Recursive authentication

2 years ago by qaz to c/memes

VikingHippie 85 points 2 years ago

Fun fact: when my country transitioned to a new public authentication app, the default way was to use your passport to register. My passport was expired, though, so I had to show up in person with my birth certificate and social security card equivalent.

To get my birth certificate, I had to show up at the local office with, you guessed it, my passport.

Lucky for me that they accepted it in spite of being expired (none of the pertinent information such as my face, name and birth date had expired, after all), or I would probably be trapped in the loop to this day, years later.

path: 0 6427424, hotness: undefined, score: 85, children: 14
Bumblefumble 29 points 2 years ago

Ohh, that reminds me of when I moved to Sweden. Their digital ID, bankID, is as the name suggests issued by your bank, not the government, even though it is used for all official authentication. And that includes... you guessed it, creating a bank account. So that was a real chicken and egg situation where it seemed impossible to be properly integrated into the Swedish system.

path: 0 6427424 6431166, hotness: undefined, score: 29, children: 7
Sprokes 18 points 2 years ago

I think you have the situation everywhere. At one time in France they ask you for your bank account details to see that you have funds so that they give an ID. But the bank will refuse to open you an account without an ID. So it will depend on the agent handling your request.

path: 0 6427424 6431166 6433146, hotness: undefined, score: 18, children: 0
CurlyMoustache 7 points 2 years ago

Reminds me of the first days of BankID here in Norway. To get my new BankID to work with my current bank, I had to log in with, you guessed it, a BankID allready configured to my bank. Took a few weeks talking to the bank, showing up in person and queueing with others with the same problem before the bank realized they've made a mistake somewhere

Same happened when the code thingy the bank sent me ran out of batteries. I went to the bank and asked for a new one. Not possible, they said. I had to contact the main branch, and they would send me new one. It would only take one week or so. I had to pay a bill that day, and asked if I could open it to replace the batteries since there was visible screw with ordinary heads. They said that was illegal and hacking, and that I must replace it. On my way home I opened it, and bought the exact same batteries from a shop, and replaced them. Worked perfectly!

path: 0 6427424 6431166 6454716, hotness: undefined, score: 7, children: 0
liquidparasyte 7 points 2 years ago

Why do y'all in Europe have your bank manage your legal ID? Seems a bit backwards

path: 0 6427424 6431166 6465147, hotness: undefined, score: 7, children: 1
VikingHippie 2 points 2 years ago

We don't. We show banks picture ID to prove that we are who we say we are. That picture ID is usually our passport or driver's license, neither of which is managed by the bank.

path: 0 6427424 6431166 6465147 6473309, hotness: undefined, score: 2, children: 0
VikingHippie 6 points 2 years ago

Hi neighbor! waves across Øresund

Yeah, I'm a big fan of Scandinavian style government (unlike the current governments of both of our countries, it would seem) in general, but sometimes the bureaucracy can get a little bit ridiculous 😂

path: 0 6427424 6431166 6431834, hotness: undefined, score: 6, children: 1
Bumblefumble 2 points 2 years ago

Bare rolig, jeg er tilbage på den rigtige side af Sundet nu 😉

path: 0 6427424 6431166 6431834 6434753, hotness: undefined, score: 2, children: 0
Baku 1 point 2 years ago
path: 0 6427424 6431166 6594254, hotness: undefined, score: 1, children: 0
DillyDaily 5 points 2 years ago

This is why I currently have no proper ID.

I have my birth certificate and my public healthcare card, and a not expired but no longer fully accepted proof of age card that previously counted as full ID but no longer does, but without it I dont have enough ID to get the new form of ID the government introduced in place of the old one I have.

It's enough to prove who I am at a liquor store or chemist, day to day, but I can't get a passport until I sort it out.

path: 0 6427424 6467644, hotness: undefined, score: 5, children: 5
MisterFrog 1 point 2 years ago

When did they remove proof of age cards? (Vic or SA?)

path: 0 6427424 6467644 6471290, hotness: undefined, score: 1, children: 4
DillyDaily 3 points 2 years ago

Actual Proof of Age Cards are still around, and that's what I need to get (but I don't have anything with my current address on it, other than the lease agreement, so it's going to take a few steps over red tape to get proper ID, and I am not mentally healthy enough to push that process along right now)

I had a keypass, which they stopped in 2022. I only found out about proof of age cards last year, when I tried to get into an RSL and the bouncer asked if I had anything else because they're phasing out keypass.

