0 vote
Just had a go with this on Android. My hope was to find something more flexible than Google Authenticator.
We use TOTP tokens which come with seeds (keys) in various formats. Having an Authenticator App to use the same code is essential for us.
For example, our current batch of tokens use 40-character hex keys, while Google Authenticator only recognises base32 characters.
While we can convert the hex to base32 it would be much easier to use the native hex keys.
As it stands, the Devolutions Authenticator has nothing to differentiate it from the Google offering.
Providing an option for hex input would, for us, be a major plus.
(I note there is a ‘cloud-sync’ option but I cannot find any Authenticator documentation to refer to).
Hi Les,
Currently the only accepted input is a base32 key and I understand that it can be annoying to convert from Hex to base32. As it's fairly easy to add such feature, we will add the possibility to enter a Hex key in the next release that's coming very soon.
Also, the cloud sync feature is a backup of all the entries in your list. For example, if the app is deleted from your phone and you reinstall it, all your entries will be recovered as before the app deletion.
Feel free to ask all your questions about the app.
Sébastien Aubin
Product manager - Password Management
Thank you.
I don't quite understand the cloud sync mechanism. I have not registered for any account on my phone with this app so how can I retrieve my saved details?
There may be some unique ID in the downloaded app but how would the recovery work if the app was uninstalled or installed on a new phone?
Hi,
There a unique ID generated for each device which mean that if you change your device, your entries will not be recovered on it. The mechanism is very simple and it's meant to recover your entries on the same device. On the other hand, a "full" cloud sync function will be available on the app in the next few weeks to overcome this problem (connected with your Devolutions account).
Sébastien Aubin
Product manager - Password Management
Having received such a quick and positive response, can I suggest some more?
There are some more parameters relating to TOTP tokens and it would be great if they could be incorporated, allowing universal use.
I think the actual programming changes required are quite simple.
To the best of our knowledge the available variations are:
Key format: Hex or Base32 (both in use)
Algorithm: SHA-1 or SHA-256 or SHA-512 (SHA-1 most common but the others will replace it)
Timestep: 30 or 60 seconds (both in use though 30 seconds the most common)
Digits: 6 or 8 (both in use with 6 the most common)
We actually currently use: Hex and Base32; SHA-1; 30 and 60 sec; 6 digits
Allowing both 30 and 60 seconds is trivial to code: It is a simple divisor. The SHA options will depend on whether the existing library you use includes them.
One more point - this time about the GUI.
Today's trend for minimalistic interfaces leaves us old fogies very confusing - especially as there is no defined standard for anything.
So your save icon in the top right hand corner (a very old floppy disk) does not really catch the eye. The google Authenticator has a simple save button that is nice as well as being clear and obvious (I think they switched from an icon)
As to the camera being opened automatically when a new entry is requested - this too is confusing. I understand the logic behind it (probably most additions are via a QR code) but I believe the simpler and more explicit approach of google Authenticator is better - it asks you to select which you want rather than jumping to conclusions.
The most flexible approach would be to allow the user to set his own preferences. You might even gain some insight into what users like by getting user feedback (with their permission of course).
Your RDM software has a trillion options so having some sensible options on the Authenticator should appeal :)
Hi,
Thank you for your feedback and your suggestions! Since we have our proper integration of the library, it would be fairly easy to add these variations. We will add the possibility to change the timestep to both 30 or 60 seconds and add the support for SHA-256 and SHA-512 in the next release that will already come with the Hex feature. I will also work on the UI to add some settings for it. Again, thanks for your feedback as it's very appreciated!
Sébastien Aubin
Product manager - Password Management
Not sure if the error I originally reported with the current app via a ticket was passed over when it was switched to here.
If an invalid code is entered, rather than detecting it and reporting it, the app crashes.
Select TOTP and enter the details. Try code: 861QAOLBLB6L6K04NO1DV1E7MKL92M3O
Tap the Save icon and the app just closes.
======================================================================
One other GUI point.
When adding an account, the screen defaults to 'Push Notification' rather than TOTP.
I believe that the majority of users want TOTP and if they do not notice the selection at the top, they will get confused and waste their time.
I think the option should be much more prominent (currently just looks like part of the furniture) and should default to TOTP, or neither. Other Authenticators only offer TOTP so probably it would be prudent to default to TOTP as many may not know which to select.
======================================================================
In 'Push Notification' mode, if I paste in any key (as I did by mistake) and tap save I get a pop-up which shows:
Error
Error in the process..
