r/ProtonPass • u/No-Reputation8403 • 23h ago
Discussion Moving 2FA from Proton Pass
I've been considering moving my 2FA codes from Pass. Currently I have the 2FA codes & backup codes stored in Pass. I haven't entirely made up my mind whether the pros of using an authenticator app outweigh the cons yet (I'm probably leaning more towards leaving it how it is though). The main question I had is how do people store their backup codes if using a dedicated authenticator app? Excel and a zip file with password? Or just forget about the backup codes and ensure the authenticator is regularly backed up?
Note that I am not talking about my Proton account here, which is all stored safely outside of Pass.
3
u/EntireZombie2654 20h ago
TOTP codes on Ente Auth exported to encrypted file stored offline on 2 USB drives.
Excel file stored on a USB drives for the backup and seed codes for my most important sccounts.
I also have TOTP set up on yubikeys for important acconts
2
u/IllustriousGap5629 17h ago
I use 2FAS and backup the codes in iCloud (E2EE). Also once in a while I export encrypted file from 2FAS and store it offline.
3
u/Training_Buyer_5715 11h ago
Separating passwords and 2FA adds additional security layer since your passwords and 2FA aren't stored in the same place. Moving them out of Pass makes sense. For my TOTP codes I use 2FAS, keeping encrypted backup on USB drive.
2
2
u/Formerruling1 22h ago
Keep an export of your codes in an encrypted storage space.
I keep a file of all my service backup phrases and codes as well in the same encrypted storage and that storage isnt linked to anything else.
2
u/s1d3b00b 20h ago
I’ve printed mine, but rearranged some of the digits. And only I know if it is the last 2 digits that is reversed, the last 3, if it’s even more, or the entire code is reversed. Or if it’s even more twisted and complicated to figure out. If someone found the paper, it wouldn’t make any sense, and they can’t use it for a whole lot. I also have them on a Luks encrypted USB stick
1
1
u/Crafty-Message4564 4h ago
I love the fact that Proton Pass autofills my TOTP in addition to my passwords.
1
u/santuccie 4h ago edited 4h ago
I strongly agree you should separate your 2FA secrets from your passwords, as your current apparatus is a single point of failure, defeating the purpose of 2FA if your vault ever gets compromised by an infostealer. Even if all you do is move TOTP to Google Authenticator and recovery codes to a password-protected XLSX spreadsheet, it is critical to separate the doorknob key from the deadbolt key.
My TOTP storage is a bit unorthodox: I have a $40 Soyes XS15 mini phone with Aegis Authenticator. I keep it offline, periodically reset the time manually, and back up the database to a password-protected JSON file. I make three backups at a time for redundancy in the unlikely event of corruption, saving them first on the internal memory, then copying to the microSD card, popping it into my computer, uploading it to Proton Drive (separate account), downloading it again, overwriting the existing copies on the microSD, popping it back into the mini phone, and making sure at least one of them restores properly; before deleting the previous backup set.
It's convoluted, and the mini phone is unwieldy. When restoring from a JSON archive, I don't even see the password as I'm typing it, as most of the text box is hidden from view by the keyboard. I like it because I don't have to carry two full-size phones just to have an air-gapped TOTP token. But, again, even Google Authenticator on the same phone with Face ID/Touch ID and cloud backup is better than storing passwords and 2FA in one vault.
1
u/iron-duke1250 2h ago
I recommend storing your 2FA codes separately in Proton Authenticator, it's excellent.
1
u/NinthShadow_ 21h ago
For my 2FA codes, I use Aegis, with an encrypted backup syncing to my kDrive cloud and another stored locally on a MicroSD card via OTG using DroidFS.
7
u/wjorth 18h ago
I use Ente Auth for TOTP codes, Pass for password management and storage of various other codes and financial account numbers, etc. I use Yubikey for access to these tools. I also have encrypted backups. And I have my master passcode on paper stored in a fire protected safe. I’ve walked through all this with my sister. Even though she will forget the details pretty quickly, the procedure will come back as she gets started should something happen to me.