Live data from Hacker News

Lithuanian university locks out students again for not using proprietary 2FA

gitlab.digilol.net

21–30 of 65 posts

Re: Lithuanian university locks out students again for not using proprietary 2FA

#21

Earlier quoted context omitted.

Some of us don't use any proprietary OS. What are we supposed to do?

[flagged]

Actually when I was a student I was using OpenBSD on my laptop and couldn't afford a smart phone. This smells a lot like "Oh you're a fan? Name three of their songs!"

Re: Lithuanian university locks out students again for not using proprietary 2FA

#22
post #12

Earlier quoted context omitted.

The emails mention students only using FOSS. And while they are the minority, their point of view is reasonable. Studying should not involve handing over one’s data to MS or any other big tech corp without good reason.

Yeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..

When I was a student last, I was using an Ubuntu laptop, and an android phone that was no longer receiving updates, so couldn't run any of the new versions of the apps required to do so many things.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#23
post #17

Earlier quoted context omitted.

Yeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..

To me this looks like it’s about principle of not being denied education if you do not consent to big corp EULAs.

Foreign big corp EULAs.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#24

Earlier quoted context omitted.

Some of us don't use any proprietary OS. What are we supposed to do?

[flagged]

Clearly we must make many compromises with our privacy and personal data day-to-day. Perhaps this is not how things should be.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#25
It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else.

And as they say in the letter, MS Authenticator (which is not even really a 2FA system but a passwordless authentication product, likely the best on the market right now) is not even mandatory as SMS is also an option. Setting downsides of SMS 2FA aside, they are not actually being required to use proprietary software, but instead seem to have bundled two mostly unrelated concerns together. I mean, they're objecting to having to share their phone number with MS... In order to access their email that MS hosts. The privacy boundary they're making this stand over is just a very strange one.

TOTP isn't really a drop in replacement either, as MS Authenticator is intended to protect against a couple of classes of attacks that TOTP doesn't, most importantly 2FA interactive phishing, which TOTP remains vulnerable to. Following the Okta attacks a number of organizations have prohibited TOTP, as interactive phishing of TOTP tokens is becoming pretty common such that TOTP 2FA is no longer substantial protection against this extremely common attack vector. FIDO is another good option but frankly the usability of FIDO remains very poor and it produces a much higher volume of support issues than app-based interactive verification.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#26
post #20

I know it will be an unpopular answer, but given there are two options (namely: Microsoft Authenticator or using the SMS option) what is the problem? If the SMS option is such an attack to your privacy, use a cheapo phone with a prepaid SIM registered to your dog. Not all countries permit this, but it's a start.

[deleted]

Re: Lithuanian university locks out students again for not using proprietary 2FA

#27

Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.

You are wrong, sir. Seems like some of these students use Android ROMs without Google Services...and probably without any proprietary software.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#28

It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…

> The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product?

The objection is that they're being required to compromise their security, either by installing Microsoft's spyware or enabling SMS 2FA.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#29

It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…

I think it’s more fundamental than this. They do not want their education to be conditional on having MSFT software on their phone, or handing over personally identifiable data like their phone number to a big tech corp.

But the students were further aggravated by the incompetence of the university. There’s a bit in the articles and emails about how easy it was to hack into their infrastructure despite 2FA efforts. Together, these things (and some of the published emails) seem to show the university is stubborn and incompetent. Which is where students and VGTU seem to clash as well.

The university staff should have just enabled TOTP, or at least offered some reason to believe they generally knew what it was. Given the university claims to be specialised in tech, it is a reasonable expectation. Instead, their technical staff demonstrated a front line tech support level understanding.

It seems like those are the fundamental problems the students are surfacing.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#30

Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.

No, they're not using an iPhone or an Android.

In the article the student mentions that they're using "a PinePhone running PostmarketOS"

Post reply on HN