▲ 751 ▼ Recursive authentication (lemmy.world) submitted 2 years ago by qaz@lemmy.world to c/memes@lemmy.ml 99 comments fedilink hide all child comments
[–] ComradePedro@lemmy.ml 46 points 2 years ago (3 children) Aegis Authenticator is the best 🏆 permalink fedilink source hideshow 6 child comments replies: [–] theo@lemmy.world 14 points 2 years ago (2 children) Unfortunately, Microsoft will often force their own 2FA app when logging in to 365. permalink fedilink source parent hideshow 4 child comments replies: [–] bdonvr@thelemmy.club 18 points 2 years ago (1 child) Not true, I've always used Authy. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 2 points 2 years ago (1 child) It became true in the past 6 months for me after always using Aegis. permalink fedilink source parent hideshow 2 child comments replies: [–] pineapplelover@lemm.ee 1 point 2 years ago Unless your organization forces specifically microsoft authenticator, then yeah. However, for several schools, that's never been an issue, there should be an option to use a third party authenticator in small text. permalink fedilink source parent [–] LemmyIsFantastic@lemmy.world 8 points 2 years ago (1 child) No they don't. That's a configuration setting. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 8 points 2 years ago (1 child) If your admins change the default away from Authenticator only they see bright red "MS 365 insecure" banners. So... Its a dark pattern that technically allows other options. permalink fedilink source parent hideshow 2 child comments replies: [–] dayvid@lemmy.world 4 points 2 years ago (1 child) TOTP codes can be phished. Technically FIDO2 keys like Yubikeys are one of the only phishing-resistant authenticators out there now, because they’re tied to the official domain of the real site and won’t authenticate to a fake. Passkeys are similarly phishing resistant, and Microsoft Authenticator will basically have passkey support added early this year. For now it’s actually not phishing resistant! Though it’s somewhat better than TOTP. The issue is that phishing resistance is important but it doesn’t stop session stealing (someone getting ahold of the cookie on your computer that confirms you’re signed in and have done MFA). But it does make it harder to steal sessions because phishing resistance means attackers need to get it from your computer instead of intercepting a fake login. Just a little technical backstory around why admins are needing to lock down auth methods in more ways as attacks become more sneaky and the more sophisticated attacks become automated and easier and thus more frequent. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 1 point 2 years ago I would use a yubikey if Microsoft let me :) Our admin tried allowing me to but there were errors. permalink fedilink source parent [–] burgersc12@sh.itjust.works 10 points 2 years ago Best one out there permalink fedilink source parent [–] onlyfans@lemmy.world 2 points 2 years ago (2 children) Thank you, how about for iOS users? permalink fedilink source parent hideshow 4 child comments replies: [–] ComradePedro@lemmy.ml 2 points 2 years ago Just switch to Android/AOSP lol I've heard good things about Raivo Authenticator for Apple devices, although I've never used it myself. permalink fedilink source parent [–] venji10@feddit.de 2 points 2 years ago Buy a different phone.. Apple is terrible in so many ways permalink fedilink source parent
[–] theo@lemmy.world 14 points 2 years ago (2 children) Unfortunately, Microsoft will often force their own 2FA app when logging in to 365. permalink fedilink source parent hideshow 4 child comments replies: [–] bdonvr@thelemmy.club 18 points 2 years ago (1 child) Not true, I've always used Authy. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 2 points 2 years ago (1 child) It became true in the past 6 months for me after always using Aegis. permalink fedilink source parent hideshow 2 child comments replies: [–] pineapplelover@lemm.ee 1 point 2 years ago Unless your organization forces specifically microsoft authenticator, then yeah. However, for several schools, that's never been an issue, there should be an option to use a third party authenticator in small text. permalink fedilink source parent [–] LemmyIsFantastic@lemmy.world 8 points 2 years ago (1 child) No they don't. That's a configuration setting. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 8 points 2 years ago (1 child) If your admins change the default away from Authenticator only they see bright red "MS 365 insecure" banners. So... Its a dark pattern that technically allows other options. permalink fedilink source parent hideshow 2 child comments replies: [–] dayvid@lemmy.world 4 points 2 years ago (1 child) TOTP codes can be phished. Technically FIDO2 keys like Yubikeys are one of the only phishing-resistant authenticators out there now, because they’re tied to the official domain of the real site and won’t authenticate to a fake. Passkeys are similarly phishing resistant, and Microsoft Authenticator will basically have passkey support added early this year. For now it’s actually not phishing resistant! Though it’s somewhat better than TOTP. The issue is that phishing resistance is important but it doesn’t stop session stealing (someone getting ahold of the cookie on your computer that confirms you’re signed in and have done MFA). But it does make it harder to steal sessions because phishing resistance means attackers need to get it from your computer instead of intercepting a fake login. Just a little technical backstory around why admins are needing to lock down auth methods in more ways as attacks become more sneaky and the more sophisticated attacks become automated and easier and thus more frequent. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 1 point 2 years ago I would use a yubikey if Microsoft let me :) Our admin tried allowing me to but there were errors. permalink fedilink source parent
[–] bdonvr@thelemmy.club 18 points 2 years ago (1 child) Not true, I've always used Authy. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 2 points 2 years ago (1 child) It became true in the past 6 months for me after always using Aegis. permalink fedilink source parent hideshow 2 child comments replies: [–] pineapplelover@lemm.ee 1 point 2 years ago Unless your organization forces specifically microsoft authenticator, then yeah. However, for several schools, that's never been an issue, there should be an option to use a third party authenticator in small text. permalink fedilink source parent
