Hi, I have a semi-private Google account for Youtube (yes, I know you can’t really be private with Google, but I only use it in Safari with the private relay, and a separate phone number), and I’d like to enable 2FA on that account, I use Ente Auth on a device that doesn’t have any IP protection, does Ente Auth leak the IP to Google if I add it like this? or is it offline but with syncing only
Well, unless Ente Auth never ever connects to the Internet, you can’t be sure. For instance, Ente Auth uses “Sentry” for bug capture, which most definitely connects somewhere.
In theory, TOTPs are fully functional offline. In practice, TOTP apps need to sync time from trusted sources, which could be Google or Cloudflare, who run public “roughtime” instances (but in Ente Auth’s case, these instances aren’t used, for now; Ente Auth seems to have handrolled custom time sync implementation).