• Hotzilla@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    21
    ·
    edit-2
    11 months ago

    Sorry, as IT person I have to disagree, app based MFA is just way much easier to maintain instead of HW keys.

    Edit: forgot to mention that in Finland companies here has to provide phone if your work require that. In IT I don’t want nothing to do with users personal devices, and it sounds insane to me that in US companies force apps to your personal devices.

    • FiniteBanjo@lemmy.today
      cake
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      2
      ·
      edit-2
      11 months ago

      If you want to install software on my personal device with elevated privileges then I’ll just use a different service than your shitty low effort maintained trash.

      • Hotzilla@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        2
        ·
        11 months ago

        Company device of course. Like mentioned, in IT, I want nothing to do with users personal phones

        • FiniteBanjo@lemmy.today
          cake
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          11 months ago

          Oh hell yeah, then. At that point it’s just the company making their own apps to install on their own stuff, the way it should be.

    • jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      11 months ago

      I’ve had this argument with different people when asking for a hardware token vs app only two factor.

      I’m not installing a proprietary app on my personal device. I’ll use a open standard, I’ll use a light weight hardware token. I’m not going to run a invasive binary black box for push authentication 24/7 on my personal device.

      At this point everyone has extra phones that don’t get security updates. I just used a old phone installed the app on that phone, and left it in my desk… It’s kind of a terrible security dongle at this point.

      • Hotzilla@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        11 months ago

        Has to be company phone of course. In IT I don’t want nothing to do with your personal device.

        Here in Finland it is normal (or even required) that company provides you phone and subscription if your work needs that.

      • bus_factor@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        arrow-down
        1
        ·
        11 months ago

        They’re talking about operationally. They don’t want to configure and distribute a bajillion dongles to users.

      • HeavyDogFeet@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        2
        ·
        11 months ago

        Often times, yes. I don’t want to always have to have a USB key on me, but I always have access to MFA apps via my phone, watch, or laptop. I have no idea why you’re typing the code out instead of copying and pasting.

      • daq@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 months ago

        Pretty sure he’s talking about mfa that just asks for confirmation whether that’s you logging in on the phone. No typing required.

    • MSids@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      2
      ·
      11 months ago

      App-based TOTP are not phishing resistant and do not require any level of proximity to the login session. The future is more likely passkeys that use device TPMs.