Live data from Hacker News

Lithuanian university locks out students again for not using proprietary 2FA

gitlab.digilol.net

41–50 of 65 posts

Re: Lithuanian university locks out students again for not using proprietary 2FA

#41

Earlier quoted context omitted.

To be fair, it’s easier and more convenient to just tell the user to download their own app than having to set up any other 2FA service. Authentication has been a solved problem for decades but no bank is going to ask the general public to use their SSH keys.

The question is whether something standard like TOTP is also offered as an option (regardless of how "dark-patterny" it is to get to the option --- I've seen services that will heavily push their own app, but if you look carefully you'll see TOTP too, often disguised as "Google Authenticator" or something else that doesn't explicitly say TOTP but actually is.) Authentication has been a solved problem for decades but…

British banks issued EMV card readers and used them for authentication from around 2005 to 2010, 2015-ish.

It looks like some still provide this to customers who can't use other methods.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#42

It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…

> It's kind of hard to follow the moral stance here. Fighting for civil rights often makes you look like a prick, because you keep laser-focused on your goal and need to counter all the reasonable-sounding objections of people who were following their daily routines before this ball-breaker came along; but it is nevertheless necessary. Contrary to Hollywood films, people don't stamp on other people's rights because t…

> Fighting for civil rights often makes you look like a prick, because you keep laser-focused on your goal and need to counter all the reasonable-sounding objections of people who were following their daily routines before this ball-breaker came along; but it is nevertheless necessary.

you are correct. All true.

But there are no easy to implement groupware, open office, email, chat suite. Yes, in hn you can say zoho or sogo or libreoffice. While I totally use OSS, it is a pain for Universities to find talent to implement this at scale.

Also a majority just use MS products and want compatibility. This is similar to tons of devs doing OSS dev but using MacOS (and using VM or remote ssh) as they want their devices to run for 12 hours on battery.

Some European universities tried going open solutions - this patchwork either failed or some even got hacked.

At the end, there are no easy solutions. I sincerely wished some one like Linux foundation implements a total OSS solution based on nextcloud to build all integrated suite to compete with G-suite or MS.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#43
> To use TOTP we need to reconfigure more than one system because they work differently or 2FA was not thought of when they were designed.

This thought is repeated in the correspondence, does anyone have any idea what they actually mean by that? After all, if they're using Azure Active Directory, then surely the type of 2FA shouldn't matter that much to most of the software that's integrated with it, right?

Why wouldn't the suggestions presented in the e-mails work?

  Go to Security > Multifactor Authentication > Additional cloud-based multifactor authentication settings.
  Tick the checkboxes like in the attached image.
Presumably along the lines of: https://learn.microsoft.com/en-us/azure/active-directory-b2c...

Other than that, it feels like repeated back and forth, with either a lack of mutual understanding of what's actually being used sometimes, or the repeated statement above, which is unfortunate to see.

Props to the person for standing their ground due to what they believe in, but I feel that many would (unfortunately?) just get a cheap Android device for something like this, if their daily driver was something else.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#44

> To use TOTP we need to reconfigure more than one system because they work differently or 2FA was not thought of when they were designed. This thought is repeated in the correspondence, does anyone have any idea what they actually mean by that? After all, if they're using Azure Active Directory, then surely the type of 2FA shouldn't matter that much to most of the software that's integrated with it, right? Why would…

The school should be providing phones if the students require them. I strongly believe 2fa is important, but it is even more important to acknowledge that not everyone owns the gadgets that you do. And they may not want to. So if a service requires 2fa they should also supply the necessary hardware to all of their users.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#45

Earlier quoted context omitted.

> It's kind of hard to follow the moral stance here. Fighting for civil rights often makes you look like a prick, because you keep laser-focused on your goal and need to counter all the reasonable-sounding objections of people who were following their daily routines before this ball-breaker came along; but it is nevertheless necessary. Contrary to Hollywood films, people don't stamp on other people's rights because t…

> Fighting for civil rights often makes you look like a prick, because you keep laser-focused on your goal and need to counter all the reasonable-sounding objections of people who were following their daily routines before this ball-breaker came along; but it is nevertheless necessary. you are correct. All true. But there are no easy to implement groupware, open office, email, chat suite. Yes, in hn you can say zoho…

The problem is being required to install Microsoft spyware on your personal devices

Re: Lithuanian university locks out students again for not using proprietary 2FA

#46
post #28

Earlier quoted context omitted.

> The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? The objection is that they're being required to compromise their security, either by installing Microsoft's spyware or enabling SMS 2FA.

Security of what though? MS email and onedrive. I don't get it either, unless the critique isn't actually limited to the 2fa app.

The security of their personal devices on which they must install Microsoft spyware and accept it's terms, before being allowed to complete their education.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#47
post #12

Earlier quoted context omitted.

The emails mention students only using FOSS. And while they are the minority, their point of view is reasonable. Studying should not involve handing over one’s data to MS or any other big tech corp without good reason.

Yeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..

Did anyone force you to use either of those to complete your education? No? What's your point again?

Re: Lithuanian university locks out students again for not using proprietary 2FA

#48

Earlier quoted context omitted.

Some of us don't use any proprietary OS. What are we supposed to do?

I work for a uni which is rolling out the MS modern auth - we have a FIDO2 option (Yubikeys I guess) for contentious objectors to the Authenticator apps.

Do you hand out the keys for free? If not you are still punishing people who have the moral high ground.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#49

> To use TOTP we need to reconfigure more than one system because they work differently or 2FA was not thought of when they were designed. This thought is repeated in the correspondence, does anyone have any idea what they actually mean by that? After all, if they're using Azure Active Directory, then surely the type of 2FA shouldn't matter that much to most of the software that's integrated with it, right? Why would…

The universities in Lithuania are incompetent when it comes to IT. I graduated from Vilnius University and they also were Microsoft shills that don't know anything better.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#50
post #12

Earlier quoted context omitted.

The emails mention students only using FOSS. And while they are the minority, their point of view is reasonable. Studying should not involve handing over one’s data to MS or any other big tech corp without good reason.

Yeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..

Heh, ironic that a user named cyberpunk is defending the corporate default.

Advocating for change is not invalidated by hypocritical details. Don't be that guy.

Post reply on HN