App Stores without Google & Apple
Illustration: Florian Biege
We all use passwords to protect our data, for example when using online banking or our email account. But passwords alone can be insecure: if others figure them out (for example, through carelessness, a data breach or a cyberattack), your data is at risk.
The second factor (known as ‘two-factor authentication’, or ‘2FA’ for short) then acts as an additional security barrier: an app generates a code (a six-digit number), without which access to your data is denied. A new numerical code is generated after around 30 seconds. Only the app on your device knows these constantly changing access keys. Wherever possible, you should therefore enable two-factor authentication (2FA), particularly for email accounts, online banking, your cloud storage, the Deutsche Bahn’s DB Navigator, or when using government services.
The Authenticator apps from Microsoft and Google also do this for you – though they store your codes in a locked cage in the cloud: you cannot export the access codes (with Google, it’s very difficult) and transfer them to another app. Microsoft and Google are therefore deliberately making it difficult for us to use other services. Furthermore, to the best of our knowledge, Google does not encrypt data when codes are transmitted.
However, you can liberate your personal services and accounts (your employer may require you to use a specific app). Take a little time to make this change, which is not as easy as it sounds.
Our digital switch recipes provide an easy, simple way to give Big Tech the push, but there are other options available. We have tried to make it easy by focusing on a single approach and a small number of options, but there are other alternatives that are just as good. After all, what we mean by ‘good’, ‘not so good’ and ‘bad’ is open to debate: DI.DAY is about easy ways to give Big Tech the push (without getting into purism or being preachy). Our decisions are based on advice from our advisory panel.
An overview of the alternatives is available on the next page:
with Android or iOS
for which you are using two-factor authentication
– Make sure you back it up before making the change!
for notes
makes the move easier
Warning: Switching from Microsoft or Google Authenticator to a big-tech-free alternative is a little more complicated than switching to other services. If you make a mistake during the switch, you could lose access to your accounts. So, before you start, you should back up the ‘recovery codes’ for all your services. They’ll be your lifeline if anything goes wrong.
Make a list of all the services for which you use two-factor authentication. These are likely to include email accounts, social media, bank accounts, cloud services or online shopping sites. For each service, make a note of the name, email address or username, and the recovery codes.
Go to every service where you use two-factor authentication and download or print out the recovery codes. You’ll need these codes if you lose access to a service whilst moving house. Keep them in a safe place – ideally printed out and stored in a safe – or digitally in a password manager that you can access even without two-factor authentication.
This step is necessary if your security codes are currently stored with Google. If you’re using the Microsoft Authenticator, continue with step 4.
The app will now generate a QR code on your screen. Take a screenshot of it. You can then scan this screenshot (which you may have printed out) using the QR code reader in the new app (step 6).
There are several good alternatives to Microsoft or Google Authenticator, particularly open-source programmes:
offers encrypted backups, biometric unlocking and the option to store backups in the cloud. The app is particularly user-friendly.
for iOS and Android: A simple but effective app developed by Red Hat. It supports TOTP.
for iOS, Android, Windows and Linux: offers end-to-end encryption, cross-platform synchronisation as well as import from Google and Microsoft Authenticator.
for Android, iOS, Windows, macOS, Linux: offers end-to-end encryption and synchronisation between devices (with a Proton account); can also be used without a Proton account. The generated codes can be exported.
for Android, iOS: also available as a browser extension.
is part of the Bitwarden password manager (see switch recipe), but can also be used as a stand-alone app at all times. It offers encrypted backups and synchronisation with the Bitwarden account.
The first time you launch the new app, you’ll set up encryption: choose a strong password (or use fingerprint biometrics for quick access). These codes are then stored in encrypted form on your smartphone – not in a third-party cloud.
From Google: Set up the new accesses by scanning the QR codes you saved in step 3. There have been reports that not all third-party Authenticator apps can read the codes generated by Google Authenticator. Then follow the same procedure as for Microsoft.
From Microsoft: Go through your list and set up your new logins. To do this, go to the relevant website, log in (still using the Microsoft or Google Authenticator) and set up a new 2FA access. You’ll usually find this option in the account or security settings.
Scan the QR code (or setup key) for each service, for example for your account on Bahn.de or the DB Navigator. Test the new 2FA immediately: enter the numeric code displayed on the website. You will only have activated the second factor once the service has confirmed it.
For Microsoft accounts:
If you want to be on the safe side with work-related two-factor authentication codes, you may want to keep the Microsoft Authenticator app.
To ensure your codes aren’t lost if you lose your smartphone or switch to a new one: Open the ‘Backups’ settings in the app and enable automatic backups. Choose a strong backup password – without this password, the file is worthless. We recommend also copying the backup file to a secure location: your own cloud storage (see our switch recipe Cloud Storage) or an external USB stick. You can later transfer everything to a new mobile in just a minute by importing this backup file with your security keys.
Once you #DIDit – share our post about the digital switch and inspire others to take control of their own digital lives!
Passkeys instead of codes: More and more services now support passkeys – the modern, phishing-proof successor to passwords plus 2FA. Where a service offers them, you can set them up as an additional security measure. What’s more, Aegis also shows how much time each code takes to generate.
App Stores without Google & Apple
Collaborating without Google & Co.
Photos without Google, Apple & Co.
Reading E-Books without Amazon
Video Streaming without YouTube, Prime & Netflix
Shopping without Amazon
Video calls without Zoom, Teams & Co.
Android phone without Google
Have a Hold on Your Passwords
Alternatives to ChatGPT & Co.
From Spotify to Fair Music Streaming
Set Your Calendars and Contacts Free
Independent Data Clouds
Nextcloud – Your Very Own Cloud
From Windows to Linux Mint
From Big Tech Maps to Open Street Map
Microsoft to LibreOffice & Co.
PayPal to Wero
Chrome to Firefox
Gmail to Independent Email
From Amazon to the Local Bookstore
From Google to Other Search Engines
WhatsApp to Signal
X to Mastodon