I know it's stupid and ignorance isn't an excuse, but as a teenager I was told to get a keypass because "that's the ID you get when you don't have a licence" so I got a keypass, and for the next 15 years I didn't run into a single issue with not having the right ID. No one I worked with ever questioned why that's the only ID I had, so I never really stopped to research the specifics. I didn't know that keypass and "proof of age card" were different, I thought keypass was a proof of age card, just different names for it.

path: 0 6427424 6467644 6471290 6473145, hotness: undefined, score: 3, children: 3
VikingHippie 2 points 2 years ago

I am not mentally healthy enough to push that process along right now

Aren't there anyone who can help you with it, then? I don't know about Britain or Ireland (I'm guessing based on your use of chemist), but here in Denmark, there's all kinds of help available for when you can't do that kind of thing.

Granted, if you have ADHD and/or anxiety like me, I fully understand that even finding who to contact about it and then contacting them can itself be extremely difficult 😮‍💨

path: 0 6427424 6467644 6471290 6473145 6473373, hotness: undefined, score: 2, children: 2
ComradePedro 40 points 2 years ago path: 0 6424948, hotness: undefined, score: 40, children: 12
theo 14 points 2 years ago

Unfortunately, Microsoft will often force their own 2FA app when logging in to 365.

path: 0 6424948 6429372, hotness: undefined, score: 14, children: 7
bdonvr 17 points 2 years ago

Not true, I've always used Authy.

path: 0 6424948 6429372 6430175, hotness: undefined, score: 17, children: 2
ParetoOptimalDev 2 points 2 years ago

It became true in the past 6 months for me after always using Aegis.

path: 0 6424948 6429372 6430175 6435919, hotness: undefined, score: 2, children: 1
pineapplelover 1 point 2 years ago

Unless your organization forces specifically microsoft authenticator, then yeah. However, for several schools, that's never been an issue, there should be an option to use a third party authenticator in small text.

path: 0 6424948 6429372 6430175 6435919 6451054, hotness: undefined, score: 1, children: 0
LemmyIsFantastic 7 points 2 years ago

No they don't. That's a configuration setting.

path: 0 6424948 6429372 6429651, hotness: undefined, score: 7, children: 3
ParetoOptimalDev 8 points 2 years ago

If your admins change the default away from Authenticator only they see bright red "MS 365 insecure" banners.

So... Its a dark pattern that technically allows other options.

path: 0 6424948 6429372 6429651 6435903, hotness: undefined, score: 8, children: 2
dayvid 4 points 2 years ago

TOTP codes can be phished. Technically FIDO2 keys like Yubikeys are one of the only phishing-resistant authenticators out there now, because they’re tied to the official domain of the real site and won’t authenticate to a fake.

Passkeys are similarly phishing resistant, and Microsoft Authenticator will basically have passkey support added early this year. For now it’s actually not phishing resistant! Though it’s somewhat better than TOTP.

The issue is that phishing resistance is important but it doesn’t stop session stealing (someone getting ahold of the cookie on your computer that confirms you’re signed in and have done MFA). But it does make it harder to steal sessions because phishing resistance means attackers need to get it from your computer instead of intercepting a fake login.

Just a little technical backstory around why admins are needing to lock down auth methods in more ways as attacks become more sneaky and the more sophisticated attacks become automated and easier and thus more frequent.

path: 0 6424948 6429372 6429651 6435903 6468345, hotness: undefined, score: 4, children: 1
burgersc12 8 points 2 years ago
path: 0 6424948 6425065, hotness: undefined, score: 8, children: 0
onlyfans 2 points 2 years ago

Thank you, how about for iOS users?

path: 0 6424948 6427948, hotness: undefined, score: 2, children: 2
venji10 2 points 2 years ago

Buy a different phone.. Apple is terrible in so many ways

path: 0 6424948 6427948 6591635, hotness: undefined, score: 2, children: 0
ComradePedro 2 points 2 years ago

