Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Show HN: Obsidian - OTP Authenticator (obsidianapp.io)
36 points by r4id4 on March 18, 2021 | hide | past | favorite | 41 comments


I got confused for a second. I thought they added OTP to the Markdown editor that I use[1]. I wonder if the name "Obsidian" is gaining more popularity because of the recent surge in Minecraft's player base.

[1] https://obsidian.md/


I actually released Obsidian 3-4 years ago :)


To be fair it makes a lot more sense to call an OTP authenticator, obisdian, than a Markdown editor.


Why's that?


Obsidian is supposed to be a super tough type of stone (in the Minecraft game, in reality it's like glass, it's brittle and shatters easily, but because of the game everybody thinks Obsidian is tough). OTP Authenticator implying that it's tough like obsidian makes more sense, than a Markdown Editor. Of course, this is my opinion and I don't know why either of them called their project Obsidian.


I can answer for the Obsidian Authenticator, I've always loved gems and minerals and I thought the name was cool! as simple as that :)


Cool name for sure, works for both I guess, both are tough and deep I guess.


Yep! There is enough space for multiple Obsidians :)


"Uses iCloud Keychain to communicate across devices. Your data are never transferred or stored in any external server."

That cannot be true.


Hi cassianleal, I'm the founder of Obsidian. The meaning of the statement is that users' data are not stored on some external database nor are transferred (even if temporarly) to any server.

Communication happens only between Obsidian (app) and the iCloud keychain.


I think it might clear things up if you said that the data is not stored on any Obsidian servers, because the data is stored on iCloud servers.


That's true, I'll update the copy to be more clear!

You are right.


I'd love an explanation of that statement: if it uses iCloud, your data are stored on Apple's servers. Your data may be encrypted, but they are definitely being transferred from/to your devices and iCloud, and being stored there.

I don't have a problem with this, I use iCloud for this purpose myself, but I do believe you are correct to call out this statement.


Hi Peter, I see your point. Yeah it's actually true what you say, I didn't consider it as a "server".

But you are right!

In the statement I was meaning any "Obsidian" or third-party server!

Sorry for the misunderstanding!


Hi r4id4,

Sorry I wrote in a bit of a rush and could have been more verbose. :)

Thanks for acknowledging the mistake, it's a much better response than denying or dismissing.

Just another small nitpick - iCloud's / Apple's servers are still a third-party servers since they are neither mine nor yours.

Your app looks pretty nice though, I wish you success with it!


You were right, there was nothing to deny ahah :) I've updated the copy and specified "apart from iCloud"


I'm curious why I'd use this over authy?


Authy requires a phone number, which you may or may not want to give out, but it also lets that phone number restore backups, so it’s vulnerable to SIM swaps.

Also it’s ugly and super high latency to navigate, but that’s just my opinion.


"but it also lets that phone number restore backups" - is this true? I use Authy and can use a phone number to connect a new device to my account, but to restore access to credentials on the new device I need to enter a passphrase. I don't think there's a way to restore credentials with just a phone number, but will need to check.

Edit: the following article appears to confirm my beliefs: https://support.authy.com/hc/en-us/articles/360036580453-Rec...

Without the backup password, you won't be able to restore a backup.


You can disable the multi-device capability of Authy to lock it to a specific set of devices e.g. primary and a backup burner if that's your thing.


Yep, I can add that backups in Obsidian are automatically managed and stored on the iCloud Keychain, hence accessible just by using the app on any device


Just yesterday I thought it’d be great if Authy used iCloud instead of their own backend for storage. Thank you for building this.

Can I import my OTPs from Authy?


I haven't been using Authy for years, last time I checked there was no easy way to export data from it (they want to keep you tieeeed!), but hopefully things have changed.

You would only need to edit/export the "secret" and copy/paste it to Obsidian, in case they allow it.


Anecdotal, but, Authy has been very buggy for me lately. Locking up (100% CPU) on my computer and sync across devices sometimes not working.

No specific reason to assume Obsidian is better, but, its annoying enough that it turned Authy from something that seamlessly "just works" into something which I feel like i'm fighting with.


For syncing across multiple devices and being potentially available on the web portal or from the browser extension check out Saas Pass if that’s what you might be interested in.

Disclaimer: worked on it


Agreed. It's been buggy enough that I've been looking for an alternative to migrate things to. Perhaps I'll try Obsidian!


Let me know if you need any help :)

In the app settings you can also find the email to contact me directly!

Cheers


I'm not saying Obsidian "just works", but it does ahah.

I'm kidding, anyway you can give it a try to see if it satisfies your needs


Obsidian works on top of iCloud Keychain, so your data are not stored in some external server (except iCloud) as Authy does.

The sync with iCloud works seamlessly and Obsidian features themes (also Dark) :)

You can give Obsidian a try if you feel like!


I'm curious about the "daily backups". Does this mean that if the data is deleted from the Apple Keychain the app has a local copy that can be reverted to?


Hi Kevin, every time you make a change (ie add a new token, delete a token, rename a token) a snapshot is made and saved under the current date. These snapshots are then stored always in the iCloud Keychian.

Anyway the Apple Keychain retain a local copy on the device, which means that even if in airplane mode Obsidian works by reading the local keychain.


Thanks for clarifying. It seems like this will prevent some issues such as deleting the wrong token howver storing all of your "backups" in the same place as your primary storage (iCloud) is not a good strategy. If anything wiped your keychain it would be propagated to all your devices (unless you leave some on airplane mode) and you are now locked out of your accounts.


Apple Keychain is key-value storage, Obsidian stores tokens and backups under different keys to be able to avoid erroneous overwrites or key corruption.

Obviously if the whole keychain gets corrupted/wiped then there is no way to recover, but I find it unlikely, or at least never heard about it.


There's a typo/misspelling on page: https://obsidianapp.io/

Search for Kychain.


Thanks jay! Will fix it!


I see there's an in-app purchase. Are any of the features limited by this? The site doesn't seem to mention it.


Hi endperform, here are the perks of Obsidian Fusion (the in app purchase). Everything else is available in the standard version!

- Daily Backups

- Unlimited tokens

- Clubhouse and Black themes

- New features that will be rolled out in the near future


So what’s the limit for the number of tokens and backup frequency without the subscription?

Sad to see this as a subscription, seems easy to justify paying $5 one time but not $12 every year.


Hi OkGoDoIt, free tier contains 5 tokens.

I'm sorry you feel this way. Subscription model is a way to continue funding the developments and maintenance of the app.

I've seen so many one-time payments app turn into subscriptions (e.g. 1Password etc) or be abandoned by the developers.

$12/year or $1/month seemed a reasonable price for the service offered and what will come next, but I understand your point of view.

I just want to keep the service level as high as possible.


What are the features on top of the in-app purchase?


Hi lourenci, here is what you can obtain with Obsidian Fusion:

- Daily Backups

- Unlimited tokens

- Clubhouse and Black themes

- New features that will be rolled out in the near future




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: