Google Authenticator 2FA

In Cloud mode, two-factor authentication protects the login to your account. Rempar uses the TOTP standard (RFC 6238), compatible with Google Authenticator, Microsoft Authenticator, Aegis, 1Password, and any six-digit code application.

Why, when the server sees nothing

Even without 2FA, an attacker who knows your e-mail address and your master password would already need both secrets to log in. 2FA adds a third factor: a physical device. It blocks the login of a new device, and therefore the download of your blobs, even if the password has leaked.

Enabling

  1. Settings, Account, Two-factor authentication, Enable.
  2. Open Google Authenticator, tap +, then Scan a QR code.
  3. Scan the QR code shown by Rempar. The entry appears under the name Rempar: your@email.
  4. Enter the six-digit code to confirm. 2FA is active.

If you cannot scan, enter the secret key shown below the QR code using the Enter a setup key option.

At login

After the e-mail address and the master password, Rempar asks for the current code. Codes change every 30 seconds; a tolerance of one period in each direction is accepted to absorb clock drift.

Losing your phone

  • From a device that is already logged in: Settings, Account, Two-factor authentication, Disable, then enable it again with the new phone.
  • With no logged-in device: write to support@rempar.org from the account's e-mail address. After identity verification, 2FA can be disabled by an administrator. Your blobs remain unreadable to us throughout the operation.

Remember to enable Google Authenticator backup or to export your accounts to the new phone before changing devices.

Disabling

Settings, Account, Two-factor authentication, Disable. The current code is required to confirm.


A question not answered here? support@rempar.org