Live data from Hacker News

Lithuanian university locks out students again for not using proprietary 2FA

gitlab.digilol.net

51–60 of 65 posts

Re: Lithuanian university locks out students again for not using proprietary 2FA

#51

My Indian university does this and I'm powerless. Emailing then or convincing them didn't help. Atleast Europeans care about privacy. Everyone looked at me like I was retarded when I tried to explain the issue to them.

You are powerless because there is no law that makes you right. Maybe find someone who can change that?

Re: Lithuanian university locks out students again for not using proprietary 2FA

#52

> To use TOTP we need to reconfigure more than one system because they work differently or 2FA was not thought of when they were designed. This thought is repeated in the correspondence, does anyone have any idea what they actually mean by that? After all, if they're using Azure Active Directory, then surely the type of 2FA shouldn't matter that much to most of the software that's integrated with it, right? Why would…

The school should be providing phones if the students require them. I strongly believe 2fa is important, but it is even more important to acknowledge that not everyone owns the gadgets that you do. And they may not want to. So if a service requires 2fa they should also supply the necessary hardware to all of their users.

> The school should be providing phones if the students require them.

I agree in principle, but doubt that our reality matches up with that. It's easier for them to blame the minority of people, especially if nobody will stand up for them.

In their own words:

>> If your phone doesn’t support Microsoft Authenticator, you need to use “Call to phone”, if you don’t want that method to use, you need to change your phone, which support Microsoft.

They can just say: "Most people use phones with a mainstream OS, don't be a weirdo and just use a phone like that, like the rest of the people." Same unfortunate situation across the board, with plenty of software being Windows/Mac-only, drivers not being open source and for the most part almost nobody caring.

What's worse, in this case it seems like TOTP should be able to be supported, with relatively few issues, unless there is indeed something major I'm missing.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#53
post #10

Keep up the fight. I've tried this with banks, who are keen on forcing Android/iPhone apps on everyone. Should hopefully be easier to get a public entity to provide non-proprietary 2fa implementations.

Your bank allows apps? Luxury!

Re: Lithuanian university locks out students again for not using proprietary 2FA

#54

My Indian university does this and I'm powerless. Emailing then or convincing them didn't help. Atleast Europeans care about privacy. Everyone looked at me like I was retarded when I tried to explain the issue to them.

You are powerless because there is no law that makes you right. Maybe find someone who can change that?

I've tried but there's not enough momentum on this issue. Nobody cares. Can't find anyone who cares about the issue AND has the power/ability to cause change. There's no law too against this AFAIK. so there's no way forward that I can see.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#55

Earlier quoted context omitted.

You are powerless because there is no law that makes you right. Maybe find someone who can change that?

I've tried but there's not enough momentum on this issue. Nobody cares. Can't find anyone who cares about the issue AND has the power/ability to cause change. There's no law too against this AFAIK. so there's no way forward that I can see.

Most likely you are correct. I suspect most citizens of India put “right to privacy” far, far below many other issues. So many are still affected daily by clean water and electricity shortages, lack of economic opportunities, and inconsistent (corrupt) governance.

Europe is afforded the luxury to spend energy on issues like this that are well higher on Maslow’s hierarchy.

However, due to prevailing issues between religions and castes in India, perhaps some would be interested in a blanket “right-to-privacy” in order to better hide their affiliations. This doesn’t seem to be the direction they’re heading but it’s a small fulcrum for change perhaps.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#56

Earlier quoted context omitted.

The school should be providing phones if the students require them. I strongly believe 2fa is important, but it is even more important to acknowledge that not everyone owns the gadgets that you do. And they may not want to. So if a service requires 2fa they should also supply the necessary hardware to all of their users.

> The school should be providing phones if the students require them. I agree in principle, but doubt that our reality matches up with that. It's easier for them to blame the minority of people, especially if nobody will stand up for them. In their own words: >> If your phone doesn’t support Microsoft Authenticator, you need to use “Call to phone”, if you don’t want that method to use, you need to change your phone,…

Isn't it just weird that a university is using this language at all? A lot of their messages seem so unempathetic and unprofessional. The spirit of academia has always been about being open to ideas and embracing open standards from my experience, too. Something feels off.

