!”

zaphod12today at 2:17 PM

if it helps, I've used ente for a year and I really like it.