Articles · Apps

Authenticator apps you can actually move to a new phone

A time-based code is generated from a shared secret and the clock. Nothing about it is tied to a device, which means any authenticator can generate the same codes given the same secrets. The difficulty is entirely in whether your current app will give those secrets back, and several historically would not.

Which apps let you leave

AppExportBackup
AegisEncrypted file you holdYes, to your own storage
Google AuthenticatorTransfer to another phone by QROptional account sync
Microsoft AuthenticatorCloud backup tied to an accountYes, account based
Duo MobileAccount-based restoreYes, for supported accounts
A password manager's built-in codesYes, with the vaultYes, and see the caveat below

Quảng cáo

The apps

1

Aegis Authenticator - 2FA App

Beem Development
4,7 500 N+ 7 MB

Open source, encrypted vault, exports to a file you control, imports from most other apps. The right default for anyone who wants to own their codes.

2

Google Authenticator

Google LLC
3,9 100 Tr+ 6 MB

Simple and universally supported. Phone-to-phone transfer by QR code works well now, which was the historical complaint.

3

Microsoft Authenticator

Microsoft Corporation
4,6 100 Tr+ 56 MB

Necessary if your workplace uses Microsoft accounts, and it handles standard codes alongside them.

4

Duo Mobile

Cisco Systems, Inc.
4,2 50 Tr+ 10 MB

Common in universities and larger companies. Restore depends on the organisation's configuration.

The part everyone skips

Every service that offers two-factor also offers backup codes, usually shown once during setup. Those codes are the way back in when the phone is gone, and almost nobody saves them.

  1. Save the backup codes at setup Every time. A printed copy in a drawer beats a file on the phone holding the authenticator.
  2. Register a second factor where possible A second phone, a hardware key, or a second authenticator with the same secrets.
  3. Keep the recovery material away from the phone If both live on the same device, one loss takes everything.
  4. Test recovery on one account Once, deliberately, while nothing is wrong.

Should the password manager hold the codes?

Convenient
  • One app, autofilled together
  • Backed up with the vault
  • Much better than not using two-factor at all
Weaker
  • Both factors behind one master password
  • One compromise takes both
  • Defeats the purpose for high-value accounts

The reasonable middle is to split by value. Codes for forums and shopping sites in the password manager is fine. Codes for email, banking and the password manager's own account belong in a separate app, because email is the reset path for everything else.

Use Aegis if you want to own the file, save every service's backup codes today, and keep email and banking codes out of your password manager.

Frequently asked questions

Can I use the same codes on two phones?

Yes. The secret is what matters, so importing it into a second app on a second device gives identical codes. That is a legitimate backup strategy.

What happens if I lose the phone with no backup?

You use the backup codes. Without those, recovery depends entirely on each service's support process, and some have none.

Is SMS two-factor good enough?

Better than nothing, and the weakest option, because a number can be taken over. Move to an app wherever the service allows it.

Read next

APK download against the Play Store

This is not a rivalry. Each does something the other cannot.

Paying for a VPN: what changes

You are not buying encryption. You are buying an operator whose income does not depend on you.

Archive tools on Android compared

For a plain ZIP either works. For a split, password-protected archive, only one does.