Live data from Hacker News

Microsoft urges users to stop using phone-based multi-factor authentication

zdnet.com

11–20 of 26 posts

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#11

I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…

I use cheap android(100$) and that country's SIM, with Verizon (think TMobile also) the phone will work BAU when connected to WiFi in other countries, you will get your normal calls and SMS just as if you are in US.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#13
post #11

I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…

I use cheap android(100$) and that country's SIM, with Verizon (think TMobile also) the phone will work BAU when connected to WiFi in other countries, you will get your normal calls and SMS just as if you are in US.

I am not American, but it doesn't matter.

Yes, of course I can have a second phone or other solution. The point is that SMS-based auth is just worse than the alternatives.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#14
post #9

Earlier quoted context omitted.

It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.

You can just scan the QR code on multiple devices during setup. I have an old junker phone that I use just for this and being a universal remote that never leaves my end-table.

This is how I do it.

But of course, keeping emergency codes is a good idea too.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#15

Earlier quoted context omitted.

First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.

It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.

I use KeePassXC to store and create my TOTPs. If needed, I can (painfully) type the underlying hash into any app.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#16
post #12
post #8

And yet Azure login forces me to use SMS for 2FA.

I use Azure and haven't experienced that to be fair.

It may depend on your AD admins, to be fair. But still, it should be heavily discouraged, if not impossible.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#17

I literally hate when services and apps force me to use SMS-based authentication. When I travel I need to use a different SIM to access reasonably priced internet. Because I don't have a double-SIM phone, that means my other SIM is not active at the moment. Really dangerous trend is when this SMS confirmation is requested when I don't expect it. Once I was in the Philippines and AirBnb wanted me to verify my authenti…

I got a number through https://jmp.chat/ to solve this. Instead of using my real phone number, I use the VOIP number which is accessible over XMPP. Unlike most VOIP nubmers it works with short code numbers. Most services will use the number a couple are dumb and refuse to send messages to it.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#18

Earlier quoted context omitted.

First, it is a good idea to setup the authentication on multiple devices. This is not hard to do. Second, if that happens you are in the same situation as with the phone authentication -> so the disadvantage is the same.

It's not possible to have Google authenticator on multiple devices with the same accounts on it. It's easy to transfer from one to the other but that doesn't remove the single point of failure. Solution is to have back up codes for each account.

This is a problem with Google authenticator, not with RFC 6238 TOTP in general. Plenty of authenticator apps support backing up your secrets.

Re: Microsoft urges users to stop using phone-based multi-factor authentication

#20
post #2

So how do they suggest you reset these authenticators when your phone breaks?

Your company is usually given a privileged management interface to reset it for you.

If you work for an organization with their own PKI then there’s probably also an automated self service reset mechanism using a complicated process.

Post reply on HN