After everything that has happened with Raivo over the last few days it’s reminded me that I need to go through my accounts with 2FA enabled.

However, how do others keep things organised? My main 2FA app is Proton Pass but I’ll be adding Ente Auth as a backup alongside my Yubikey. In the past I saved a copy of the QR codes when setting up 2FA but I’d occasionally forget to save new ones.

Does anyone have a good system for saving either the QR code or setup code (not actually sure what it’s called) for future use?

EDIT: the code I’m referring to is the initial secret code used to setup the 2FA

Final Edit: I’ve settled on saving the QR codes into a folder that is setup as a git repo.

    • UID_Zero@infosec.pub
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 year ago

      Same, but my seeds are stored in a separate vault from my passwords. Seems like having MFA and passwords in the same place defeats the purpose. I used to let keepassxc auto fill MFA tokens, but finally changed to a separate app.

  • mcmodknower@programming.dev
    link
    fedilink
    arrow-up
    8
    ·
    1 year ago

    I have the backup codes for the accounts on paper. This is not the same as the initialization qr codes, but it should also work.

  • Onno (VK6FLAB)@lemmy.radio
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    1 year ago

    The 2FA codes are just images. You can save them where you like. No requirement to backup your 2FA “to the cloud”.

    Just make sure that your storage is backed up.

  • Otherbarry@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    1 year ago

    Screenshot the QR codes & save offline to a USB disk. Alternatively some people do print them but that only works for people that have printers or access to one. Same with the 2FA backup codes.

    Or less ideal you can save them somewhere secure on your desktop/laptop/whatever, just keep in mind if you get hacked or get malware/whatever then it’s game over.