home.social

#aegis — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #aegis, aggregated by home.social.

  1. #DUTgemacht am 1. Sonntag im Mai: ich habe meinen Authentificator getauscht.
    Jetzt du: Microsoft oder Google Authenticator gegen eine europäische, Open Source Alternative tauschen.
    #aegis
    #diday #digitalesouveränität #opensource

  2. Det här var riktigt coolt. TOTP från tvåfaktorautentifieringsappen Aegis kan exporteras till lösenordsdatabasen KeepassXC!

    linux.org/threads/in-depth-tut

    #FOSS #KeepassXC #Aegis

  3. @samy_crypto @kuketzblog Ja, #aegis ist eine Top-App. Nutze ich schon lange und kann sie uneingeschränkt empfehlen.

  4. kidwarp @npub1kyeml3tma4su8yw5aru48wgxclchp8zr3kguwhakmtmegjw40zws82sfjk@momostr.pink ·
    Can’t login into to #ditto w/ #aegis on iOS
  5. Mi rispondo da solo, per aiutare i posteri :speech_balloon:

    Cercavo un provider #PEC che consentisse autenticazione a 2 fattori tramite app di terze parti (G Auth, Aegis...).

    Aruba e Ionos/Namirial obbligano alla loro app proprietaria.
    L'unico che lo consente pare essere #Libero (e forse #Virgilio, stesso gruppo #ItaliaOnline).

    #2FA #autenticazione #sicurezza #email #Aruba #Namirial #Ionos #Libero #TOTP #GoogleAuthenticator #Aegis

  6. Built a production SOC for my home/mobile infra. Sharing it.

    #AEGIS is a unified threat intelligence platform running on a single Linux server:

    → DNS sinkhole (port 53, custom blocklists)
    → Suricata IDS in AF-packet passive mode + ClamAV on filestore
    → Zeek NSM (http, ssl, dns, conn, weird, notice)
    → ModSecurity WAF — OWASP CRS 4.22, full enforcement
    → Fail2Ban + auditd
    → Rust orchestrator aggregating all event sources into one REST/WS API

    Auto-heal watchdog, anti-DDoS engine with dynamic iptables injection, real-time dashboard.

    One thing I wanted to get right: the orchestrator never touches iptables with NFQUEUE — passive only. No inline mode that can brick SSH access.

    aegis.centurialabs.pl

    #infosec #SOC #homelab #Suricata #Zeek #Rust #threathunting

  7. @vicgrinberg Ja, das stimmt. Irgendwo habe ich gelesen, daß der authenticator bei bestimmten MS Logins Pflicht ist, oder als Pflicht konfiguriert werden kann. Das macht dann ggf. die grapheneOS Nutzung schwieriger. Besonders, wenn Arbeitgeber*innen eine restriktive login policy mit "bring your own device" für 2FA koppeln 🤦 und dann das sicherste OS nicht genutzt werden kann 🙄

    #microsoft #itsec #itsecurity #graphenos #totp #2fa #aegis #diday #DigitaleSouveränität

  8. RE: chaos.social/@jonty/1161539646

    Someone calling themselves #Veritas is running what amounts to an “AI” enabled protection racket they’re calling #Aegis . They claim critical vulnerabilities and then refuse to disclose unless your project pays them nearly $300 dollars.

    Given the extremely poor work done by #LLM in evaluating code so far, it’s extremely unlikely that the LLM identified any real vulnerabilities. But, as a responsible developer, you’d be hard pressed to completely ignore these claims unless you’d already dealt with spurious LLM claims against your code.

    #Technology

  9. @plantarum @veronica
    I'm using #Aegis installed from @fdroidorg and it works without any problem. I'm syncing encrypted keys with my @nextcloud instance

  10. #Aegis users, the aegis icons project has now been revived. If there is a service that you use and have made a vector icon, please submit a pull request. It may take some time to revive and bring the project upto scratch.

