Live data from Hacker News

Ask HN: Should employers pay for employees' phones if 2FA apps are required?

news.ycombinator.com

11–20 of 70 posts

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#11
If it's necessary for the employee to do the work, then yes. However, there are cheaper alternatives to phones, for example we provide hardware tokens (they cost around $30-40, such as https://www.yubico.com/products/security-key/ ) for those who don't have a corporate smartphone and are unwilling to use their personal devices for 2FA.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#12
In the big picture, I think that an employer has the obligation to provide any equipment that is needed to do the job.

In the case of something like TOTP, though, I wouldn't insist that they provide a phone to use for it because it works without talking to any servers (unless I don't have a smartphone, of course).

My concern is to keep my employer's business and my personal business off of each other's systems. So if there's a requirement to use an app or to interact with company systems, then my employer needs to supply the equipment necessary to do that.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#14
post #10

Our organization is using Office365. Either by accident, or just defaults getting increasingly more tight, Outlook won't connect to the account unless I allow it to be a device administrator. On my personal phone, that's a hard no. So I'm using the PWA for the occasions I NEED to check email. But a TOTP app of my choice, implementing a standard RFC protocol? I think that's okay , on the condition that it does not mea…

In the past I believe this was so that if the phone was lost it could be remote wiped for security. I agree that's a hard no for personal devices though.

It can be less intrusive, but it depends how the person in charge of mobility set things up and the MDM tool capabilities.

On Android you can define a device as corporate owned, which mean the employer have full control over the device, or it can be user owned and instead of taking control of the entire device, it makes a sandbox in which the corporate data resides, and the mobility admin can only touch what is inside that sandbox. If the phone is lost or the employee leave the business, you can remotely wipe the sandbox while leaving the user data untouched.

IMO this is a better approach, but it depends on how the system is set up.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#15
My company wants me it install Microsoft Authenticator but I find that unacceptable. That is my personal device and installation of any app is my choice and my choice only.

That being said, TOTP is practically standard and every phone have a method of generating their own TOTP so I don't mind adding employer's company to my BitWarden or Apple passwords. Same way I would not have problem to have SMS as a MFA.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#18

Does anything the employer require need MDM? If so then yes, in fact they need to provide the phone in that case. Otherwise no IMHO.

Yeah generally security sensitive orgs don’t want mixing anyway. They want a work only device and provide one.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#19
post #10

Our organization is using Office365. Either by accident, or just defaults getting increasingly more tight, Outlook won't connect to the account unless I allow it to be a device administrator. On my personal phone, that's a hard no. So I'm using the PWA for the occasions I NEED to check email. But a TOTP app of my choice, implementing a standard RFC protocol? I think that's okay , on the condition that it does not mea…

In the past I believe this was so that if the phone was lost it could be remote wiped for security. I agree that's a hard no for personal devices though.

Amazing how they will install spyware to wipe the device but not to back up the device

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#20
post #16

Well, the bigger question is, why is your employer using a 2FA mechanism that requires a phone?

Because duo sales got the nontechnical admin to sign a contract. You really can’t run from that phenomenon unless you run your own business.
Post reply on HN