Live data from Hacker News

Ask HN: Should employers pay for employees' phones if 2FA apps are required?

news.ycombinator.com

21–30 of 70 posts

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#23
post #10

Our organization is using Office365. Either by accident, or just defaults getting increasingly more tight, Outlook won't connect to the account unless I allow it to be a device administrator. On my personal phone, that's a hard no. So I'm using the PWA for the occasions I NEED to check email. But a TOTP app of my choice, implementing a standard RFC protocol? I think that's okay , on the condition that it does not mea…

In the past I believe this was so that if the phone was lost it could be remote wiped for security. I agree that's a hard no for personal devices though.

My university tried to do this with all android devices connecting to their exchange too a few years back. Hard no from me. I’m not letting some random person in IT wipe my phone remotely because they mixed me up with someone, or because I’m getting fired/expelled.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#24
post #14
post #10

Earlier quoted context omitted.

In the past I believe this was so that if the phone was lost it could be remote wiped for security. I agree that's a hard no for personal devices though.

It can be less intrusive, but it depends how the person in charge of mobility set things up and the MDM tool capabilities. On Android you can define a device as corporate owned, which mean the employer have full control over the device, or it can be user owned and instead of taking control of the entire device, it makes a sandbox in which the corporate data resides, and the mobility admin can only touch what is insid…

Personally, that's still an unacceptable approach. There is no way I'm going to allow any employer to have any degree of access to my phone. If my employer needs me to use a phone for work purposes, my employer needs to provide a work phone to me.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#25

My company wants me it install Microsoft Authenticator but I find that unacceptable. That is my personal device and installation of any app is my choice and my choice only. That being said, TOTP is practically standard and every phone have a method of generating their own TOTP so I don't mind adding employer's company to my BitWarden or Apple passwords. Same way I would not have problem to have SMS as a MFA.

I already have a TOTP app on my phone for all my other security (I have like 15 MFA codes), so adding an extra code isnt really a problem for me. P lus I'd much rather have just an extra code than carry a 2nd phone. Plus for me, a 2nd phone means on call. Plus Im just happy to have a good paying job. Me complaining about wanting an extra device doesnt benefit anyone. But thats just my situation.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#26

My company wants me it install Microsoft Authenticator but I find that unacceptable. That is my personal device and installation of any app is my choice and my choice only. That being said, TOTP is practically standard and every phone have a method of generating their own TOTP so I don't mind adding employer's company to my BitWarden or Apple passwords. Same way I would not have problem to have SMS as a MFA.

I won't use my personal phone number for SMS company accounts, because a lot of services won't let me use it for my personal account then.

Also it's gross, I hate giving out my number

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#27
If I am required to use my personal phone for work related 2FA and SMS(lots of services require a mobile phone number just to create an account), then I will start using work resources for my own personal benefit. Those GPUs are idle too much anyhow....

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#28
Personal devices should _never_ be used for work.

That allows the line between self-owned work and employer-owned work to be thin/non-existent.

That can make it a lot easier for your employer to own your personal projects.

Don't do it. Don't use your corporate laptop for personal things, and don't use your personal equipment for corporate things.

If they want to use 2FA, they need to provide the 2FA device.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#30
My employer pays for 1Password, and also a Yubikey. I don't have to use my phone for any work-related 2FA.

But yes, my policy is to absolutely never use personal devices for work, and vice versa. Complete and total separation. The laptop I use for work was paid for by my employer.

Post reply on HN