I don't really mind using shit software on work devices. Yes it's slow and inefficient, I spent half an hour today on Windows doing what would be a very short command on Linux. Fuck it, get paid the same. I just use Linux at home in my own time.
I'll point out better software exists. If I don't get support in changing it or allowed to change it, fuck it. It's on them at that point.
The main problem as I see it is if I have to download authenticator onto my personal device because something has happened to my work device. That's the only way I could see this being a problem since I use Graphene OS on my personal phone. Even then I would probably just use the authenticator on my work computer rather than going to that trouble.
Only if the company supports OTP methods for Entra login (logging in to M365 account).
But I'd say most don't anymore, as there has been a push towards Microsoft Authenticators push-method for a while (where the website/app shows a number and you have to type it in to the authenticator), as it is a slightly safer method than OTP, and can be used passwordless.
It also made people ready for passkeys, as the authenticator supports easy activation off passkey on accounts that are saved with push-method (you pretty much just click a button in the app), and authenticator is easy to set up on the admin side if you require device bound and attestation for passkey.
It depends…. Your company IT department can choose what types of 2FA are available to use and Microsoft Authenticator is separate from OTP and other methods, and it is possible to restrict them.
That’s also yet another reason why I force the issue of a company phone as part of my equipment to do my job.
Work isn't an excuse unless your work is trying to cut corners by having you use your personal phone instead of providing a work one. In which case they deserve to be taught this lesson for being cheap as fuck.
Your IT should be issuing you a phone handled by MDM, which should be locked down and not allow you to use a rooted or jailbroken device anyway.
Nope, the Microsoft authenticator is slightly different, and other authenticators won't work. I just went through this with my IT dep. Microsoft authenticator will sometimes pop the numbers up on the computer and make you enter it in the app, not the other way around.
Some organizations require authenticator; they don't just use it for MFA codes, it's goes deeper than that.
Also, most large enterprise fall for the stupid Microsoft trap. They buy enterpise licensing in bulk (E3, E5, whatever) and bosses who have no brains will say "well, let's use more microsoft products since they're 'free'". The trap is that, yes, your enterprise license agreement includes entitlements to a lot of their stuff, but they nickle and dime you on stupid shit like the storage so you can keep the logging and telemetry data you typically need for security, troubleshooting and some audit requirements.
I can't imagine ever using any of their shit beyond Office products. Their security software is crap compared to most offerings, they still seem to think that networks are bad so we should do as little as possible about them. Azure is just a completely uncontrollable money drain (by design) that is damn near impossible to secure properly once you give developers enough access to actually do their jobs.
I've been working in security for a long time now and they continue to be such a fucking liability and drain on money at every turn. If I ran the zoo, I would switch the entire enteprise to Linux and find just about any other collaboration suite to use.
Fuck Excel and fuck you if all you do with it is make lists. Fuck powerpoint and fuck every boss who is too dumb to read and only can accept information when it is spoon fed to them in a deck. Word is OK, but nobody reads anymore so what's the point?
I had to use it for my work. They required MS authenticator. I think it's bullshit and tried to export my 2fa to bitwarden. I couldn't. And to add another 2fa .method I need to call support so I gave it up
They don't let you use https://mysignins.microsoft.com/ to replace/add MFA methods? That site was very useful at my last employer, as I was switching phones often.
Probably. I suppose that I was lucky that I could manage these things myself. As we had only one local IT FTE, and I wouldn't have known who to contact beyond that single resource. And might have hated life if I had needed someone else to manage this for me.
I had a yubikey as my hardware authentication, then a coworkers email got hacked so IT moved us all to Microsoft authenticator, so now I have a less secure login method LOL
Yup, I use Aegis, and found a strange little trick with Bitwarden Authenticator where I can import them into the main app (the Vaultwarden server). I know keeping all my power in one place defeats the purpose of 2FA but you know, I trust Vaultwarden, and myself to keep it secure, implicitly.
This change is really more about enterprise use cases. If you take DLP seriously you need to make sure the integrity of the controls on work provided devices are intact. Authenticator isn't managed by intune since users could use it for many things.