Close
The Close button does not in fact remove the message.
I have never set up a Push Notification account in this way so I suspect this facility has not been fully implemented.
Hi,
The fact that the app is crashing when you paste a bad code is a bug. It's on our list for the next release.
For the GUI, I understand your concern. The main reason we decided to develop Devolutions Authenticator was for our users to be able to authenticate with the push notification method. It was not the only reason but the main reason. With that being said, we understand that a lot of users use the push notification but also a lot don't. For the next release, we will take the time to refine the GUI and consider your concerns.
Finally, the Push notification mode will also be fixed in the next release.
Sébastien Aubin
Product manager - Password Management
Thank you for all your prompt, clear and helpful responses.
Hi, the new version of Authenticator is now available on the Google Play store. The iOS version should be available in the next few hours.
Sébastien Aubin
Product manager - Password Management
Thank you for the notification (though shouldn't the android apps update automatically?).
Great and quick work - all the things I suggested are there. Thank you.
Just a couple of points on the UI.
When creating a new entry there are input headings: Issuer and Account. In Edit mode these appear as: Name and Account.
I would think that the use of Name on both would be the most appropriate. 'Issuer' is too specific - it may not be meaningful in all circumstances.
Also, the order of the input fields is: Account then Issuer (Name) while on the edit screen and the Entries list it is reversed - which is the correct way for it to be.
One other small point. On a new entry, the placeholders appear in black font while I think convention seems to be to show that in grey - though I'm happy with the clarity of black.
The fact that the placeholder text does not disappear when clicking into it is very good.
Hi, we decided to make a few changes following your input. Again, thank you for that. We will deploy a new version of the app this morning (UTC-4) so it will be available for update this evening or tomorrow morning.
Sébastien Aubin
Product manager - Password Management
Looks good.
Checking through the Set a PIN screen.
===============================
Just trying to understand what the Sync button (cloud icon with down arrow) does - how Sync works overall.
An earlier post advised that the Sync function would do nothing on a replacement phone. It was only relevant to the current device. (There was mention of a later development)
So I assume it is a backup of my accounts on this phone.
a. If I add a new account, does it sync UP to the cloud automatically?
b. What does the cloud icon actually do:
i. I created a new account - Do I have to do anything to send it UP? I tapped it anyway.
ii. I deleted the account. I tap the cloud icon. Nothing changes - the deleted account does not come back.
Hi, yes there's a bug in the PIN option and I'm able to reproduce it.
For the cloud sync, if the option in the setting page is activated, you have nothing to do to sync the entries.
How it works:
When you create the first entry in the app, the app sync with the server and creates a row for your phone (unique) then upload your entry info. Afterwards, each entry created will be automatically synced with the server. If you delete the entry, it will delete it in the server too. It's not a BACKUP service but more a SYNC service. The goal is to prevent the loss of your entries if the APP is deleted by accident or it does not boot anymore due to a bug. With that in mind, in the near future we can add a feature to do a backup of your entries. I can see where it could be useful for some users. This feature would take a "snapshot" of your entry list and back it up on the server.
Sébastien Aubin
Product manager - Password Management
There are some more issues I have found.
I have several accounts that I created manually and they are fine.
I created an account for Namecheap scanning their QR image. I did it both on Devolutions Authenticator (DA) and Google Authenticator (GA).
There are two issues with DA:
The number is shown as 4/space/2 rather than 3/space/three as is normal. This only happens with this account. The manually created accounts are OK.
Like normal, the TOTP code has a 30 second timeslice - it changes every 30 seconds. GA shows it like that.
DA shows a code matching GA but the countdown starts at 60 (see 44 above) and the number does not change till the countdown reaches zero.
Meanwhile, after 30 seconds GA shows a new number - correctly - while SA continues to show what is now an invalid code.
The internal calculations must be correct (using a 30 second timeslice), as if it was indeed using a 60 second timeslice the codes it would generate would be different.
A sample of the text inside a Namecheap QR code:
otpauth://totp/username?secret=DZ6XGCSZGT62DB6xxxxFV4NI2SENVP4O&issuer=Namecheap
Entering the same code manually all works fine.
One other small point: GA and others have a time-sync utility. I personally do not thing that current phones have time issues but you may consider adding it for completeness.
Hi, we will check into that. Thank you
Sébastien Aubin
Product manager - Password Management
Hi, a new version of Devolutions Authenticator is now available.
Sébastien Aubin
Product manager - Password Management
Thank you. Working fine.