Just switch to Android/AOSP lol I've heard good things about Raivo Authenticator for Apple devices, although I've never used it myself.

path: 0 6424948 6427948 6477719, hotness: undefined, score: 2, children: 0
Strawberry 36 points 2 years ago

PSA, don't use Microsoft authenticator. It's easy to accidentally wipe your cloud backup and lose all your authenticator codes when switching devices

path: 0 6430836, hotness: undefined, score: 36, children: 16
Dirk 11 points 2 years ago

Cooperate forces me.

path: 0 6430836 6433119, hotness: undefined, score: 11, children: 3
Killercat103 5 points 2 years ago

I think you can use standard TOTP regardless if you add TOTP as an option in the authentication methods on your account page. At least I did and the system has yet to complain.

path: 0 6430836 6433119 6435899, hotness: undefined, score: 5, children: 2
PM_Your_Nudes_Please 3 points 2 years ago

Nope, IT can disable third-party TOTP services, and force all employees to use the official MS Authenticator app.

path: 0 6430836 6433119 6435899 6439133, hotness: undefined, score: 3, children: 1
Killercat103 1 point 2 years ago

Sounds like a antitrust violation imo. (Not based in knowledge of laws). In the future I hope to work in a co-op, non-profit, foss or privacy oriented bussiness or whatever. Just something I believe is beneficial to our future and not detrimental. Don't care if I lose potential wages or job security.

Just the standard run of the mill tech company for a private owner idealizing infinite growth for investors and making software that tries taking advantage of the user or even required to use such? Not for me. (I don't need perfection just want improvent)

path: 0 6430836 6433119 6435899 6439133 6469641, hotness: undefined, score: 1, children: 0
BluDood 9 points 2 years ago

Is there actually any way to export the secrets from MS authenticator? I've been wanting to move them to something like bitwarden but it's gonna take ages if I have to reset all ~50

path: 0 6430836 6431328, hotness: undefined, score: 9, children: 2
Midnight1938 3 points 2 years ago

They provide "Cloud Backups".

Take the time, move them 5 a day. Better than loosing them forever

path: 0 6430836 6431328 6435796, hotness: undefined, score: 3, children: 1
BluDood 1 point 2 years ago

Yeah I suppose that's the best solution, I'm just a little impatient lol

path: 0 6430836 6431328 6435796 6439755, hotness: undefined, score: 1, children: 0
scytale 4 points 2 years ago

Can you provide more info how it’s easy to accidentally wipe? I’ve only done a transfer once, but it was by installing authenticator on the new phone and logging in, then deleting the other one on the old phone after testing that the codes work.

path: 0 6430836 6457646, hotness: undefined, score: 4, children: 2
Strawberry 8 points 2 years ago

You have to begin the recovery on the new device before logging in. If you log in normally and enable cloud backup on the new device, it will simply overwrite the existing backup with a new empty one

path: 0 6430836 6457646 6462845, hotness: undefined, score: 8, children: 1
GreenSkree 4 points 2 years ago

That design is awful

path: 0 6430836 6457646 6462845 6468309, hotness: undefined, score: 4, children: 0
qaz 3 points 2 years ago

Don't worry, I'm going to keep using Bitwarden for my personal accounts.

path: 0 6430836 6430938, hotness: undefined, score: 3, children: 0
cyberpunk007 3 points 2 years ago

Yes, and while you can move it phone to phone on iOS, you cannot on Android. So stupid.

If you are forced to use it by your company just use it for that email, nothing else. Use something like authy instead.

path: 0 6430836 6435828, hotness: undefined, score: 3, children: 2
highenergyphysics 3 points 2 years ago

If your company forced you to use mobile authentication, they should also be providing you with a device on the company plan at no cost to the employee.

