I ditched Google Authenticator for an open source alternative; I've never looked back

by · Android Police

I am obsessed with de-Googling my life as much as possible. I like to check out new privacy-focused browsers when I can, or use open source alternatives for other services.

My next target was something I don't use every day but still need from time to time.

Google Authenticator has been a reliable way to generate 2FA codes for my various logins, until I experienced a glitch recently.

That's when I decided to switch to an alternative that worked offline.

Google Authenticator failed me at the worst time possible

A glitch in the matrix

You can call me paranoid all you want, but I do not trust Google with my data, and I'm skeptical about its encryption implementation for Authenticator.

Like many of Google's services, Authenticator runs in the cloud and is tied to an account. Being tied to a closed cloud service isn't ideal.

But I still used the service because I'd had it set up for a long time and didn't want to switch to a different app, since I had the same concerns with other services.

I also considered switching to other services like Proton Authenticator, 2FAS, and Ente Auth, but I didn't follow through.

The main reason I decided to ditch Google Authenticator was an issue I ran into one night while I was planning to play games.

I turned on my Nintendo Switch after a few months, and the console asked me to sign in again. Since my Nintendo account's 2FA was linked to Google Authenticator, I didn't foresee any issues.

But when I tried to sign in, the Google Authenticator 2FA didn't work. After the code refreshed, the second attempt didn't work either.

After a few hours, I managed to sign in to my Nintendo account but missed a night of gaming. In my books, that was unacceptable.

I wasn't thrilled with the experience, especially since it had worked without issues before. After some thought, I realized that there may have been a glitch in the matrix in Google's cloud service.

Even if the issue was temporary, it was enough to push me to take the plunge. During some online research, I came across Aegis Authenticator in a subreddit that advises users on how to de-Google devices.

It's open source, free, and can generate codes completely offline. That was enough for me to switch because it aligned with my principles, and I just needed a good reason.

But after switching to Aegis Authenticator, I realized I didn't even miss a beat.

Everything Aegis Authenticator gets right and how it won me over

It didn't take me long to get convinced

Aegis Authenticator is everything I was looking for in a 2FA app that could replace Google's offering.

It's a GPL-3.0 open source app that requires no account, has no telemetry, and doesn't depend on the cloud to generate codes.

It's exactly the opposite of what Google Authenticator stands for, while offering the same service.

The app's core security is based on an AES-256-encrypted local vault, so it can work completely offline and doesn't need cloud access.

For added security, the app can be unlocked with a PIN, password, or biometrics, which I highly appreciate.

What's neat is that the 2FA-generated codes stay encrypted until you manually unlock them. With Google Authenticator and other apps, these codes show as soon as you open the app.

The switch was also stress-free, with excellent support for importing accounts and tokens from Google Authenticator and other apps.


You can transfer to Aegis Authenticator from another authenticator app using a QR code or a file, depending on the app you are switching from.


Backing up accounts on Aegis Authenticator is also straightforward. The app gives you full control, as you can export a file to a folder of your choice.

The backups are fully encrypted, which is reassuring in case I lose my device.

There is one problem, though. I am solely responsible for automatic backups, and since I don't want to share it with cloud services, I had to come up with a solution.

My solution was simple, since I set up Syncthing to back up data to my NAS (Network Attached Storage). I added the Aegis backup file to sync with my NAS, so I don't have to worry about losing access.

If you're thinking of switching, you can use the same method on your laptop or home computer and avoid sharing the file on cloud services.

Still, I wish Aegis Authenticator were available on iOS devices, as I use an iPad for work and media.

But what I love about Aegis is that it works completely offline. I no longer have to depend on a cloud service, as I did with Google.

It's the perfect alternative for people who want to de-Google their device and still use a service that is basically a necessity. You can use other services like Proton Authenticator or Ente, but for my use, Aegis was ideal.

I no longer trust cloud-based authenticators

After using Google Authenticator for years and exploring other services, I no longer prefer using cloud-based authenticators.

Something doesn't feel right about having personal data sit in the cloud, where it can be breached any day.

But with an open source alternative like Aegis Authenticator, I have full control of my data and can access 2FA codes without any interaction with the cloud.