Nothing stops someone taking a photo of another screen. It's not a panacea. It's just one more hurdle.
I can guarantee this will be a hilarious shitstorm of false positives wasting IT departments' time, because their detection of it is massively flawed.
At least once a month my - completely stock, and un-rooted - phone tells me I can't use Outlook/Teams because of root. Every time, a reboot is required to resolve this. One one occasion, TWO reboots.
Ignoring whatever reason Microsoft think they're blocking this for, it's going to regularly block regular users, who are not going to stand for it.
Ths is gonna cause some fun at work. I know our IT team would not be on top of this until one day a portion of employees can't SSO in. Then mayhem will ensue by heels being dug on both sides.
Your company should be issuing devices if employees need to use apps like that. IT issued equipment shouldn't be jailbroken or rooted, it should be managed via MDM.
Otherwise they deserve it for trying to cut corners by having employees use personal devices. If they're doing that, they're almost certainly not paying for the work use of those devices either.
Yes, I'm aware, but if both your passkey and your OTA codes are on the same device, it's not really two-factor authentication anymore, is it?
Your passwords sit in your password manager, the Yubikey is your 2FA.
Depending on the service you’re using they may allow you to use WebAuthn to authenticate your account passwordless so all you would need is your Email/Username + Authentication device, however not all services support this.
Yeah that's my choice too bc it offers access from my desktop browser too, not just the mobile app. Tying accounts to a single device makes me uncomfortable.
I don't use my account for email anymore or use Windows very often but I just changed the two factor authenticator to Aegis. They make the text to use an alternative authenticator app tiny blue hyperlink text but you can do it confirmed.
I wont use my personal phone for anything work related except authentication. Since it sits in its own little jail, it's fine.
I work all over the world and remote in. I have no other work related devices or equipment.
I look at it as a key card from the old days when I had to go into a building. I think that is a pretty trivial use case and doesn't need them to provide a phone, and in fact I absolutely would not want a device owned by anyone else that I carried around. That is FAR worse.
That said, this change sucks as I will now need to get around this bullshit.
Does it just use the Play Integrety API, or does it use some kind of other attestation check?
The need for full root privilege has fallen by the wayside assuming you can trust the OS running on the device. I dont hate this change if I can run a custom ROM that will report that the user does not have root privilege and that the OS has not been modified since boot.
Everyone that cares about security or privacy is working on custom android ROMs since there is no actual benefit to Apple hardware or software at this point in history. Plus you save money buying a Pixel device.
Google is doing their best to strangle those too, by only releasing their source code when a new major Android release comes out. Custom ROM developers then have to rebase and integrate several months of commits all at once, with nowhere near enough time or resources to actually vet more than a tiny fraction of the changes.
Not everyone. Depending where you live there's no devices available that are compatible with secure custom ROMs (you might be able to deGoogle, but that's different from being secure).
Your security doesn't just depend on what flavour of AOSP you decide to use. I'm assuming you're referring to GrapheneOS, which is only compatible with Pixel devices. Your threat model is also highly relevant. Depending on who you are and what you do, you can be secure on say LineageOS, which will run on a large variety of devices.
yep. it's sort of dead right now but not completely. in fact, a new bootrom exploit for Xs/11 era devices got released recently, and 11 is still getting supported on latest iOS 27.
89 Comments
Wizard_Pope@lemmy.world · 77 pts · 52d
Why would you use microsoft Authenticator anyway? There are other options
skooma_king@piefed.social · 68 pts · 52d
Work
Korhaka@sopuli.xyz · 15 pts · 52d
I don't really mind using shit software on work devices. Yes it's slow and inefficient, I spent half an hour today on Windows doing what would be a very short command on Linux. Fuck it, get paid the same. I just use Linux at home in my own time.
I'll point out better software exists. If I don't get support in changing it or allowed to change it, fuck it. It's on them at that point.
