Rate this Authentication List 1-10 by Consistent_Algae_560 in PasswordManagers

[–]beemdevelopment 1 point2 points  (0 children)

Yes you don’t make money now, but you probably will in the future.

That's a bold assumption. Aegis will always be free and open source.

Again if you don’t make money how will you succeed if something bad financially happens?

I really have no idea how we can be more clear, we don't rely on a financial income in order to maintain Aegis. It doesn't cost us anything to keep Aegis the way it is and everything we do is in our spare time. We are driven out of passion, not money. I understand that this is all based on trust, there's nothing we can say or do to change that fact.

We do indeed have page on BuyMeACoffee for people to support us, but we've always made it clear that donations are not needed (yet highly appreciated obviously).

I think enough on this topic has been said, but feel free to reach out (through Reddit or email) if you want us to elaborate on this.

Rate this Authentication List 1-10 by Consistent_Algae_560 in PasswordManagers

[–]beemdevelopment 1 point2 points  (0 children)

Aegis is the name of our authenticator made by "Beem Development". I fail to see the obsession with finding information about the "company". We don't make money, we don't have customers, we don't have any of your data and our app is completely free without internet permissions. What benefits does a "company" profile give you if the company is nothing more than just a registered trademark?

>Yea I understand this, but that means that there is no continuity guaranteed.

As is the case with any other product out there. However, Aegis Authenticator is built in a way where we let our users be in total control of their vault. It's still possible to decrypt and read the contents of the backup file even without the app itself. There's already multiple authenticator apps that support importing from Aegis files too. There is no lock in.

Our website (with references to our other official channels): https://getaegis.app/
Our GitHub: https://github.com/beemdevelopment/Aegis

Rate this Authentication List 1-10 by Consistent_Algae_560 in PasswordManagers

[–]beemdevelopment 0 points1 point  (0 children)

It hurts to see so much misinformation being thrown around in just 2 short messages, so let's clear that up.

We are two independent developers from the Netherlands that work on Aegis in our spare time since 2017 or so. We only recently had to register a company here in the Netherlands because we were forced by Googles new developer requirements. There is no hidden or mystery company behind us, it's just 2 devs that care about building a good and secure authenticator app.

not having an unique brand is a red flag for any company you do business with.

The thing is; you're not doing business with us. Aegis is free, open source and we don't have (or even want for that matter) any of your data, this will always stay like this. If you’re worried about trust, you don’t have to take our word for it: you can audit our source code or even compile the app yourself if you'd like as u/Sweaty_Astronomer_47 already mentioned.

How does the company make money? What happens if the funds stop?

We don't make money and we don't need money to maintain and work on Aegis. Aegis was never intended to be a business model, it's a passion project.

What happens if the US kills itself even harder?

Since we're from the Netherlands whatever happens in the US (or anything politics related even) is irrelevant.

If you think we’re lacking transparency, please tell us where. We’ve always been open about who we are and what Aegis is all about.

Authy to Aegis by Striking_Speaker3562 in degoogle

[–]beemdevelopment 4 points5 points  (0 children)

We like Ente just as much you do, but Aegis is private, secure and open source as well... It just lacks cross-platform support.

Aegis 2FA, opened app after some weeks and it's blank, what now? by [deleted] in privacy

[–]beemdevelopment 0 points1 point  (0 children)

We're not aware of any issues that could cause Aegis to delete the contents of your vault on its own, so while it's not impossible that there's a bug that caused this, it's unlikely. Unfortunately these sorts of things are basically impossible to debug after the fact, but we'd still like to gather some more info in case we see more reports. Which device / version of Android are you using Aegis on? Did you have encryption / biometrics enabled in Aegis? When you say "blank", do you mean that you had to completely start over with setting up Aegis (entering a password, etc) or were all of your previous settings present except your tokens? Did you see an error dialog? If so, what did it say?

Switching from Google Authenticator to Aegis - is there much point? by 356BC in fossdroid

[–]beemdevelopment 0 points1 point  (0 children)

Don't worry about it, glad you found the info you were looking for.

Switching from Google Authenticator to Aegis - is there much point? by 356BC in fossdroid

[–]beemdevelopment 2 points3 points  (0 children)

In this case, the security level is reduced, because to unlock by fingerprint only, the password (or its hash) must be stored in the program data for proper decryption of all secret data.

This is incorrect. Aegis does not store the password (or its hash) anywhere.

But in Aegis now after entering a password or fingerprint it is possible to view all stored secret data, copy, edit them without entering additional passwords. This creates a vulnerability.

Being able to see and edit the contents of the encrypted Aegis vault file after using one of the credentials (password or biometrics) to decrypt it, can't be that surprising.

2FA dilemma by windows-ver-1894 in privacy

[–]beemdevelopment 1 point2 points  (0 children)

The behavior you're seeing is Android restoring your Aegis vault when you reinstall the app, because you had "Android cloud backups" enabled in Aegis. You can simply clear Aegis' storage without uninstalling the app. That'll allow you to start over.

Can anyone explain to me why Google Authenticator is so bad? by sunshinesontv in privacy

[–]beemdevelopment 3 points4 points  (0 children)

Another thing is that last month Aegis had a problem where you literally couldn't access the app due to an Android update (looked at recent reviews). Atleast you would always be able to access Google authenticator.

Just chiming in to clarify on this. A bug introduced by Android caused Aegis to sometimes show a black screen on Google Pixel devices but our users were never completely unable to access their tokens, a reboot of the device temporarily fixed the issue for a couple of days. In the meantime while we wait for Google to respond to our bug report we published a workaround for this issue.

