Ask HN: Should employers pay for employees' phones if 2FA apps are required?
11–20 of 70 posts
Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#12In the case of something like TOTP, though, I wouldn't insist that they provide a phone to use for it because it works without talking to any servers (unless I don't have a smartphone, of course).
My concern is to keep my employer's business and my personal business off of each other's systems. So if there's a requirement to use an app or to interact with company systems, then my employer needs to supply the equipment necessary to do that.
Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#13Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#14Our organization is using Office365. Either by accident, or just defaults getting increasingly more tight, Outlook won't connect to the account unless I allow it to be a device administrator. On my personal phone, that's a hard no. So I'm using the PWA for the occasions I NEED to check email. But a TOTP app of my choice, implementing a standard RFC protocol? I think that's okay , on the condition that it does not mea…
In the past I believe this was so that if the phone was lost it could be remote wiped for security. I agree that's a hard no for personal devices though.
On Android you can define a device as corporate owned, which mean the employer have full control over the device, or it can be user owned and instead of taking control of the entire device, it makes a sandbox in which the corporate data resides, and the mobility admin can only touch what is inside that sandbox. If the phone is lost or the employee leave the business, you can remotely wipe the sandbox while leaving the user data untouched.
IMO this is a better approach, but it depends on how the system is set up.
Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#15That being said, TOTP is practically standard and every phone have a method of generating their own TOTP so I don't mind adding employer's company to my BitWarden or Apple passwords. Same way I would not have problem to have SMS as a MFA.
Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#16Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#17Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#18Does anything the employer require need MDM? If so then yes, in fact they need to provide the phone in that case. Otherwise no IMHO.
Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#19Our organization is using Office365. Either by accident, or just defaults getting increasingly more tight, Outlook won't connect to the account unless I allow it to be a device administrator. On my personal phone, that's a hard no. So I'm using the PWA for the occasions I NEED to check email. But a TOTP app of my choice, implementing a standard RFC protocol? I think that's okay , on the condition that it does not mea…
In the past I believe this was so that if the phone was lost it could be remote wiped for security. I agree that's a hard no for personal devices though.
Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?
#20Well, the bigger question is, why is your employer using a 2FA mechanism that requires a phone?