    New releases will be monthly

    aegis-icons.github.io

  11. Update bis jetzt:
    * Copilot 365 (aka MS Office Abo 🤦‍♂️) nicht verlängert! 😀
    * OneCloud fast komplett leergeräumt
    * 2FA von Google-Authenticator zu #Aegis migriert
    * #Firefox + #Vivaldibrowser
    * #Ecosia als Suchmaschine
    * #Posteo Email und #Tutamail Erprobung
    * GooglePhotos-Daten als Offline Backup runtergezogen (für später #Immich)
    * WhatsApp? Elterngruppe will nicht wechseln 😫
    * facebook, X, Instagram gelöscht, #Mastodon, #BlueSky
    * Passwörter: NUR #Keepass (nicht mehr bei Google, MS, etc)
    👍

  12. @davemosk cool to see another nice #libre entry. I've been using the superb #Aegis (getaegis.app/ - I installed it via F-Droid) for quite a few years now. Works very nicely, and it's easy to back up even if Google is disabled on ones phone.

  13. It’s an exciting #FieldworkFriday for me today — I’m travelling from -2 °C snow in Denmark to 22 °C in Najaf, #Iraq!

    Together with my colleagues Tobias Richter from Copenhagen and Jaafar Jotheri from Al Qadisiyah University, I’ll be scouting out potential sites for future fieldwork as part of #AEGIS (aegisearth.bio). It’s my first time in Iraq so I cannot wait to finally see all the places I’ve been reading about since I was student!

    #Archaeology

  14. @[email protected] @[email protected]

    Bei
    #Aegis kann man die Einträge auch über einen #QRCode in eine andere #OTP App (auf einem anderen Gerät mit Kamera) übertragen und dann in beiden nutzen.
    Oder eben den ganzen Export woanders wieder importieren.

  15. I'm proud of my mom. Spotted a #phishing email from "websupport" for the company website from a wrong domain saying the payment didn't work. Just asked me to confirm all was well. And then did a "Of course I didn't click the link in the email. I opened the websupport admin panel separately and used my 2FA from #Aegis to confirm payments were OK".

    Yessss

  16. • Gestionnaire de Mots de Passe : Google Password Manager → Nextcloud Passwords
    Apps : Nextcloud Passwords sur téléphone , extension Mozilla Nextcloud passwords sur PC.

    • Authentification 2FA : Google Authenticator → #Aegis Authenticator
    Authenticator open-source.

    • Localisation d'Appareil : Google Find My Device → Nextcloud PhoneTrack
    Suivi des trajets et localisation des appareils enregistrés.

    • Domotique : Google Home → @homeassistant
    Home Assistant est installé sur le mini-PC.

    5/13

  17. @ac @ente @elementary That's a interesting tool, it lists many niche options also, like the convenient email provider Migadu 👌 I made one about me too, it was fun! As DNS I usually prefer OpenNIC but it's not listed, I will open a pull request as well

    #migadu #proton #kagi #zenbrowser #simplex #logseq #gopass #aegis #nextcloud #fdroid #homeassistant #osmand #matrix #archlinux #endeavouros #lineageos

  18. Buongiorno popolo del Fediverso...
    quanti di voi utilizzano programmi per la creazione di password e software 2FA per la creazione di codici OTP?

    programmi come #bitwarden #vaultwarden e #Aegis

    #CyberSicurezza #fediverso #poll

  19. Im Rahmen meines Umzugs von #bigtech nach #GraphenOS konnte ich heute den nächsten Schritt abschließen. Die #Zweifaktorauthentifizierung Apps (jetzt: #aegis) und Banking Apps sind jetzt alle hier und laufen! Zuletzt war die @glsbank dran, mit der #SecureGo APP. Diese hatte die #Briefpost Zustellung eines Aktivierungscodes erfordert.
    #unplugtrump #deapple

  20. I upgraded my phone, from a #pixel6a to a #pixel9a. I'm surprised still how difficult the OS and apps make these transitions:
    - Forgotten notification sounds and alarms
    - App notification preferences
    - Applications that don't persist their settings and data - ugh!
    - Wifi, Google Wallet cards, etc

    Kudos to app devs who take care of this. Like the 2FA #Aegis app and the rShopping List app - seamless.

  21. If you are like me, then you might have installed the #GoogleAuthenticator app, back in the days when it was the only solution out there for #TOTP #2FA.

    But that is long ago. Since then, #Google has closed-sourced it's solution, forced #cloudsync otto it's users and stores these information unencrypted; plus it's suspected to collect even more data from you than needed. And it's a US BigTech company.

