Live data from Hacker News

Microsoft urges users to stop using phone-based multi-factor authentication

zdnet.com

1–10 of 26 posts

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#3
I literally hate when services and apps force me to use SMS-based authentication.

When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment.

Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authentication attempt. It can be not only frustrating, but dangerous - I have accommodation scheduled and without the access to my home number I could be easily left on the streets in a foreign country.

And my last complaint -> SMS can arrive pretty late when you are in a foreign country. Sometimes too late that the authentication window is closed.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#4
post #2

So how do they suggest you reset these authenticators when your phone breaks?

First, it is a good idea to setup the authentication on multiple devices. This is not hard to do.

Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#6

I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…

This.

With roaming and rampant robot calls, phone numbers should basically be considered no more static than IPs.

There's a reason iMessage/WhatsApp took over from legacy SMS.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#7
post #2

So how do they suggest you reset these authenticators when your phone breaks?

First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.

It's not possible to have Google authenticator on multiple devices with the same accounts on it.

It's easy to transfer from one to the other but that doesn't remove the single point of failure.

Solution is to have back up codes for each account.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#9

Earlier quoted context omitted.

First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.

It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.

You can just scan the QR code on multiple devices during setup. I have an old junker phone that I use just for this and being a universal remote that never leaves my end-table.
Post reply on HN