Live data from Hacker News

Ask HN: Should employers pay for employees' phones if 2FA apps are required?

news.ycombinator.com

51–60 of 70 posts

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#51
Of course: if they need the security, especially if it can't be achieved with a standard TOTP generator, it doesn't really make sense to rely on whatever their employers have lying around (which could very well be not an Android/iOS phone, new enough, with enough space, bootlocked/un-rooted enough, or even a phone in the first place).

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#52

My company wants me it install Microsoft Authenticator but I find that unacceptable. That is my personal device and installation of any app is my choice and my choice only. That being said, TOTP is practically standard and every phone have a method of generating their own TOTP so I don't mind adding employer's company to my BitWarden or Apple passwords. Same way I would not have problem to have SMS as a MFA.

I won't use my personal phone number for SMS company accounts, because a lot of services won't let me use it for my personal account then. Also it's gross, I hate giving out my number

Agreed, but industry best practice is to not use SMS for MFA.

If anyone is doing that in 2024, that is a warning sign.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#53
If you use linux on your work laptop you can use oathtool to register 2fa. I have a custom script (with zenity) that, when pressing a global hotkey, allows me to fill the 6-number directly. No personal phone needed, and it's even faster. My work laptop is my work's 2fa device.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#55
post #14
post #10

Earlier quoted context omitted.

In the past I believe this was so that if the phone was lost it could be remote wiped for security. I agree that's a hard no for personal devices though.

It can be less intrusive, but it depends how the person in charge of mobility set things up and the MDM tool capabilities. On Android you can define a device as corporate owned, which mean the employer have full control over the device, or it can be user owned and instead of taking control of the entire device, it makes a sandbox in which the corporate data resides, and the mobility admin can only touch what is insid…

We tried this but didn't make an exception for outlook or teams so it was useless.

I'm not going to turn that sandbox on when I'm not at work.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#56
post #24
post #14

Earlier quoted context omitted.

It can be less intrusive, but it depends how the person in charge of mobility set things up and the MDM tool capabilities. On Android you can define a device as corporate owned, which mean the employer have full control over the device, or it can be user owned and instead of taking control of the entire device, it makes a sandbox in which the corporate data resides, and the mobility admin can only touch what is insid…

Personally, that's still an unacceptable approach. There is no way I'm going to allow any employer to have any degree of access to my phone. If my employer needs me to use a phone for work purposes, my employer needs to provide a work phone to me.

And that's entirely your right not to use your personal device for work, and I agree with your position, while some others might be more lenient and will accept to have it on their personal device for the convenience of carrying and charging only one device.

It's nice having some flexibility for the different mindsets, but as long as the tools are provided by the employer when they're mandatory I don't see a problem.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#57

My company wants me it install Microsoft Authenticator but I find that unacceptable. That is my personal device and installation of any app is my choice and my choice only. That being said, TOTP is practically standard and every phone have a method of generating their own TOTP so I don't mind adding employer's company to my BitWarden or Apple passwords. Same way I would not have problem to have SMS as a MFA.

> My company wants me it install Microsoft Authenticator but I find that unacceptable.

I had them give me a phone. It sits on my desk. 99% of 9he time, it's used only for Microsoft Authenticator. (That does not count the seemingly endless "Scam Likely" calls I simply ignore.)

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#59
If my employer wants me “on call” and accessable, they can either:

A) provide a phone. B) pay for part of my personal bill; but no MDM allowed. C) be ok with me not always being available. I enter the job like this. I state I am also a firefighter, if I don’t answer, I’m involved. Managers can manage.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#60

They probably should, but they generally won’t.

I guess this depends on location.

I work in Finland and in all the jobs I've hard for Finnish companies they've either offered to pay for a new phone for me, or offered to pay my phone bill if I kept my personal phone.

Generally I don't actually do anything work-related on my phone, I just use Duo and Okta apps for logins, and have a 2FA application for some site-specific logins.

Post reply on HN