Wizard_Pope@lemmy.world · 3 pts · 52d
You can use other authenticators. I use ente auth for my microsoft account
atrielienz@lemmy.world · 17 pts · 52d
I can't. The authenticator for my job was set up on my work device by my IT department.
OwOarchist@pawb.social · 3 pts · 52d
If your work requires you to have a Microsoft Authenticator-compatible device, they should provide you with one.
atrielienz@lemmy.world · 9 pts · 51d
Arcka@midwest.social · 6 pts · 51d
Which would never be rooted or jailbroken in the first place so why even bring it up in this this context?
whatyousaidontwitter@sh.itjust.works · 2 pts · 51d
Wizard_Pope@lemmy.world · 2 pts · 52d
Sucks to have that. Have you tried asking IT if you could use a different one?
atrielienz@lemmy.world · 3 pts · 51d
The main problem as I see it is if I have to download authenticator onto my personal device because something has happened to my work device. That's the only way I could see this being a problem since I use Graphene OS on my personal phone. Even then I would probably just use the authenticator on my work computer rather than going to that trouble.
mereo@piefed.ca · 4 pts · 51d
That sucks. I refused so they gave me a Yubikey instead.
atrielienz@lemmy.world · 2 pts · 51d
I have a yubikey (two actually, one from a previous employer). New company won't actually let me use it.
skooma_king@piefed.social · 6 pts · 52d
Depends on how your M365 tenant is configured. Both conditional access policies and authentication strengths can enforce the requirement
tostiman@sh.itjust.works · 4 pts · 51d
My work MS account requires MS authenticator specifically, can't use another 2fa app
fatalicus@lemmy.world · 2 pts · 51d
Only if the company supports OTP methods for Entra login (logging in to M365 account).
But I'd say most don't anymore, as there has been a push towards Microsoft Authenticators push-method for a while (where the website/app shows a number and you have to type it in to the authenticator), as it is a slightly safer method than OTP, and can be used passwordless.
It also made people ready for passkeys, as the authenticator supports easy activation off passkey on accounts that are saved with push-method (you pretty much just click a button in the app), and authenticator is easy to set up on the admin side if you require device bound and attestation for passkey.
artyom@piefed.social · -2 pts · 52d
You don't need it for work. You can use any authenticator.
ramble81@lemmy.zip · 36 pts · 52d
It depends…. Your company IT department can choose what types of 2FA are available to use and Microsoft Authenticator is separate from OTP and other methods, and it is possible to restrict them.
That’s also yet another reason why I force the issue of a company phone as part of my equipment to do my job.
baines@lemmy.cafe · 10 pts · 52d
my company IT can provide a phone
no work software is ever touching a personal phone
and work phones get shut off at closing
halcyoncmdr@piefed.social · 4 pts · 51d
Work isn't an excuse unless your work is trying to cut corners by having you use your personal phone instead of providing a work one. In which case they deserve to be taught this lesson for being cheap as fuck.
Your IT should be issuing you a phone handled by MDM, which should be locked down and not allow you to use a rooted or jailbroken device anyway.
swicano@programming.dev · 13 pts · 52d
Nope, the Microsoft authenticator is slightly different, and other authenticators won't work. I just went through this with my IT dep. Microsoft authenticator will sometimes pop the numbers up on the computer and make you enter it in the app, not the other way around.
scytale@piefed.zip · 5 pts · 51d
IIRC if you use M365 (i.e. Outlook), you can only use their authenticator app for MFA. Happy to be corrected though.
Vittelius@feddit.org · 3 pts · 51d
M365 can be used with other 2fa apps. But organisations can force the use of Microsoft Authenticator
EnsignWashout@startrek.website · 1 pts · 51d
Aegis works fine, as long as your organization allows standards compliant authenticators.
timewarp@lemmy.world · -3 pts · 52d
Then stop working for retards who support Nazis
fyzzlefry@retrolemmy.com · 5 pts · 51d
I like the energy. But you took that from a 4 to a 10 fast.
blargh513@sh.itjust.works · 15 pts · 51d
Some organizations require authenticator; they don't just use it for MFA codes, it's goes deeper than that.
