Live data from Hacker News

Lithuanian university locks out students again for not using proprietary 2FA

gitlab.digilol.net

11–20 of 65 posts

Re: Lithuanian university locks out students again for not using proprietary 2FA

#11
post #10

Keep up the fight. I've tried this with banks, who are keen on forcing Android/iPhone apps on everyone. Should hopefully be easier to get a public entity to provide non-proprietary 2fa implementations.

To be fair, it’s easier and more convenient to just tell the user to download their own app than having to set up any other 2FA service.

Authentication has been a solved problem for decades but no bank is going to ask the general public to use their SSH keys.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#12

Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.

The emails mention students only using FOSS. And while they are the minority, their point of view is reasonable. Studying should not involve handing over one’s data to MS or any other big tech corp without good reason.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#13
post #5

Maybe the EU should solve this by mandating that all 2FA implementations support TOTP, analogous to how they mandated USB-C for smartphones.

I genuinely didn't know there was a 2FA system that didn't support SMS/Email or TOTP.

Yandex key does. I have tried to scan the barcode & see the details, but its not standard TOTP. You need to have Yandex Key app installed.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#14

Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.

Some of us don't use any proprietary OS. What are we supposed to do?

Re: Lithuanian university locks out students again for not using proprietary 2FA

#15
post #12

Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.

The emails mention students only using FOSS. And while they are the minority, their point of view is reasonable. Studying should not involve handing over one’s data to MS or any other big tech corp without good reason.

Yeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..

Re: Lithuanian university locks out students again for not using proprietary 2FA

#16

Maybe the EU should solve this by mandating that all 2FA implementations support TOTP, analogous to how they mandated USB-C for smartphones.

It could happen, they recently forced banks to use 2FA for some operations if I remember correctly.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#17
post #12

Earlier quoted context omitted.

The emails mention students only using FOSS. And while they are the minority, their point of view is reasonable. Studying should not involve handing over one’s data to MS or any other big tech corp without good reason.

Yeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..

To me this looks like it’s about principle of not being denied education if you do not consent to big corp EULAs.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#18

Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.

Some of us don't use any proprietary OS. What are we supposed to do?

[flagged]

Re: Lithuanian university locks out students again for not using proprietary 2FA

#19
post #10

Keep up the fight. I've tried this with banks, who are keen on forcing Android/iPhone apps on everyone. Should hopefully be easier to get a public entity to provide non-proprietary 2fa implementations.

To be fair, it’s easier and more convenient to just tell the user to download their own app than having to set up any other 2FA service. Authentication has been a solved problem for decades but no bank is going to ask the general public to use their SSH keys.

The question is whether something standard like TOTP is also offered as an option (regardless of how "dark-patterny" it is to get to the option --- I've seen services that will heavily push their own app, but if you look carefully you'll see TOTP too, often disguised as "Google Authenticator" or something else that doesn't explicitly say TOTP but actually is.)

Authentication has been a solved problem for decades but no bank is going to ask the general public to use their SSH keys.

Nor ask them to put their smartcard in the reader, although many banks will already have given one to their customers...

Re: Lithuanian university locks out students again for not using proprietary 2FA

#20
I know it will be an unpopular answer, but given there are two options (namely: Microsoft Authenticator or using the SMS option) what is the problem? If the SMS option is such an attack to your privacy, use a cheapo phone with a prepaid SIM registered to your dog. Not all countries permit this, but it's a start.
Post reply on HN