Best way to secure authenticator app itself?

I use Aegis, and when I’m setting new 2FA credential, I add secret to KeePassXC database (separate from one I use for passwords), so I have it at 2 places (actually on each device I use), plus backup.
It means you have to keep and maintain 2 databases, but quantity is quite small for me (20-25 services), and it’s not I’m changing it often (most likely never)

1 Like