Also, most large enterprise fall for the stupid Microsoft trap. They buy enterpise licensing in bulk (E3, E5, whatever) and bosses who have no brains will say "well, let's use more microsoft products since they're 'free'". The trap is that, yes, your enterprise license agreement includes entitlements to a lot of their stuff, but they nickle and dime you on stupid shit like the storage so you can keep the logging and telemetry data you typically need for security, troubleshooting and some audit requirements.
I can't imagine ever using any of their shit beyond Office products. Their security software is crap compared to most offerings, they still seem to think that networks are bad so we should do as little as possible about them. Azure is just a completely uncontrollable money drain (by design) that is damn near impossible to secure properly once you give developers enough access to actually do their jobs.
I've been working in security for a long time now and they continue to be such a fucking liability and drain on money at every turn. If I ran the zoo, I would switch the entire enteprise to Linux and find just about any other collaboration suite to use.
Fuck Excel and fuck you if all you do with it is make lists. Fuck powerpoint and fuck every boss who is too dumb to read and only can accept information when it is spoon fed to them in a deck. Word is OK, but nobody reads anymore so what's the point?
ThunderLegend@sh.itjust.works · 6 pts · 51d
I had to use it for my work. They required MS authenticator. I think it's bullshit and tried to export my 2fa to bitwarden. I couldn't. And to add another 2fa .method I need to call support so I gave it up
kazerniel@lemmy.world · 2 pts · 51d
79WistfulVista@lemmy.zip · 2 pts · 51d
They don't let you use https://mysignins.microsoft.com/ to replace/add MFA methods? That site was very useful at my last employer, as I was switching phones often.
baatliwala@lemmy.world · 2 pts · 51d
Guessing IT can mandate which MFA options are available for users to choose
79WistfulVista@lemmy.world · 2 pts · 51d
Probably. I suppose that I was lucky that I could manage these things myself. As we had only one local IT FTE, and I wouldn't have known who to contact beyond that single resource. And might have hated life if I had needed someone else to manage this for me.
BCsven@lemmy.ca · 5 pts · 51d
I had a yubikey as my hardware authentication, then a coworkers email got hacked so IT moved us all to Microsoft authenticator, so now I have a less secure login method LOL
richardwallass@sh.itjust.works · 4 pts · 51d
When you are using your phone for your work you don't really have the choice.
Wizard_Pope@lemmy.world · 5 pts · 51d
If it's work provided sure. But if its your own device then fuck them, not installing that shit on my own device. Provide one for me
eleitl@lemmy.zip · 2 pts · 50d
It's not my phone, then. I don't use my private devices for work.
richardwallass@sh.itjust.works · 1 pts · 48d
BYOD they said
eleitl@lemmy.zip · 1 pts · 48d
It never pays working for people who are cheap.
lyralycan@sh.itjust.works · 3 pts · 52d
Yup, I use Aegis, and found a strange little trick with Bitwarden Authenticator where I can import them into the main app (the Vaultwarden server). I know keeping all my power in one place defeats the purpose of 2FA but you know, I trust Vaultwarden, and myself to keep it secure, implicitly.
Prove_your_argument@piefed.social · 2 pts · 52d
This change is really more about enterprise use cases. If you take DLP seriously you need to make sure the integrity of the controls on work provided devices are intact. Authenticator isn't managed by intune since users could use it for many things.
Nothing stops someone taking a photo of another screen. It's not a panacea. It's just one more hurdle.
Tollana1234567@lemmy.today · 1 pts · 51d
people likely using workday as for a job probably, or any app that uses MS.
AlecSadler@lemmy.dbzer0.com · 1 pts · 51d
Ugh, fuck workday
qupada@fedia.io · 53 pts · 52d
I can guarantee this will be a hilarious shitstorm of false positives wasting IT departments' time, because their detection of it is massively flawed.
At least once a month my - completely stock, and un-rooted - phone tells me I can't use Outlook/Teams because of root. Every time, a reboot is required to resolve this. One one occasion, TWO reboots.