[–] ParetoOptimalDev@lemmy.today 2 points 2 years ago (1 child) It became true in the past 6 months for me after always using Aegis. permalink fedilink source parent hideshow 2 child comments replies: [–] pineapplelover@lemm.ee 1 point 2 years ago Unless your organization forces specifically microsoft authenticator, then yeah. However, for several schools, that's never been an issue, there should be an option to use a third party authenticator in small text. permalink fedilink source parent
[–] pineapplelover@lemm.ee 1 point 2 years ago Unless your organization forces specifically microsoft authenticator, then yeah. However, for several schools, that's never been an issue, there should be an option to use a third party authenticator in small text. permalink fedilink source parent
[–] LemmyIsFantastic@lemmy.world 8 points 2 years ago (1 child) No they don't. That's a configuration setting. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 8 points 2 years ago (1 child) If your admins change the default away from Authenticator only they see bright red "MS 365 insecure" banners. So... Its a dark pattern that technically allows other options. permalink fedilink source parent hideshow 2 child comments replies: [–] dayvid@lemmy.world 4 points 2 years ago (1 child) TOTP codes can be phished. Technically FIDO2 keys like Yubikeys are one of the only phishing-resistant authenticators out there now, because they’re tied to the official domain of the real site and won’t authenticate to a fake. Passkeys are similarly phishing resistant, and Microsoft Authenticator will basically have passkey support added early this year. For now it’s actually not phishing resistant! Though it’s somewhat better than TOTP. The issue is that phishing resistance is important but it doesn’t stop session stealing (someone getting ahold of the cookie on your computer that confirms you’re signed in and have done MFA). But it does make it harder to steal sessions because phishing resistance means attackers need to get it from your computer instead of intercepting a fake login. Just a little technical backstory around why admins are needing to lock down auth methods in more ways as attacks become more sneaky and the more sophisticated attacks become automated and easier and thus more frequent. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 1 point 2 years ago I would use a yubikey if Microsoft let me :) Our admin tried allowing me to but there were errors. permalink fedilink source parent
[–] ParetoOptimalDev@lemmy.today 8 points 2 years ago (1 child) If your admins change the default away from Authenticator only they see bright red "MS 365 insecure" banners. So... Its a dark pattern that technically allows other options. permalink fedilink source parent hideshow 2 child comments replies: [–] dayvid@lemmy.world 4 points 2 years ago (1 child) TOTP codes can be phished. Technically FIDO2 keys like Yubikeys are one of the only phishing-resistant authenticators out there now, because they’re tied to the official domain of the real site and won’t authenticate to a fake. Passkeys are similarly phishing resistant, and Microsoft Authenticator will basically have passkey support added early this year. For now it’s actually not phishing resistant! Though it’s somewhat better than TOTP. The issue is that phishing resistance is important but it doesn’t stop session stealing (someone getting ahold of the cookie on your computer that confirms you’re signed in and have done MFA). But it does make it harder to steal sessions because phishing resistance means attackers need to get it from your computer instead of intercepting a fake login. Just a little technical backstory around why admins are needing to lock down auth methods in more ways as attacks become more sneaky and the more sophisticated attacks become automated and easier and thus more frequent. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 1 point 2 years ago I would use a yubikey if Microsoft let me :) Our admin tried allowing me to but there were errors. permalink fedilink source parent
[–] dayvid@lemmy.world 4 points 2 years ago (1 child) TOTP codes can be phished. Technically FIDO2 keys like Yubikeys are one of the only phishing-resistant authenticators out there now, because they’re tied to the official domain of the real site and won’t authenticate to a fake. Passkeys are similarly phishing resistant, and Microsoft Authenticator will basically have passkey support added early this year. For now it’s actually not phishing resistant! Though it’s somewhat better than TOTP. The issue is that phishing resistance is important but it doesn’t stop session stealing (someone getting ahold of the cookie on your computer that confirms you’re signed in and have done MFA). But it does make it harder to steal sessions because phishing resistance means attackers need to get it from your computer instead of intercepting a fake login. Just a little technical backstory around why admins are needing to lock down auth methods in more ways as attacks become more sneaky and the more sophisticated attacks become automated and easier and thus more frequent. permalink fedilink source parent hideshow 2 child comments replies: [–] ParetoOptimalDev@lemmy.today 1 point 2 years ago I would use a yubikey if Microsoft let me :) Our admin tried allowing me to but there were errors. permalink fedilink source parent
[–] ParetoOptimalDev@lemmy.today 1 point 2 years ago I would use a yubikey if Microsoft let me :) Our admin tried allowing me to but there were errors. permalink fedilink source parent
[–] burgersc12@sh.itjust.works 10 points 2 years ago Best one out there permalink fedilink source parent
[–] onlyfans@lemmy.world 2 points 2 years ago (2 children) Thank you, how about for iOS users? permalink fedilink source parent hideshow 4 child comments replies: [–] ComradePedro@lemmy.ml 2 points 2 years ago Just switch to Android/AOSP lol I've heard good things about Raivo Authenticator for Apple devices, although I've never used it myself. permalink fedilink source parent [–] venji10@feddit.de 2 points 2 years ago Buy a different phone.. Apple is terrible in so many ways permalink fedilink source parent
[–] ComradePedro@lemmy.ml 2 points 2 years ago Just switch to Android/AOSP lol I've heard good things about Raivo Authenticator for Apple devices, although I've never used it myself. permalink fedilink source parent
[–] venji10@feddit.de 2 points 2 years ago Buy a different phone.. Apple is terrible in so many ways permalink fedilink source parent