Earlier quoted context omitted.
Some of us don't use any proprietary OS. What are we supposed to do?
[flagged]
Lithuanian university locks out students again for not using proprietary 2FA
21–30 of 65 posts
Re: Lithuanian university locks out students again for not using proprietary 2FA
#22Earlier quoted context omitted.
The emails mention students only using FOSS. And while they are the minority, their point of view is reasonable. Studying should not involve handing over one’s data to MS or any other big tech corp without good reason.
Yeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..
Re: Lithuanian university locks out students again for not using proprietary 2FA
#23Re: Lithuanian university locks out students again for not using proprietary 2FA
#24Re: Lithuanian university locks out students again for not using proprietary 2FA
#25And as they say in the letter, MS Authenticator (which is not even really a 2FA system but a passwordless authentication product, likely the best on the market right now) is not even mandatory as SMS is also an option. Setting downsides of SMS 2FA aside, they are not actually being required to use proprietary software, but instead seem to have bundled two mostly unrelated concerns together. I mean, they're objecting to having to share their phone number with MS... In order to access their email that MS hosts. The privacy boundary they're making this stand over is just a very strange one.
TOTP isn't really a drop in replacement either, as MS Authenticator is intended to protect against a couple of classes of attacks that TOTP doesn't, most importantly 2FA interactive phishing, which TOTP remains vulnerable to. Following the Okta attacks a number of organizations have prohibited TOTP, as interactive phishing of TOTP tokens is becoming pretty common such that TOTP 2FA is no longer substantial protection against this extremely common attack vector. FIDO is another good option but frankly the usability of FIDO remains very poor and it produces a much higher volume of support issues than app-based interactive verification.
Re: Lithuanian university locks out students again for not using proprietary 2FA
#26I know it will be an unpopular answer, but given there are two options (namely: Microsoft Authenticator or using the SMS option) what is the problem? If the SMS option is such an attack to your privacy, use a cheapo phone with a prepaid SIM registered to your dog. Not all countries permit this, but it's a start.
Re: Lithuanian university locks out students again for not using proprietary 2FA
#27Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.
Re: Lithuanian university locks out students again for not using proprietary 2FA
#28It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…
The objection is that they're being required to compromise their security, either by installing Microsoft's spyware or enabling SMS 2FA.
Re: Lithuanian university locks out students again for not using proprietary 2FA
#29It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…
But the students were further aggravated by the incompetence of the university. There’s a bit in the articles and emails about how easy it was to hack into their infrastructure despite 2FA efforts. Together, these things (and some of the published emails) seem to show the university is stubborn and incompetent. Which is where students and VGTU seem to clash as well.
The university staff should have just enabled TOTP, or at least offered some reason to believe they generally knew what it was. Given the university claims to be specialised in tech, it is a reasonable expectation. Instead, their technical staff demonstrated a front line tech support level understanding.
It seems like those are the fundamental problems the students are surfacing.
Re: Lithuanian university locks out students again for not using proprietary 2FA
#30Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.
In the article the student mentions that they're using "a PinePhone running PostmarketOS"