In which case you should absolutely use MS Auth and give them all your delicious work data because nothing personal should be on the device anyway.

path: 0 6430836 6435828 6437407, hotness: undefined, score: 3, children: 0
toastal 2 points 2 years ago

Authy requires a phone number last I checked & is a part of a for-profit entity. TOTP management is a simple task so there is no reason not to be using something open source.

path: 0 6430836 6435828 6470576, hotness: undefined, score: 2, children: 0
Midnight1938 1 point 2 years ago

Learnt that the hard way

path: 0 6430836 6435783, hotness: undefined, score: 1, children: 0
Swuden 1 point 2 years ago

Somehow I don't think there's much risk of anyone doing it willingly...

path: 0 6430836 6435218, hotness: undefined, score: 1, children: 0
CoopaLoopa 24 points 2 years ago

This is specifically an issue with corporate M365 accounts when a user tries to migrate to a new phone without access to the old phone where the authenticator was setup.

Personal MS accounts can backup their auth secret keys to cloud storage, and when signing in on a new device, it authenticates you with your cloud storage (Google/Apple) and properly restores your MS Authenticator app.

The issue is that while MS says you can backup your corporate M365 accounts in MS Authenticator, it doesnt actually store the secret key, so it's useless.

Have your administrator enable TAP (Temporary Access Passwords) on the tenant. Then an M365 admin can create a TAP for your account that lets you login without a password/2FA. You can use the TAP to login and rejoin MS Authenticator app. The TAP expires in 1 hour by default.

path: 0 6440488, hotness: undefined, score: 24, children: 2
spiffy_spaceman 3 points 2 years ago

I'm in this particular loop at work where I don't want and don't really need an account, so I'm going to pretend I didn't see this and if you could ensure that IT doesn't see this, that'd be great, thanks.

path: 0 6440488 6471218, hotness: undefined, score: 3, children: 0
agressivelyPassive 1 point 2 years ago

MS auth also supports SMS via phone number. That's a whole new level of insecure, but lets you migrate to a new phone rather easily.

I'm 90% sure, all that 2FA crap is a sham anyway.

path: 0 6440488 6598965, hotness: undefined, score: 1, children: 0
piranhaphish 18 points 2 years ago

Brought to you by the same company that takes you to the logout page when you go to the login URL

path: 0 6466871, hotness: undefined, score: 18, children: 0
MythTheWolf 16 points 2 years ago

∞-FA

path: 0 6425868, hotness: undefined, score: 16, children: 0
EdanGrey 14 points 2 years ago

I had this exact problem when I had to install this. Ridiculous

path: 0 6424983, hotness: undefined, score: 14, children: 1
qaz 10 points 2 years ago

You'd think such an important application would be properly tested, right?

path: 0 6424983 6425725, hotness: undefined, score: 10, children: 0
MMNT 13 points 2 years ago

I got FreeOTP from F-droid. Works like a charm.

path: 0 6424035, hotness: undefined, score: 13, children: 6
Appoxo 20 points 2 years ago

Aegis here

path: 0 6424035 6424890, hotness: undefined, score: 20, children: 1
AVincentInSpace 3 points 2 years ago

Secur user checking in

path: 0 6424035 6424890 6427392, hotness: undefined, score: 3, children: 0
qaz 10 points 2 years ago

I usually use Bitwarden myself, but the company uses Microsoft Authenticator.

path: 0 6424035 6424847, hotness: undefined, score: 10, children: 2
SeedyOne 5 points 2 years ago

I feel your pain

path: 0 6424035 6424847 6425790, hotness: undefined, score: 5, children: 0
saltesc 2 points 2 years ago

I use it for all of my work accounts. When it gives me troubles, I put my feet up.

path: 0 6424035 6424847 6427359, hotness: undefined, score: 2, children: 0
ryannathans 1 point 2 years ago

Isn't that discontinued? I just installed aegis from fdroid

path: 0 6424035 6594053, hotness: undefined, score: 1, children: 0
ChallengeApathy 12 points 2 years ago

That sort of risk is one major reason I stopped using MS Auth and went through the painstaking process of manually switching all of my accounts to a FOSS authenticator (Aegis Auth) instead.

path: 0 6436981, hotness: undefined, score: 12, children: 4
qaz 2 points 2 years ago

Does Aegis sync between devices?

path: 0 6436981 6438724, hotness: undefined, score: 2, children: 3
Appoxo 11 points 2 years ago

No, but you can back it up (encrypted) and restore it.

