this post was submitted on 29 Sep 2025
457 points (99.6% liked)

Android

31993 readers
181 users here now

DROID DOES

Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


We are Android girls*,

In our Lemmy.world.

The back is plastic,

It's fantastic.

*Well, not just girls: people of all gender identities are welcomed here.


Our Partner Communities:

!android@lemmy.ml


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] hessenjunge@discuss.tchncs.de 3 points 1 day ago (1 children)

Well, they have a kind of 2FA since at least 30 years, long before rolling tokens were all over the place. Their latest implementations are as simple to use as Steam 2FA. If a bank isn’t able to implement a proper 2FA login there’s a ton of other security issues to worry about. Lastly, I think by using their own implementation/app they prevent their customers from using compromised apps.

[–] pinball_wizard@lemmy.zip 1 points 18 hours ago* (last edited 18 hours ago) (1 children)

If a bank isn’t able to implement a proper 2FA login there’s a ton of other security issues to worry about.

Exactly. Any organization whose MFA doesn't work on Aegis, I take action to protect myself from their incompetence.

Lastly, I think by using their own implementation/app they prevent their customers from using compromised apps.

I'm sure they claim that. But I still recognize it as simple incompetence. They aren't able or willing to hire someone with the Cybersecurity expertise to implement a relatively simple open specification.

Y'all are welcome to risk your money there. It's probably insured anyway, right?

For me, that's too much risk. Even if insurance makes me whole, getting robbed is a huge pain.

[–] hessenjunge@discuss.tchncs.de 1 points 16 hours ago* (last edited 16 hours ago)

Exactly. Any organization whose MFA doesn’t work on Aegis, I take action to protect myself from their incompetence.

That'll surely end their business. /s

I’m sure they claim that. But I still recognize it as simple incompetence. They aren’t able or willing to hire someone with the Cybersecurity expertise to implement a relatively simple open specification.

Just out of curiosity: What percentage of the population is capable of running Graphene/Aegis? What percentage, regardless of capability, is willing to do so?

Creators of popular OSS regularly warn about downloading their stuff elsewhere or pay for it. How do you think that would apply to any 2FA application?

Now think of how stupid the average person is, and realize half of them are stupider than that. (love some George Carlin). Given that even (very) stupid people have and need bank accounts: How would you implement an authentication that can't easily be compromised to ripp off stupid people?*

* Let's just assume that you, the lead developer, are not at all "incompetent", quite the opposite. Also take into consideration that you need to keep cost down (hint: That means you want no one to call support because of 3rd party applications!).