Live data from Hacker News

Lithuanian university locks out students again for not using proprietary 2FA

gitlab.digilol.net

31–40 of 65 posts

Re: Lithuanian university locks out students again for not using proprietary 2FA

#31

It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…

>It's kind of hard to follow the moral stance here.

Fighting for civil rights often makes you look like a prick, because you keep laser-focused on your goal and need to counter all the reasonable-sounding objections of people who were following their daily routines before this ball-breaker came along; but it is nevertheless necessary.

Contrary to Hollywood films, people don't stamp on other people's rights because they have some inner impulse to do evil, but because injustices are ingrained in the common way to do things, and fixing then implies to deviate from those routines; that's why it's so hard to change them.

That's the real meaning of the sentence "for evil to triumph, all it takes is for good people to do nothing". The movie script of a hero taken the matter in their hands and saving the world with heavy guns is but a fantasy

Re: Lithuanian university locks out students again for not using proprietary 2FA

#32

It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…

In no particular order:

* O365 doesn't require installing anything on your local device.

* SMS 2FA is less secure.

* Personal phone number is in a separate privacy domain from work/school email.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#33

Earlier quoted context omitted.

Some of us don't use any proprietary OS. What are we supposed to do?

[flagged]

Just because someone has a tiny binary blob on their otherwise open source device, doesn't mean they should give up and install a whole proprietary app from a marketing company that regularly communicates to the internet.

Let's try to be respectful; not everyone is willing to 'submit', and that's OK

Re: Lithuanian university locks out students again for not using proprietary 2FA

#36

Theyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.

Some of us don't use any proprietary OS. What are we supposed to do?

I work for a uni which is rolling out the MS modern auth - we have a FIDO2 option (Yubikeys I guess) for contentious objectors to the Authenticator apps.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#37
post #28

It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…

> The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? The objection is that they're being required to compromise their security, either by installing Microsoft's spyware or enabling SMS 2FA.

Security of what though? MS email and onedrive. I don't get it either, unless the critique isn't actually limited to the 2fa app.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#38
post #22

Earlier quoted context omitted.

Yeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..

When I was a student last, I was using an Ubuntu laptop, and an android phone that was no longer receiving updates, so couldn't run any of the new versions of the apps required to do so many things.

I had a Debian and a firefoxOS!

Nowadays I'm a sellout and traded liberty for convenience (and deserve neither, paraphrasing Benjamin Franklin), but I used to fight the FOSS fight. My first two jobs were on Agpl/gplv3/gplv2 products!

Re: Lithuanian university locks out students again for not using proprietary 2FA

#39
post #20

I know it will be an unpopular answer, but given there are two options (namely: Microsoft Authenticator or using the SMS option) what is the problem? If the SMS option is such an attack to your privacy, use a cheapo phone with a prepaid SIM registered to your dog. Not all countries permit this, but it's a start.

> registered to your dog. Not all countries permit this

In Lithuania you don’t even need to register anything. You can just buy a bag full of sim cards in any supermarket completely anonymously.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#40
post #6

I had a similar problem when I was required to use Outlook email. It turns out that outlook does support FIDO2 hardware keys (or app) in place of MS authenticator, but it is disabled by default. The Admin has to explicitly enable it. One then has to get though a number of roadblocks including: * The option to log in with a FIDO key does not show up in Firefox, only Chrome (and Edge?). Bugs? * MS only recognises keys…

Firefox on Mac and Linux doesn't yet support the Pin-required version of FIDO2. MS365 requires this mode.
Post reply on HN