Authenticator is an open-source 2-step verification app for iOS

Ashwin
Sep 9, 2019
iOS, Security
|
5

When it comes to iOS, open-source apps are something of a rarity but that doesn't mean they don't exist.

If you're looking for an alternative for Google Authenticator, Microsoft Authenticator, LastPass Authenticator, or Authy, you may want to give Authenticator a chance.

Authenticator for iOS

Why? Do you really want to hand over the two-factor authentication process to these big companies or proprietary software?

This is a TOTP (time-based one-time password) app and does not require an Internet connection because of that. The app is probably one of the simplest that you will come across in the niche; it just has the option to add/remove accounts and that is about it.

Well, the only other option that is available is the "Digit Grouping". You can either choose to display the codes in 3 x 2-digit pair groups, or 2 x 3-digit groups. Once you have installed Authenticator on your iPhone or iPad, you will see a nearly blank screen with a few buttons on start.

Adding an account to Authenticator

Authenticator supports adding accounts using QR codes and manually adding accounts.

Refer to your email/social network account's website to set up 2-step verification. Once you get to the page where you are asked to scan a "QR code", run Authenticator and tap on the + button to add an account. Point the camera to the QR code on the computer's screen.

The app should add the account, and display the 6-digit code for it on the screen. Now, most websites which you're setting up 2-step authentication for will require you to enter the TOTP to confirm that it has been configured correctly.

Manually setting up 2FA tokens:

Tap on the plus button, and then on the edit button (note and pencil icon) on the top and you will see a screen which asks for the following:

  • Issuer (website's name)
  • Account name (username@account.com)
  • Secret Key

You can obtain the secret key for your account from its associated website. You can set TOTP or Counter based tokens, and set it to 6, 7 or 8 digits, SHA-1, SHA-256 or SHA-512.

Where it lacks and shines

Personally, I would have liked it if the app asked me for a PIN code or password to unlock the 2FA database. An extra layer of security is always a good idea even if it would rely on TouchID or the device's PIN.

You may reduce the issue by setting the screen timeout to the minimum and not the 2-minute default on iOS.

On the bright side, it does not store your 2FA tokens in the cloud in any form. There is no way to backup (or export) your tokens on the other hand. And the fact that Authenticator is open source, unlike nearly every iOS 2-factor authentication app out there, makes it priceless in my opinion.

A 2-step verification enabled account is nearly hacker-proof, read Martin's article for more information.

Here's some advice regarding 2FA apps.

  • Use an open source app whenever possible.
  • Do not use SMS based 2-factor verification systems (I think Yahoo still uses this) as the text message protocol is not secure.
  • Use an app which works completely offline if possible; this is not only better as it will work in regions with bad Internet reception or if the mobile provider has issues, it is also better for security as you eliminate transfers and don't risk losing access to accounts if you lose your phone or device.
  • It is not a good idea to use the password manager for 2FA as well if the manager supports it as you would put all eggs in a basket. At the very least, make sure you're using separate databases for your 2FAs and passwords. But I'd use separate apps for 2FA and passwords. In case of cloud-based password managers that also support 2FA, think about it. If the password database or service is breached, so is your 2FA.
  • Always have backup or recovery codes at hand in case something goes terribly wrong. Most services support these during creation.

Now You: Do you use two-factor authentication apps?

Summary
Author Rating
1.5 based on 4 votes
Software Name
Authenticator
Operating System
iOS
Software Category
Security
Price
Free
Landing Page
Advertisement

Tutorials & Tips


Previous Post: «
Next Post: «

Comments

  1. Anonymous said on March 2, 2021 at 8:33 am
    Reply

    No me funcionan los codigos que puedo hacer ayuda

  2. Jason said on September 11, 2019 at 8:21 pm
    Reply

    I’ve used this app for a few years for all of my MFA accounts. I like the fact that it doesn’t back up to the cloud – I don’t want Apple (or whoever manages to hack into iCloud accounts) to have that information.

    In order to get around the whole issue of having no backup I printed out all of the QR codes that I scanned during the MFA setup for each site. That way if I have to replace my phone I can just scan them back in.

  3. AuthyUser said on September 10, 2019 at 10:15 am
    Reply

    I still prefer Authy even it’s not open source. I prefer it because I want to have two mobile devices in case one disappears or breaks. Imho multiple device option should be a standard feature.

  4. Anonee said on September 10, 2019 at 6:46 am
    Reply

    Yeah, I used this app like a couple years ago but it was lacking in certain features, like the import/export mentioned above, so I ended up switching to the LastPass Authenticator, which not only is the most feature rich, but it ties in seamlessly with LastPass – my main password manager!

  5. Rob said on September 9, 2019 at 8:13 pm
    Reply

    This app is similar to Google Authenticator in its simplicity. As for me lack of export / import option is deal breaker. I use OTP Auth which is free (with optional one time fee to support developer) which offers:
    – iCloud sync (optional)
    – import / export
    – ability to store key configs in backup (optional)
    – groups / categories
    …and much much more!
    Highly recommended!

Leave a Reply

Check the box to consent to your data being stored in line with the guidelines set out in our privacy policy

We love comments and welcome thoughtful and civilized discussion. Rudeness and personal attacks will not be tolerated. Please stay on-topic.
Please note that your comment may not appear immediately after you post it.