"You need to change your phone, which support Microsoft" just sounds very shady for a state-funded university. Or perhaps I am too sceptical. But a "proprietary tech only" university seems a bit of an oxymoron and close-minded for me. I would expect even staff to protest that.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#57

It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…

> It's kind of hard to follow the moral stance here. Fighting for civil rights often makes you look like a prick, because you keep laser-focused on your goal and need to counter all the reasonable-sounding objections of people who were following their daily routines before this ball-breaker came along; but it is nevertheless necessary. Contrary to Hollywood films, people don't stamp on other people's rights because t…

This seems somewhat overblown, inasmuch as the use of proprietary, closed-source productivity applications developed in the United States is itself an a priori compromise of eFSF values.

Email is a thankless, dirty business (ask anyone that has ever done an Exchange migration), and there is no incentive for the University to necessarily use and maintain a persistent free software-based email backend. It would be a better outcome to allow students the ability to use their own, personally-chosen communication services and devices, with the caveat that this might exclude some students or faculty from accessing resources that are under the control of commercial partnerships.

Stop putting your hand in the meat grinder and turning the crank. It IS possible to live the FOSS dream; just stop whining that non-FOSS software and services have left you behind-it's not their directive to do so.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#58

Earlier quoted context omitted.

> Fighting for civil rights often makes you look like a prick, because you keep laser-focused on your goal and need to counter all the reasonable-sounding objections of people who were following their daily routines before this ball-breaker came along; but it is nevertheless necessary. you are correct. All true. But there are no easy to implement groupware, open office, email, chat suite. Yes, in hn you can say zoho…

The problem is being required to install Microsoft spyware on your personal devices

...to access non-free software or services. That is patently ridiculous and philosophically inconsistent.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#59
post #6

I had a similar problem when I was required to use Outlook email. It turns out that outlook does support FIDO2 hardware keys (or app) in place of MS authenticator, but it is disabled by default. The Admin has to explicitly enable it. One then has to get though a number of roadblocks including: * The option to log in with a FIDO key does not show up in Firefox, only Chrome (and Edge?). Bugs? * MS only recognises keys…

Some of the things you mention here are organizational implementation, potentially making things more difficult to support. For example, attestation is not enabled by default. An admin enabled that, and didn’t automatically allow-list common AAGUIDs.

TAPs can be programmatically generated in batches for a roll out.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#60
post #56

Earlier quoted context omitted.

> The school should be providing phones if the students require them. I agree in principle, but doubt that our reality matches up with that. It's easier for them to blame the minority of people, especially if nobody will stand up for them. In their own words: >> If your phone doesn’t support Microsoft Authenticator, you need to use “Call to phone”, if you don’t want that method to use, you need to change your phone,…

Isn't it just weird that a university is using this language at all? A lot of their messages seem so unempathetic and unprofessional. The spirit of academia has always been about being open to ideas and embracing open standards from my experience, too. Something feels off. "You need to change your phone, which support Microsoft" just sounds very shady for a state-funded university. Or perhaps I am too sceptical. But…

> Isn't it just weird that a university is using this language at all? A lot of their messages seem so unempathetic and unprofessional. The spirit of academia has always been about being open to ideas and embracing open standards from my experience, too. Something feels off.

It might just be a cultural thing, or the perception on the behalf of the staff, that this person is creating problems for them, where none should exist. I'm from Latvia, which is right next to Lithuania - most of the correspondence I've received in a Latvian university has also been a bit on the terse side of things. It also mirrors the attitude that some of the staff can have, some take pride in failing students, not really helping out with the subjects much, some are genuinely overworked. Of course, there were also plenty of genuinely good staff members.

For example, I remember reaching out to a professor to explain that I'm attending a software development conference and whether I could re-schedule the date on which I'd take an exam (maybe to take it together with those who would later re-take it after not passing). The answer was simply: "No." with a typo in that single word response, somehow. Also, I recall the local IT department sending me a fairly accusatory message about me doing port scanning, when I was testing out OpenVAS against my own VPS (a single node). Nothing wrong with asking questions, but maybe there's no reason to start with an accusatory tone and demanding an explanation. Oh well.

As another example, I recently had a postal package come in that I couldn't redirect to a package machine for pickup, for some reason. So, I wanted to have it delivered to my house (a service that's offered) by the postal worker. I reached out to the customer service by e-mail and just got a copy paste from the FAQ, with my question about the delivery going completely unaddressed. When I called them on the phone, the person there was nice and helped me figure everything out in a few minutes and arranged for the delivery.

People can be nice in person (or when talking over the phone) or when they know you, but for whatever reason many of the people are less nice online. There are fewer pleasantries in general, people typically get to the point more quickly, or might seem cold to someone from US or similar countries. That said, you don't really open the comments sections of news sites over here, unless you want to see something mocking or with profanity.

I'm really not sure why that is. It should probably be better somehow.

Post reply on HN