Is there an iOS authenticator app which doesn't phone home?

After Raivo is hard to trust an Authenticator App in iOS for me at the moment.
Tried both 2FAS and Ente, and both phone home when the app start.
Don’t like that for a security app.

Also don’t like when a privacy-security app has anything rather “Data Not Collected” as an App Privacy label in App store.
Really surprised that people here are starting to recommend ente Authenticator.

At the moment i am back to Tofu with the bare minimum entries that i use everyday and luckily i have an android device with Aegis to do the heavy lifting.

Data not collected just simply would not be true if the app will sync.
If you use the app in offline mode, it will not collect data. You should look at the facts, not at those arbitrary labels. These labels are a nice transparency thing but tell nothing more than what the developer will inform you about, nobody checks if what the devs write there is legit. Ente actually is super clear about what they do and do not collect and in which situations.

Using TOFU is IMHO not a recommendable thing, the app has not been updated in a while and the issues have piled up, it looks abandoned and unmaintained. If you use Ente without account, there would not be any difference in data collection. So this is quite ridiculous paranoia.

Raivo did not collect fewer data than Ente does, it just doesn’t make sense. You pick, either offline or with sync, both can be done in the same app. I really do not understand your concerns.

4 Likes

Well it is just me.

I just feel uncomfortable to use an authenticator app with sync.
Raivo has sync but it never phoned home and you could tell from your network logs that it is really in offline mode if you choose that.

Ente and 2FAS phone home from the moment you open the app. Sync or not sync enabled.
I personally wouldn’t use them, maybe people wouldn’t mind them, that like to have encrypted sync, but recommending them when every-time i open the app i ping their server? Weird (for an app of this purpose).

Maybe the app store labels don’t mean anything. But it is easier for an app to become sketchy when it has sketchy labels already, than an app with “Data Not Collected”. Because Apple is strict on the app store publications, and the Data Not Collected wouldn’t suffice when you decide to go sketchy.

I know the issues with TOFU, recommended? Definitely not. More comfortable to use at the moment? Yes

I ll just wait for a true offline or offline mode authenticator app to appear in iOS.
Now it would be a good time for Aegis to port in iOS for example.

Hey, one of the folks working on Ente here.

every-time i open the app i ping their server?

Only if you have installed the app from our Github releases do we make an anonymous network call. This is to notify you of critical app updates.

Zero network calls are made if you have installed the app from AppStore, FDroid or PlayStore, since these platforms provide their own update mechanisms.

If you notice anything amiss, do let us know, would be happy to fix it!

p.s. This is not an attempt to sell Auth, please use apps you are comfortable with.

3 Likes

Can you share what you’re seeing with ente Auth? I’m not seeing it make any network connections on iOS.

Doesn’t appear to make any connections now when you start the app and Crash & error reporting is disabled.

Last week i checked though i am sure i was seeing 2 or 3 plain dns requests to ente.io at the startup. Not the case anymore.

App was installed from the apple store.

I ll give the app a real try now and report back if i see something. But things seem good now.

1 Like

I think it is the exact same behavior with 2FAS. It makes a connection to googlecrash reporting or something similar if you have it enabled, else, nothing.

No, 2FAS is making an API connection to

api2.2fas.com

followed with an amazon web service connection every-time you start the app, no matter the settings applied.

2 Likes

Many Thanks! I will for sure check what this is doing.

Alright, based on a quick search and test, although it will always do that connection, it is only used for the browser extension feature. I have it blocked in my DNS and app still works just fine. Based on their github, it’s for browser extension and notification (for said extension) Could be nice to be an opt-in rather than by default.

1 Like

Hi, thanks for sharing that. How are you tracking that? Is it through the router?

hey,

you need some kind of realtime dns query logger like the ones in pi-hole or nextdns but you can watch it also within the build in App Privacy Report in Apple’s privacy settings.

I personally use Charles proxy, though they are also many more advance tools too, like Burp Suite & mitmproxy.

1 Like

I have an Asus router. I have to check if there is anything in it to analyse the traffic.

I like FreeOTP, but couldn’t speak to it’s privacy and security. I like it’s simplicity.

https://freeotp.github.io/

apple should really add built in a way to turn off network access to an app in ios like graphene has. if they did, it would encourage google to add the same to stock android, not to mention heavily increasing privacy when using some apps

3 Likes