OTP TOTP HOTP 2FA apps in F-Droid

Hi

My F-Droid only shows me mOTP as an App to use 2FA (beside SecureOTP and Copy SMS Code, but these 2 only seem to monitor apps to fill OTPs into the clipboard.

Now trying to use my github account (sorry… but I have a gitlab one too) on my phone I meet issues with mOTP. For sure I was full newby in OPT workflow when I began to use OTPClient on my AMD64 in march 2023 until now when since yesterday I try to understand what is there behind the scene. Some research told me the github secret is given as a Base32 16 digits number. I Read/compared both RFC3548 and 4648, gave some conversion trials with conversion to Hex with hexcalculator.org and dcode.fr and tryied with my own local spreadsheet, tried to generate OTPs hashed with sha1/256/512… still I’m stuck at locking my account for a while after too many login failures. I use my account name as the profile field as account is said mandatory in OTPClient. I’m not sure that is really critical as nowhere I read anything like a credential pair in OTP workflow. Probably I miss something.

Anyone successfully uses 2FA with this mOTP App ?

Thanks for any tips or workaround

many apps: F-Droid Search: otp

more apps: F-Droid Search: totp

and even more: F-Droid Search: hotp

and these: F-Droid Search: 2fa

I mean, what did you search for that you didn’t find these?

1 Like

Sorry. I just searched OTP from within the F-Droid App. Although I found more here at f-droid.org I imagined additional hits where either obsoletes or not compatible with my A15. I give a look at Secur (single hit for for totp search).

Many thanks

And it did the job :heart_eyes:
Fortunately I saved the secret in OTPClient that is able to show it as entered. GitHub hides to us the current one as soon as validated, and only shows a new one waiting for validation.

soon, Conceal Authenticator app, (pending review atm) , should become available, permission-less and decentralize, it will allow you to backup your encrypted shared key on your wallet, on blockchain.

Until I moved all sensitive stuff to my Real Computer ™, I used Aegis from F-Droid for OTP. It worked great.

4 Likes