path: 0 6436981 6438724 6438899, hotness: undefined, score: 11, children: 0
gentooer 4 points 2 years ago

TOTP isn't supposed to be saved in a "cloud"

path: 0 6436981 6438724 6452710, hotness: undefined, score: 4, children: 0
liquidparasyte 2 points 2 years ago

It has an option for Android Backup Transport spoon...maybe?

path: 0 6436981 6438724 6465031, hotness: undefined, score: 2, children: 0
missphant 12 points 2 years ago

Microsoft will just refuse to let me log with a third-party TOTP after setting it up. Security key is also "not supported" on Firefox even though it works for every other site.

The most info they will get is my Minecraft account and that's already too much...

path: 0 6431086, hotness: undefined, score: 12, children: 3
qaz 4 points 2 years ago

I set it up with Bitwarden after a reset, but it showed a popup telling me to switch to MS Auth every time until one day there was no way to refuse the switch anymore.

path: 0 6431086 6433017, hotness: undefined, score: 4, children: 0
cyberpunk007 4 points 2 years ago

It's a configurable setting on the admin side. I managed a lot of m365 tenants.

path: 0 6431086 6435801, hotness: undefined, score: 4, children: 1
CoopaLoopa 1 point 2 years ago

^ Your M365 admin needs to know where to manage the specific authentication methods and be sure to disable MS auth rollouts. By default right now, authentication rollouts are enabled on all tenants with P1 licensing or above, and it only supports the MS Authenticator app.

Once that rollout is disabled, the authentication methods your admin has made available to you will actually work properly.

path: 0 6431086 6435801 6440340, hotness: undefined, score: 1, children: 0
Agent641 10 points 2 years ago

My university recently forced us to use this shitpile to 2FA, it never fails to disappoint

path: 0 6468913, hotness: undefined, score: 10, children: 0
ParetoOptimalDev 10 points 2 years ago

Anyone else hate Microsoft forcing you to use Authenticator rather than alternatives?

Just another way I'm forced to install Microsoft crap on my devices :/

path: 0 6435871, hotness: undefined, score: 10, children: 5
lhamil64 9 points 2 years ago

It's been a long time since I set it up, but I have Microsoft accounts in my usual TOTP app (Aegis). Maybe I did it manually? But it's definitely possible.

path: 0 6435871 6435956, hotness: undefined, score: 9, children: 2
qaz 3 points 2 years ago

Not if your organization disables alternative TOTP apps 😔.

path: 0 6435871 6435956 6438689, hotness: undefined, score: 3, children: 1
Appoxo 4 points 2 years ago

Is it a default setting?
If no, our admin didnt enable it and I could do it.

path: 0 6435871 6435956 6438689 6438914, hotness: undefined, score: 4, children: 0
Appoxo 7 points 2 years ago

You can work around it to use your own 2FA app.
Did it with my O365 account.

path: 0 6435871 6438909, hotness: undefined, score: 7, children: 0
corbin 7 points 2 years ago

I have 2FA through Authy on my Microsoft account.

path: 0 6435871 6438983, hotness: undefined, score: 7, children: 0
Honytawk 9 points 2 years ago

Probably means there already is MFA setup on that account, and now you doing it a second time.

Or you can just press the "get codes" button in the top right.

path: 0 6433265, hotness: undefined, score: 9, children: 2
qaz 7 points 2 years ago

The get codes button didn’t work the first time I tried it. But it did now after restarting the app a couple times. A bit finnicky but it works.

path: 0 6433265 6433620, hotness: undefined, score: 7, children: 1
sizing743 4 points 2 years ago

Yeah, when your setting it up there's a button that says something like "use another authenticator app" or it might say something like "configure without notifications".