    I've looked into a couple of alternatives and landed with #Aegis and #EnteAuth which are both excellent #free #opensource choices from #europe. I went with @ente because of it's larger platform support.

    So why are you not already using an alternative? It's super easy, and took me less then 10 minutes:
    1. On GoogleAuthenticator go to the ☰
    2. Select transfer codes
    3. Select all the codes you want to transfer --> Google will create a number of QR-Codes, each containing 10 accounts.

    On your alternative say import, and scan the Google codes and you're good to go and can let go of yet another proprietary US BigTech dependency (and thus liability).

    If you are already using a different #TOTP #2FA app on your smartphone, which one is it, and why?

  22. Uwolnić Smartfona: Aplikacje

    Wpis ten poświęcę podstawowym aplikacjom, bez których cięzko byłoby używać naszego smartfona na co dzień. Od przeglądarek, przez komunikatory na widżecie pogody kończąc.

    wolnoscwkieszeni.pl/uwolnic-sm

  23. A lot of banks in the Philippines still rely on SMS for #2FA, despite how insecure it is—easily spoofed, intercepted, and unreliable. Some use in-app confirmations via their mobile app, but if you lose access to your phone, you're probably locked out. Why not support standard authentication apps like #2FAS, #Aegis, #Bitwarden, #Vaultwarden, or #KeePassXC, which have TOTP support and easy backups? That way, I wouldn’t have to worry about losing access. #MFA #MultiFactorAuthentication #Security

  24. Empfehlenswerte Apps für #2FA / Zwei Faktor-Authentifizierung, die sicher und #FreieSoftware sind:

    #Aegis (Android, verschlüsselt, lokal auf deinem Gerät)
    getaegis.app/

    #Ente / #EnteAuth (verschlüsselt, Sync per Onlinedienst, kann selbst gehostet werden):
    ente.io/download
    (2/2)

    #FOSS #FreeSoftware #Security

  25. Millions Of #Google, #WhatsApp, #Facebook #2FA Security Codes Leak Online forbes.com/sites/daveywinder/2

    #PIN via #SMS (or #email) is a stupid idea anyway.

    Best case: #FIDO2 hardware tokens. Well invested ~20-50€.

    If you can't, use #PassKeys if you absolutely trust the service provider.

    Both protect against phishing.

    If not, use a trustworthy #TOTP app (#GoogleAuthenticator is NOT trustworthy any more!) like: #FreeOTP #Aegis

    Other 2FA methods are more or less insecure.

    #security #authentication

  26. 🚀A very nice article on 20 years of Federated Identity Management by @klaas, Christos Kanellopoulos and Cathrin Stöver of @geant

    🎉 i'm happy and honoured to contribute to this work via @SURF

    🌐 connect.geant.org/2023/09/20/2

  27. @kirschner #AntennaPod for Podcasts, #Fedilab for Mastodon and Fediverse, #Transistor for my daily #Dlf radio needs, #Aegis for #2FA, the recent version of #AnkiDroid for learning via flash cards, #SimpleGalleryPro for media management. #Auxio as a simple yet nice looking audio player. #OrganicMaps as an simple alternative to the mighty #OsmAnd. #NewPipe for my video streaming needs (even though #LibreTube is a very fine alternative when it exclusively comes to #YouTube), #Quillpad for taking notes, #KeePassDX as password manager. #DAVx5 to get stuff synchronized, #FairEmail as email client. #Feeder for my RSS feed needs. And finally the still new #FDroidBasic client allowing automatic updates of installed apps.

    Recently tried out #SimpleX messenger and like it quite a bit so far. @fdroid

  28. @Anstattradler @phpmacher
    Gut zu wissen: Diese Codes kann man bei vielen Apps auf per QR-Code "exportieren" und auf einem zweiten Gerät einscannen (Aegis und Google Authenticator können das z.B.)

    Es gibt für #Zweifaktorauthentifizierung auch Apps für "richtige" Computer, auf Linux verwende ich #OTPClient.
    Das Programm kann #Aegis-Dateien importieren und exportieren.
    Für Geeks gibt es neben der grafischen Oberfläche auch eine Kommandozeile. (github.com/paolostivanin/OTPCl).
    #2FA #OTP #QRCode #Linux #GUI #Gtk #cli