I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…
Microsoft urges users to stop using phone-based multi-factor authentication
11–20 of 26 posts
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#12And yet Azure login forces me to use SMS for 2FA.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#13I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…
I use cheap android(100$) and that country's SIM, with Verizon (think TMobile also) the phone will work BAU when connected to WiFi in other countries, you will get your normal calls and SMS just as if you are in US.
Yes, of course I can have a second phone or other solution. The point is that SMS-based auth is just worse than the alternatives.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#14Earlier quoted context omitted.
It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.
You can just scan the QR code on multiple devices during setup. I have an old junker phone that I use just for this and being a universal remote that never leaves my end-table.
But of course, keeping emergency codes is a good idea too.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#15Earlier quoted context omitted.
First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.
It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#16Re: Microsoft urges users to stop using phone-based multi-factor authentication
#17I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#18Earlier quoted context omitted.
First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.
It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#19And yet Azure login forces me to use SMS for 2FA.
https://docs.microsoft.com/en-us/azure/active-directory/user...
Re: Microsoft urges users to stop using phone-based multi-factor authentication
#20So how do they suggest you reset these authenticators when your phone breaks?
If you work for an organization with their own PKI then there’s probably also an automated self service reset mechanism using a complicated process.