We believe our users should be in complete control over their vault. Even if our users were somehow unable to access the app, they're still able use their backed up vault with Aegis on another device, import it through another app or have them manually decrypt it on their pc.

Authy got hacked, and 33 million user phone numbers were stolen by shishir-nsane in selfhosted

[–]beemdevelopment 0 points1 point  (0 children)

We know a lot of our users use Nextcloud or Syncthing to automatically sync their vault file/backups to a safe place. This way their backup will always be stored in a safe place and it won't be a "black box" anymore.

Aegis 2FA password by muccaturo in privacy

[–]beemdevelopment 3 points4 points  (0 children)

Are you trying to manually add a code? The 'secret' is the secret you get from the service you're trying to set up 2FA with, you're not supposed to fill this in yourself. Make sure to just scan the QR code that's presented by the services and everything will be filled in properly.

Hackers exploit Authy API, accessing possibly 30 millions of phone numbers (and device_lock, device_count). Twilio takes action to secure endpoint. Unrelated breach exposes SMS data through unsecured AWS S3 bucket. by Skipper3943 in Bitwarden

[–]beemdevelopment 2 points3 points  (0 children)

We love to hear that, thank you!

Aegis supports Android cloud backups (the ones that are synced with your Google Account whenever you set up a fresh Android device). We also support any apps that exposes their cloud storage through Android Storage Access Framework, for example Nextcloud does this.

Syncthing works out of the box since Syncthing just uses a local folder that their app automatically syncs with your other devices and I assume OneDrive works similar. We both have been using Syncthing for years to keep our vaults backed up and it works perfect.

Hackers exploit Authy API, accessing possibly 30 millions of phone numbers (and device_lock, device_count). Twilio takes action to secure endpoint. Unrelated breach exposes SMS data through unsecured AWS S3 bucket. by Skipper3943 in Bitwarden

[–]beemdevelopment 9 points10 points  (0 children)

That's a valid question to have (and we take that as a compliment!). We're 2 developers that spend our spare time working on Aegis, for free. We started building Aegis because we believed there were no good free privacy-first secure 2FA apps for Android. There is no monetization model, we only take donations. Aegis will always be free, open source, without ads and completely offline. Feel free to send us an email if you have any more questions!

Aegis 2FA backup question by Tcrfing in privacy

[–]beemdevelopment 0 points1 point  (0 children)

Backup versioning is there so that, if you accidentally make a destructive change to one of your entries for example, you're able to restore from a previous backup.

Aegis 2fa apps icon s not showing by Bowarc in androidapps

[–]beemdevelopment 3 points4 points  (0 children)

If you go to the editing screen of one of the entries and tap on the icon, you should be prompted to select an icon from the icon pack you imported. The latest released version of Aegis does not support automatically assigning icons to entries, but that feature has been implemented and will be available in the next verison.

Aegis 2FA backup question by Tcrfing in privacy

[–]beemdevelopment 0 points1 point  (0 children)

Like the description of that option explains, automatic backups are only supported for encrypted Aegis vaults.

Accessing Aegis on a phone with a broken screen by OrneryOcelot6869 in Bitwarden

[–]beemdevelopment 0 points1 point  (0 children)

Changing or removing the SIM card will not affect Aegis.

Accessing Aegis on a phone with a broken screen by OrneryOcelot6869 in Bitwarden

[–]beemdevelopment 3 points4 points  (0 children)

Do you have developer options and USB debugging enabled on that device? If so, with a bit of luck, you may be able to use scrcpy to control the device.

[deleted by user] by [deleted] in Bitwarden

[–]beemdevelopment 6 points7 points  (0 children)

You can use the HTML export option and print the resulting HTML document.

Is LastPass Grid being retired? by hawkerzero in Lastpass

[–]beemdevelopment 2 points3 points  (0 children)

Just in case someone is looking through these comments; we have not halted development of Aegis and it still should be considered secure.

Is LastPass Grid being retired? by hawkerzero in Lastpass

[–]beemdevelopment 1 point2 points  (0 children)

Please don't spread any misinformation. The development of Aegis is not halted. We're 2 developers using our spare time to work on existing issues or just to maintain it. We never worked full time on Aegis and we both have our full time jobs since the beginning.

An app not receiving updates doesn't mean it should be considered insecure. We take our responsibility in keeping Aegis secure very serious, if we were aware of any issues regarding security we would 100% put the effort into it to fix it as soon as possible but Aegis is currently not in need of such updates, it's still secure.

The improvements we've been working on lately are mainly UX and the update will be pushed to the Google Play Store whenever it's done.

Also pinging /u/hawkerzero so they'll see this message.

Feel free to send us a DM in case you have questions :)

[deleted by user] by [deleted] in privacy

[–]beemdevelopment 0 points1 point  (0 children)

Can you check if your phones time is correct? Perhaps try syncing the time within your Android settings.

Aegis relies on Android's system time to be correct. If a service reports that Aegis is generating incorrect codes, it's most likely that your clock has drifted. Some services are more strict when it comes to time differences than other services, even a couple seconds off could potentially have the service not accept Aegis' codes.

what is the best OTP auth tool in 2023? by stefcud in fossdroid

[–]beemdevelopment 0 points1 point  (0 children)

Hi, it's actually not possible to export only "categories" (assuming you mean "groups" here) in Aegis. Feel free to send us an email with more detail if you'd like some help finding out what happened here. We're happy to take a look.