Live data from Hacker News

Lithuanian university locks out students again for not using proprietary 2FA

gitlab.digilol.net

1–10 of 65 posts

Re: Lithuanian university locks out students again for not using proprietary 2FA

#2
Previous discussion at https://news.ycombinator.com/item?id=35643915. The student was locked out again on 2023-04-26.

Note that the link is a permalink, and if you're reading this in the future you may want to go to the master branch at https://gitlab.digilol.net/Siren/vgtu-article/-/blob/master/....

Re: Lithuanian university locks out students again for not using proprietary 2FA

#5

Maybe the EU should solve this by mandating that all 2FA implementations support TOTP, analogous to how they mandated USB-C for smartphones.

I genuinely didn't know there was a 2FA system that didn't support SMS/Email or TOTP.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#6
I had a similar problem when I was required to use Outlook email. It turns out that outlook does support FIDO2 hardware keys (or app) in place of MS authenticator, but it is disabled by default. The Admin has to explicitly enable it.

One then has to get though a number of roadblocks including:

* The option to log in with a FIDO key does not show up in Firefox, only Chrome (and Edge?). Bugs?

* MS only recognises keys from "Partner organisations". If you go an open source key, such as Solo, it probably won't be an MS partner and you will have to get the Admin to add AAGUID numbers for your type of key.

* A "Temporary Access Pass" needs to be issued by the Admin for first sign-in, to boot the chain of trust.

All in all it's a pain for the Admin compared to saying "Download MS Authenticator", hence it may be difficult to get an Admin to admit that the FIDO option is there.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#9

Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.

I think it's a stupid hill for the university to die on.
Post reply on HN