Microsoft urges users to stop using phone-based multi-factor authentication
1–10 of 26 posts
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#2Re: Microsoft urges users to stop using phone-based multi-factor authentication
#3When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment.
Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authentication attempt. It can be not only frustrating, but dangerous - I have accommodation scheduled and without the access to my home number I could be easily left on the streets in a foreign country.
And my last complaint -> SMS can arrive pretty late when you are in a foreign country. Sometimes too late that the authentication window is closed.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#4So how do they suggest you reset these authenticators when your phone breaks?
Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#5So how do they suggest you reset these authenticators when your phone breaks?
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#6I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…
With roaming and rampant robot calls, phone numbers should basically be considered no more static than IPs.
There's a reason iMessage/WhatsApp took over from legacy SMS.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#7So how do they suggest you reset these authenticators when your phone breaks?
First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.
It's easy to transfer from one to the other but that doesn't remove the single point of failure.
Solution is to have back up codes for each account.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#8Re: Microsoft urges users to stop using phone-based multi-factor authentication
#9Earlier quoted context omitted.
First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.
It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.