Aegis vault backup
What they're not telling you: The 2FA Encryption Flaw Nobody's Fixing: How a Reddit Question Exposes Government's Password Management Blind Spot Millions of Americans are storing government-issued credentials and financial authentication codes in apps with encryption architecture that federal cybersecurity agencies have never publicly audited or vetted. The question posed on r/privacy last week is deceptively simple: If you encrypt a backup of your two-factor authentication vault with a password, then change that password, can someone still crack the old backup? The answer—yes, under certain conditions—reveals a gaping hole in how cybersecurity advice flows from federal agencies to the public they're supposed to protect.
What the Documents Show
Aegis Authenticator, the open-source app in question, uses encryption that ties backup access to the password at the time of backup creation. Change your password afterward, and older backups remain accessible to anyone with the original password and the technical knowledge to exploit them. This is not a secret. The Aegis developer community documented this behavior in their GitHub repository. But the National Institute of Standards and Technology (NIST), which since 2002 has published federal guidelines on digital authentication and cryptographic standards, has never issued specific public guidance on backup-encryption migration for consumer authenticator apps.
Follow the Money
The Cybersecurity and Infrastructure Security Agency (CISA), established in 2018 as the lead federal agency for civilian cybersecurity coordination, similarly offers no publicly available audit trail of recommendations to app developers on this precise vulnerability class. What makes this negligent is scale. According to the Pew Research Center, roughly 52 percent of American adults use two-factor authentication on at least one account. Many use Aegis or similar open-source alternatives because government agencies—primarily NIST and CISA—have consistently recommended moving away from SMS-based authentication due to SIM-swapping vulnerabilities. They pushed users toward authenticator apps. But they never mandated or publicly verified that these apps implement secure backup-rotation protocols.
What Else We Know
No formal NIST Special Publication. No CISA alert bulletin. No advisory from the Office of Management and Budget (OMB), which coordinates federal IT policy under the White House. When Reddit users asked whether their backups remain encrypted after password changes, the thread accumulated dozens of responses—most from security engineers and privacy advocates—confirming yes, old backups can be exploited. One commenter noted that users should manually delete old backups and re-encrypt new ones, assuming they remember to do so. That's not a technical safeguard.
Primary Sources
- Source: r/privacy
- Category: Government Secrets
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.