Ignoring whatever reason Microsoft think they're blocking this for, it's going to regularly block regular users, who are not going to stand for it.
baguettefish@discuss.tchncs.de · 46 pts · 52d
microsoft truly hates productivity in the workplace
turkishcryptid@lemmy.zip · 22 pts · 52d
They somehow trying to eliminate everything they cannot control, funny
lemmysmash@beehaw.org · 15 pts · 52d
Fuck all these totalitarian corpos.
saltesc@lemmy.world · 13 pts · 52d
Ths is gonna cause some fun at work. I know our IT team would not be on top of this until one day a portion of employees can't SSO in. Then mayhem will ensue by heels being dug on both sides.
halcyoncmdr@piefed.social · 6 pts · 51d
Your company should be issuing devices if employees need to use apps like that. IT issued equipment shouldn't be jailbroken or rooted, it should be managed via MDM.
Otherwise they deserve it for trying to cut corners by having employees use personal devices. If they're doing that, they're almost certainly not paying for the work use of those devices either.
MrSulu@lemmy.ml · 13 pts · 51d
It may be painful but a switch to Ente Auth or similar is a must
ohshit604@sh.itjust.works · 7 pts · 51d
Yubikey.
MrSulu@lemmy.ml · 2 pts · 51d
I do keep looking at this, but then stick with Ente Auth for no better reason than no issues so far. Will look again
45o3b@lemmy.ml · 0 pts · 51d
They're not mutually exclusive. Yubikey is great for passkeys and Ente Auth is great for 2FA.
jsnfwlr@lemmy.ml · 3 pts · 51d
Yubikey also has a 2FA app that is unlocked by your actual yubikey
45o3b@lemmy.ml · -1 pts · 50d
Yes, I'm aware, but if both your passkey and your OTA codes are on the same device, it's not really two-factor authentication anymore, is it?
ohshit604@sh.itjust.works · 2 pts · 50d
Your passwords sit in your password manager, the Yubikey is your 2FA.
Depending on the service you’re using they may allow you to use WebAuthn to authenticate your account passwordless so all you would need is your Email/Username + Authentication device, however not all services support this.
ohshit604@sh.itjust.works · 3 pts · 51d
FIDO U2F, WebAuthn and OTP are supported by Yubikey’s. That’s what makes them inherently more secure than the digital-only solutions available, you need the physical key to authenticate accounts.
kazerniel@lemmy.world · 1 pts · 51d
Yeah that's my choice too bc it offers access from my desktop browser too, not just the mobile app. Tying accounts to a single device makes me uncomfortable.
BurgerBaron@quokk.au · 12 pts · 51d
I don't use my account for email anymore or use Windows very often but I just changed the two factor authenticator to Aegis. They make the text to use an alternative authenticator app tiny blue hyperlink text but you can do it confirmed.
EnsignWashout@startrek.website · 5 pts · 51d
Yes. I also switched to Aegis.
MonkderVierte@lemmy.zip · 8 pts · 51d
No, i don't use spyware.
Squizzy@lemmy.world · 2 pts · 49d
Its why they had to announce this, the venn diagram of microsoft authenticator users and degoogled android is likely two circles
Eternal192@anarchist.nexus · 7 pts · 52d
Why the fuck would you use a personal phone for work?
Get some cheap alternative and put the authenticator on that phone and say that is your main phone.
Triumph@fedia.io · 9 pts · 52d
2FA is not just for work.
Korhaka@sopuli.xyz · 8 pts · 52d
Sure but you can use your own choice of 2FA software for your own stuff
halcyoncmdr@piefed.social · 2 pts · 51d
Yeah but that's the worst app to use if you have a choice. There are a dozen better options.
NewNewAugustEast@lemmy.zip · 5 pts · 52d
I wont use my personal phone for anything work related except authentication. Since it sits in its own little jail, it's fine.
I work all over the world and remote in. I have no other work related devices or equipment.
