Live data from Hacker News

Ask HN: Should employers pay for employees' phones if 2FA apps are required?

news.ycombinator.com

61–70 of 70 posts

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#61
post #14
post #10

Earlier quoted context omitted.

In the past I believe this was so that if the phone was lost it could be remote wiped for security. I agree that's a hard no for personal devices though.

It can be less intrusive, but it depends how the person in charge of mobility set things up and the MDM tool capabilities. On Android you can define a device as corporate owned, which mean the employer have full control over the device, or it can be user owned and instead of taking control of the entire device, it makes a sandbox in which the corporate data resides, and the mobility admin can only touch what is insid…

Famous problem is that it breaks twrp (work profile). You need disable fingerprint unlock every time, which is very annoying

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#62
post #35
post #31

Earlier quoted context omitted.

You know they'll give a low-tier samsung with physical buttons that barely passes for a smartphone and you'll complain in less than a week that you can't install work apps on your personal phone.

Speak for yourself, if my work gave me a phone like that for 2FA, it would be absolutely perfect because I wouldn't use it for anything but 2FA.

I am speaking from experience. People complained they want the company to provide phones for the oncall rotation. In less than two rotations everyone was forwarding the oncall phone number to their personal one. Soon the phone was lost in a drawer and we integrated an oncall notifying app that everyone just installed on their phone.

The hassle of carrying an extra device, charging it, storing it and taking care of it is exactly that: a hassle.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#63

Earlier quoted context omitted.

i might be mistaken but i think a lot of the compliance standards go along the lines of do not mix personal and business equipment; to me this includes Phones - and it really should include a separate vlan (at least) for distributed employees.

> separate vlan What’s that gonna achieve when entire firm has zero trust policy?

if you run network analysis you can at least see how much data flows between that device from the router level (and also keeps your personal stuff segregated from work stuff, regardless of any software on business machine). it also keeps your nice centrally managed work system from inadvertently accessing your own personal systems; i dont want my work apple/ms sending all the network-spam to my personal stuff and vice versa. Also think of solar winds and such, if your work system is compromised by a supply chain attack (seeing they are higher targets), you also dont want your other devices at home to be on the radar to be compromised too

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#64

Personal devices should _never_ be used for work. That allows the line between self-owned work and employer-owned work to be thin/non-existent. That can make it a lot easier for your employer to own your personal projects. Don't do it. Don't use your corporate laptop for personal things, and don't use your personal equipment for corporate things. If they want to use 2FA, they need to provide the 2FA device.

While you're hundred percent right, the problem here is detachment. For example, many companies' security and procurement teams operate at the top. Downstream teams around the globe have no clue what's coming, it's not in their budget to purchase and manage 2FA devices (this is more complicated than one might think) and I've never once seen the upstream teams own the whole process, despite the obvious connection.

As a regular employee, I am just unlikely to refuse the employer's silent requirement to use my own device to log in into their systems. Hell, some companies have even started promoting BYOD (Bring Your Own Device), which is wrong on so many levels.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#65
post #62
post #35

Earlier quoted context omitted.

Speak for yourself, if my work gave me a phone like that for 2FA, it would be absolutely perfect because I wouldn't use it for anything but 2FA.

I am speaking from experience. People complained they want the company to provide phones for the oncall rotation. In less than two rotations everyone was forwarding the oncall phone number to their personal one. Soon the phone was lost in a drawer and we integrated an oncall notifying app that everyone just installed on their phone. The hassle of carrying an extra device, charging it, storing it and taking care of it…

I value the sanctity of my own hardware. Also, my personal phone is also an underpowered piece of shit, in part because I'm actually willing to endure quite a lot of annoyance to maintain a semblance of privacy on my hardware. It sounds like your coworkers aren't as ornery as myself. Lucky you, probably.

But, do note that we were talking about a phone for 2FA and you're talking about a phone for on-call. I'm too senior for on-call, but I need 2FA daily.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#66
post #50
post #37

[flagged]

> If employer is already paying you a salary, just be grateful. People always act like their employers owe them. You're an employee at will. Why should anyone "be grateful" for the salary they are owed? They fulfilled their side of the contract. For that matter, why should employees have to waste their own salary if their employers can't afford a phone to run the apps they require? They should be looking around and g…

sounds like you've never done hard manual labor

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#68

My company wants me it install Microsoft Authenticator but I find that unacceptable. That is my personal device and installation of any app is my choice and my choice only. That being said, TOTP is practically standard and every phone have a method of generating their own TOTP so I don't mind adding employer's company to my BitWarden or Apple passwords. Same way I would not have problem to have SMS as a MFA.

As far as they are concerned you do not own a smart phone.

Re: Ask HN: Should employers pay for employees' phones if 2FA apps are required?

#70
post #66
post #50

Earlier quoted context omitted.

> If employer is already paying you a salary, just be grateful. People always act like their employers owe them. You're an employee at will. Why should anyone "be grateful" for the salary they are owed? They fulfilled their side of the contract. For that matter, why should employees have to waste their own salary if their employers can't afford a phone to run the apps they require? They should be looking around and g…

sounds like you've never done hard manual labor

I had a guy out to install my windows this weekend. Man! he was a hard worker. Grunted every time he picked up a window, complained about his back, smashed his finger (REALLY bad... I probably would have gotten stiches) wrapped it up and kept working.

The whole time I thought: "I'm so glad I had the opportunity to go to college and get into this field".

But not once did I think, "I'm so glad my company is so gracious to pay me".

Yes, we are paid well for working in easy conditions, but it is commiserate to the value we provide due to the stuff in our heads. It's not because our companies are generous.

Post reply on HN