Transcript

A wafrn woot (post) by @tinker@infosec.exchange saying “Microsoft Authenticator needs me to validate with Authenticator in order to log in with Authenticator to use it to authenticate another app with Authenticator. Here is the app telling me to open itself to validate itself with itself. #infosec #iHateComputers” It has a screenshot showing the microsoft authenticator app.

  • BlessedDog@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    24 minutes ago

    Currently doing an internship at an establishment with 1300+ users using Microsoft authenticator (required by policy). The amount of times I’ve had this same issue is insane. Worst part is, when we provision someone with a new company phone, they have to go to the Google play store to download Microsoft authenticator. The play store however, requires a google login to download apps, but the users cannot log in to their company Google account without authenticator, creating a circular dependency. This unintentionally means every employee HAS to have a personal google account to set up their company google account… Stupid as hell.

  • Tash@lemmy.world
    link
    fedilink
    English
    arrow-up
    48
    ·
    6 hours ago

    Pretty sure you have another device registered with Authenticator here, and it is asking you to verify against that.

    It would be bad if somebody could just steal your username/password and then register their own MFA, right?

  • Broadfern@lemmy.world
    link
    fedilink
    English
    arrow-up
    21
    arrow-down
    6
    ·
    5 hours ago

    This is why I hate passkeys and authenticators (as mandatory requirements). The moment I lose my phone I’m just completely fucked with no recourse, in actual use case.

    • TrickDacy@lemmy.world
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      47 minutes ago

      Yeah I had a beautiful moment trying to use Google’s find my phone feature in another country when it asked me to use MFA on…my fucking phone. Turned off Google MFA forever after that near nightmare. Luckily another kind tourist found and turned in my phone to the nearest worker at the place I was visiting

      • hdnsmbt@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 minutes ago

        Yeah, I also had a beautiful moment trying to use Google’s find my phone feature in another country when I didn’t know my password. Used “password123” after that near nightmare.

        Security works best when it’s really easy to get into my account even though I don’t remember my credentials.

    • CosmicTurtle0@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      12
      ·
      3 hours ago

      You’re supposed to have backups for MFA. Though for passkeys (specifically ones for yubikey) are really hard to backup.

      I am not always going to remember to register my primary yubikey and my two backups that are physically never together.

    • Wahots@pawb.social
      link
      fedilink
      arrow-up
      1
      ·
      1 hour ago

      I broke my phone, and this actually happened to me. Google had set my old broken phone as a default passkey without my knowledge, back when they were rolling it out. My sim card was retrievable, so I used SMS to get in after my password. Turns out, that’s not good enough. It took me days to get into my idiotic accounts (including Google authenticator for work) because of all the security hoops, even with backup codes, password managers, and a SIM card.

      My saving grace was Firefox Sync, which allowed me to get into Microsoft accounts and slowly start unwinding Google’s insane requirements.

    • Limonene@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      1
      ·
      5 hours ago

      I use andOTP for two factor authentication. It’s free and open source, and available from the F-Droid app store. It allows you to backup your cryptographic keys in plaintext, with a password, or asymmetrically encrypted using OpenPGP. I keep my backups in a fireproof safe on two flash drives.

      • Broadfern@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 hours ago

        Thank you for the resources, I’ll be sure to check them out.

        Unfortunately I’m still on iOS atm (hoping to switch to Android -> GrapheneOS down the line, when I have the finances), so I’m stuck trying to find something that’ll work between that and my Linux desktop, with GoogleAuth being my primary OTP app.

        Cursory Internet search suggests something called 2FAS for mobile so I’ll see if it’s a cross platform option. I actually didn’t know non-corpo authenticators existed until today so it’s an exciting path to explore. /gen /pos

        • vodka@lemm.ee
          link
          fedilink
          arrow-up
          2
          ·
          2 hours ago

          I would highly recommend Ente Auth for 2FA on iOS devices.

          It allows for export to a file that you can then import into other apps. You can also use their own sync service.

          Personally I use Ente Auth on iOS and Aegis on Android. Both support backups to files (I back up to my own nextcloud) and imports from each other. I could just use Ente Auth on my android devices too, but I just prefer Aegis.

  • oxysis@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    10
    ·
    6 hours ago

    I had an issue with this a few weeks ago, my old phone the charging port broke and I couldn’t get back into it. On my new phone it needed me to use the authenticator to log in to the authenticator. Made it my uni’s problem to solve the authenticator paradox

    • Honytawk@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      3 hours ago

      It’s a security feature.

      If it was easy to get into without the authenticator, then it would be useless.

    • LifeInMultipleChoice@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      3 hours ago

      Usually a simple fix on their end. Verify something like your school ID, go to the O365 admin portal remove the old phone (don’t have to) and send out a QR code to scan on the new phone. Depending on security measures you can assign a sms message code but many insurance companies have made requirements to phase those out. Sucks, because I liked those better, but I guess risk analysis was higher with them.

      One thing I did notice though was tokens in the authenticator app would carry over to new phones, where RSA securID tokens usually would not because they were tied to an ID number on the device. But those are just as easy to manage, but they will definitely piss people off. Now the Comp Portal app in government contracts, those are a bitch. You can spend an hour redoing everything just because a user forgot their password and all the apps aren’t linking the authenticator token with the portal.

  • Zorque@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    5 hours ago

    The steam app does this. Like, not in a fucked up useless way, but it still requires that you authenticate with its own pop up.

  • willeypete23@reddthat.com
    link
    fedilink
    arrow-up
    2
    ·
    5 hours ago

    I had Google fi. One time I got a new phone. Went to switch service to the new pixel. Moving service deactivate service on my old phone. Couldn’t sing in to Google Fi to activate my new service until I entered the code they texted me.