I look at it as a key card from the old days when I had to go into a building. I think that is a pretty trivial use case and doesn't need them to provide a phone, and in fact I absolutely would not want a device owned by anyone else that I carried around. That is FAR worse.
That said, this change sucks as I will now need to get around this bullshit.
OwOarchist@pawb.social · 5 pts · 52d
Better yet, if your work requires you to have Microsoft Authenticator, tell them that they need to provide you with a device capable of using it.
Instead of spending your own money on a burner phone just for that, make your work pay for it.
Godort@lemmy.ca · 6 pts · 52d
How does the tool actually check for this?
Does it just use the Play Integrety API, or does it use some kind of other attestation check?
The need for full root privilege has fallen by the wayside assuming you can trust the OS running on the device. I dont hate this change if I can run a custom ROM that will report that the user does not have root privilege and that the OS has not been modified since boot.
Quetzalcutlass@lemmy.world · 8 pts · 52d
Probably Play Integrity, since it's still working on my phone with the Play Integrity Fix Magisk module installed.
cmnybo@discuss.tchncs.de · 6 pts · 52d
There are a couple Android ports of KeePass. They are open source and won't care if your phone is rooted.
BrikoX@lemmy.zip · 7 pts · 52d
Does it even support OTP?
Just use https://github.com/beemdevelopment/Aegis on Android.
cmnybo@discuss.tchncs.de · 3 pts · 52d
Yes, both KeePassDX and KeePass2Android support TOTP.
hopesdead@startrek.website · -3 pts · 52d
Any password manager that does not support OTP is worthless.
Godort@lemmy.ca · 9 pts · 52d
I disagree.
In fact, there is a strong argument to be made that storing your TOTP secrets in the same place as your passwords is bad practice.
You now have a single point of failure that if exploited, could grant an attacker total access to all your accounts.
matrixrunner@lemmy.world · 5 pts · 52d
KeePassDX Android does. Been using it for a while now.
OwOarchist@pawb.social · 5 pts · 52d
Because, obviously, you can't be a real person if you don't let the corpos control your device.
Clutter@sh.itjust.works · 3 pts · 50d
"Users of safe and private android versions have laughed at Microslop and their silly software"
JigglySackles@lemmy.world · 3 pts · 52d
Guess I need to get off of it faster now.
Korhaka@sopuli.xyz · 2 pts · 52d
Glad I don't use their app then.
01189998819991197253@infosec.pub · 2 pts · 49d
I use aegis. Totp works fine. I don't need push.
assassassin@fedinsfw.app · 1 pts · 52d
You can jailbreak IOS?
BrikoX@lemmy.zip · 6 pts · 52d
https://en.wikipedia.org/wiki/IOS_jailbreaking
assassassin@fedinsfw.app · 1 pts · 52d
Damn..
So the dream is dead?
marxismtomorrow@lemmy.today · 6 pts · 52d
Everyone that cares about security or privacy is working on custom android ROMs since there is no actual benefit to Apple hardware or software at this point in history. Plus you save money buying a Pixel device.
Quetzalcutlass@lemmy.world · 3 pts · 52d
Google is doing their best to strangle those too, by only releasing their source code when a new major Android release comes out. Custom ROM developers then have to rebase and integrate several months of commits all at once, with nowhere near enough time or resources to actually vet more than a tiny fraction of the changes.
Hudell@lemmy.dbzer0.com · 1 pts · 51d
Not everyone. Depending where you live there's no devices available that are compatible with secure custom ROMs (you might be able to deGoogle, but that's different from being secure).
xep@discuss.online · 2 pts · 51d
Your security doesn't just depend on what flavour of AOSP you decide to use. I'm assuming you're referring to GrapheneOS, which is only compatible with Pixel devices. Your threat model is also highly relevant. Depending on who you are and what you do, you can be secure on say LineageOS, which will run on a large variety of devices.
hexagonwin@lemmy.today · 1 pts · 51d
yep. it's sort of dead right now but not completely. in fact, a new bootrom exploit for Xs/11 era devices got released recently, and 11 is still getting supported on latest iOS 27.