this post was submitted on 13 Oct 2025
102 points (96.4% liked)

Selfhosted

52232 readers
736 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

One more step to unhitching from Google...

Right now the only option I see in F-Droid is Aegis.

I'm not sure what to actually look for side from checking for unexpected permissions and reasonably frequent updates.

Hopefully something I can sync with a GNOME app...

top 50 comments
sorted by: hot top controversial new old
[–] Unlearned9545@lemmy.world 8 points 11 hours ago (2 children)
[–] Landless2029@lemmy.world 3 points 6 hours ago

I'm a little concerned about having OTP and passwords together in one system.

[–] ikidd@lemmy.world 1 points 9 hours ago (1 children)

Yah, I can't see a point to have another app/extension when Bitwarden has it built in, and it's a great password manager.

[–] ripcord@lemmy.world 1 points 9 hours ago (1 children)

Wait, it does? Including in the mobile app? I don't see it.

[–] ikidd@lemmy.world 1 points 8 hours ago (1 children)

Right under Password in the edit screen of an item: Authenticator Key. You put in the auth key the target site provides you when you enable TOTP and it will start generating timed tokens. Usually you'll also get a one-time pad of backup keys, I usually toss those in the Notes of the edit screen there as well in case something goes wrong.

[–] SteveTech@aussie.zone 2 points 8 hours ago

The browser extension also lets you scan the page for QR codes for the TOTP key.

[–] zingo@sh.itjust.works 11 points 12 hours ago

Aegis.

I like the auto backup feature (encrypted) . Then the backup is synced to computer via Syncthing.

Set and forget setup.

[–] W4nd3r3r@lemmy.ml 2 points 8 hours ago
[–] Curious_Canid@lemmy.ca 16 points 15 hours ago

I've been using Aegis for several years now without any problems. It replaced the Google Authenticator seamlessly.

[–] Jayjader@jlai.lu 2 points 10 hours ago

I use pass for my passwords, and it has an otp extension that I've been using more and more. I used to use aegis but I have needed to switch phones one too many times without having access to the previous phone to be comfortable with phones for 2fa.

Of course, this isn't as secure as a truly separate OTP solution, but it's still better than no OTP/2FA. And I can easily enough back up and restore my 2fa access over the internet, even on a new computer (albeit I need to also backup a PGP key that can decrypt the password store to truly be portable).

[–] julianwgs@discuss.tchncs.de 1 points 9 hours ago

I use Proton Authenticator on an iPhone without an account and I am satisfied

[–] jcolag@lemmy.sdf.org 1 points 9 hours ago

I primarily use GNOME Authenticator, but after an inopportune crash, I now also run 2FAuth on my home server as a backup, and now just hope that I remember to do the export/import dance going forward.

[–] pjusk@lemmy.dbzer0.com 1 points 9 hours ago

Woahhh defo not enough love for Ente Auth in tgese comments. Highly recommend! Its got a beautiful and intuitive UI, completely open-source and is back by super active devs and community 💚

[–] asudox@lemmy.asudox.dev 23 points 20 hours ago

I use Aegis on my phone.

[–] suicidaleggroll@lemmy.world 4 points 14 hours ago

I used to use 2FAS, but recently switched to a self-hosted instance of Ente

[–] vrighter@discuss.tchncs.de 7 points 16 hours ago

keepassxc and a yubikey. And syncthing to keep all devices in sync

[–] blackbarn@lemmy.zip 8 points 17 hours ago

Vaultwardwn/bitwarden + a yubikey for bitwarden itself and a few others

[–] deathbird@mander.xyz 54 points 1 day ago

I like Aegis.

[–] spacelord@sh.itjust.works 19 points 1 day ago

Aegis ♥️

[–] Appoxo@lemmy.dbzer0.com 19 points 1 day ago
[–] pipe01@programming.dev 66 points 1 day ago

I use Aegis, it works well

[–] salacious_coaster@infosec.pub 45 points 1 day ago (4 children)

Bitwarden. I don't self host it, though. $10 a year for password management and 2FA is fine by me.

[–] warmaster@lemmy.world 1 points 8 hours ago

I'm on the same plan, I do plan to self host it though as a backup only.

[–] TedZanzibar@feddit.uk 5 points 16 hours ago

It's niche but I like to point it out whenever I get the opportunity: if your workplace uses Bitwarden Enterprise, every licensed user gets a free family plan that can be linked to any account. I haven't personally paid for BW for years.

[–] HereIAm@lemmy.world 7 points 22 hours ago (1 children)

Same. Self hosting it sounds nice, and I self host a handful of services, but I don't want to be stuck without passwords in another country with a dead server at home because a power cut happened at some point.

[–] gaylord_fartmaster@lemmy.world 19 points 20 hours ago (2 children)

Bitwarden caches your vault to your device, so you don't actually need a live connection to the server.

[–] az04@lemmy.world 5 points 17 hours ago

I had fault in my server this summer and my local bitwarden app wouldn't work without the connection. Same in my laptop, if the connection is blocked by the firewall it doesn't let me load the vault at all.

[–] HereIAm@lemmy.world 4 points 20 hours ago* (last edited 20 hours ago)

Oh, that's actually good to know. I guess it makes sense for when you don't have a good connection as well.

load more comments (1 replies)
[–] sbeak@sopuli.xyz 9 points 22 hours ago

Aegis seems like a pretty good 2FA app on Android from what I’ve heard. Personally, I use Ente Auth as sync is very helpful when I don’t have my phone nearby (you can either use the desktop app or use your browser, both work). Don’t think you can self-host sync, though I might be wrong. Ente Auth also works without sync, so there’s that.

I would not suggest using a password manager’s 2FA integration (e.g. Bitwarden, I think Proton Pass has one if you use that?) as it kind of defeats the point of 2FA, since if someone got access to your password manager, they would also get the 2FA codes.

[–] cmnybo@discuss.tchncs.de 38 points 1 day ago (5 children)

I've been using KeePassXC. I use Syncthing to keep the database synchronized between computers.

load more comments (5 replies)
[–] Redex68@lemmy.world 3 points 18 hours ago* (last edited 18 hours ago)

I personally use Ente Auth and quite like it, don't use syncing and save an encrypted copy to my PC. I really like that you can see what the next code will be.

[–] BruisedMoose@piefed.social 3 points 19 hours ago

Adding to the Aegis chorus.

I also use Proton Pass for some sites that aren't as critical for me / don't have a bunch of PII. It's easy.

[–] fubarx@lemmy.world 17 points 1 day ago (1 children)
load more comments (1 replies)
[–] slazer2au@lemmy.world 6 points 23 hours ago

Authenticator and Authenticator.

Damn thoe innovative tech companies, what will they think of next.

[–] retro@infosec.pub 7 points 1 day ago (3 children)

Proton Authenticator. Has both Desktop and Mobile apps. Free. Don't have to sync to Proton.

load more comments (3 replies)
[–] jbk@discuss.tchncs.de 1 points 16 hours ago (1 children)

since no one mentioned andotp i might have to move away from it…

[–] sfjvvssss@lemmy.world 2 points 10 hours ago (1 children)
[–] jbk@discuss.tchncs.de 1 points 10 hours ago
[–] gagootron@feddit.org 8 points 1 day ago

Yubikey. I dont want to trust my phone, so I use some separate hardware instead

load more comments
view more: next ›