Those generate normal TOTP QR codes which you can use in other apps

path: 0 6433265 6433620 6436044, hotness: undefined, score: 4, children: 0
crsu 6 points 2 years ago

Microsoft works

path: 0 6429968, hotness: undefined, score: 6, children: 1
anarchrist 3 points 2 years ago

Jumbo shrimp

path: 0 6429968 6430265, hotness: undefined, score: 3, children: 0
afraid_of_zombies 6 points 2 years ago

One day authentication of new users will be impossible and the only way to get on will be to purchase it from someone who already has it. Entire companies will run on a single account hey bought for millions of dollars. News stories will run of a vengeful or negligent employees bricking the one corporate account, until a cartel of business owners attempts to corner the market.

path: 0 6466864, hotness: undefined, score: 6, children: 0
LemmyIsFantastic 5 points 2 years ago

This is a configuration item. Nothing to do with the app. It's a choice your company has made.

path: 0 6429702, hotness: undefined, score: 5, children: 9
ParetoOptimalDev 2 points 2 years ago

My admins said they see a big red "insecure" banner if they allow other 2FA apps.

path: 0 6429702 6435943, hotness: undefined, score: 2, children: 1
LemmyIsFantastic -1 points 2 years ago

I mean, unless your service lets you pick individually that usually means turning on SMS. That's probably why they have a general policy, it's a pain in the ass to manage multiples.

path: 0 6429702 6435943 6438687, hotness: undefined, score: -1, children: 0
qaz 2 points 2 years ago

Interesting, do you happen to know which configuration item causes this?

path: 0 6429702 6430101, hotness: undefined, score: 2, children: 6
LemmyIsFantastic 2 points 2 years ago

The one that forces you only to use 'passwordless' logins or forces that MFA challenge. Your admins had a choice on what they allow.

path: 0 6429702 6430101 6430598, hotness: undefined, score: 2, children: 5
BCsven 1 point 2 years ago

It seems something changed on MS end though because I have control of what MFA i use on our corporate acxount, which was setup with Yubikey, until about a month ago when this Use Your Outlook Mobile started on it's own

path: 0 6429702 6430101 6430598 6435142, hotness: undefined, score: 1, children: 4
LemmyIsFantastic -1 points 2 years ago

🤷‍♂️ maybe it's a bug or change

path: 0 6429702 6430101 6430598 6435142 6435527, hotness: undefined, score: -1, children: 3
crystalmerchant 3 points 2 years ago

Lmaooo this just happened to me the other day. Drove me nuts

path: 0 6436682, hotness: undefined, score: 3, children: 0
Andrew15_5 3 points 2 years ago

Wait, is this really possible? With Steam you still will be able to access TOPT in the mobile app if you need to log in the same app, at least that's how it worked.

I mean, there are probably one time passwords that go with some of accounts when using F2A. But I don't care about Microsoft account either way.

path: 0 6424108, hotness: undefined, score: 3, children: 1
qaz 4 points 2 years ago

Yeah, I already went to IT several times to ask them to forcibly reset it. I'm WFH now, so I'll have to pay them another visit on Monday.

path: 0 6424108 6424914, hotness: undefined, score: 4, children: 0
_lilith 3 points 2 years ago

People run into this for company MFA not realizing that their IT can enable new account setups. If it's a personal account you already have a device setup so I hope you didn't yeet it into the ocean or you really are screwed

path: 0 6438851, hotness: undefined, score: 3, children: 0
Pantherina 2 points 2 years ago

Aegis Authenticator. Dont trust MS or Google your stuff

path: 0 6594896, hotness: undefined, score: 2, children: 0
samokosik 2 points 2 years ago
path: 0 6555022, hotness: undefined, score: 2, children: 0
mobsenpai -1 points 2 years ago

Same thing with proton pass. How will i login to proton pass if i save my proton mail password in it.

path: 0 6469653, hotness: undefined, score: -1, children: 3
arden 7 points 2 years ago

Why would you store your password manager's password in your password manager??? That's like putting a safe's key into the safe

path: 0 6469653 6471575, hotness: undefined, score: 7, children: 2
mobsenpai 1 point 2 years ago

I know but I remember it was saved by default in it. I am really confused about it. What should I do abt it? Should I just make a memorable password and remember the proton account password? or something else?

path: 0 6469653 6471575 6714266, hotness: undefined, score: 1, children: 1
arden 1 point 2 years ago path: 0 6469653 6471575 6714266 6837302, hotness: undefined, score: 1, children: 0
memes
memes

@lemmy.ml

login for more options
56051
14599
5528

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

go to feed...