Live data from Hacker News

Lithuanian university locks out students again for not using proprietary 2FA

gitlab.digilol.net

61–65 of 65 posts

Re: Lithuanian university locks out students again for not using proprietary 2FA

#61
post #6

I had a similar problem when I was required to use Outlook email. It turns out that outlook does support FIDO2 hardware keys (or app) in place of MS authenticator, but it is disabled by default. The Admin has to explicitly enable it. One then has to get though a number of roadblocks including: * The option to log in with a FIDO key does not show up in Firefox, only Chrome (and Edge?). Bugs? * MS only recognises keys…

Firefox on Mac and Linux doesn't yet support the Pin-required version of FIDO2. MS365 requires this mode.

This is incredibly infuriating from Mozilla and very sad to see. Again their browser shows they just cannot stay in the enterprise environment. Such a shame.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#62
post #61

Earlier quoted context omitted.

Firefox on Mac and Linux doesn't yet support the Pin-required version of FIDO2. MS365 requires this mode.

This is incredibly infuriating from Mozilla and very sad to see. Again their browser shows they just cannot stay in the enterprise environment. Such a shame.

https://bugzilla.mozilla.org/show_bug.cgi?id=1530370

This is the issue tracking it, and it looks to be nearing completion.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#63

Maybe the EU should solve this by mandating that all 2FA implementations support TOTP, analogous to how they mandated USB-C for smartphones.

TOTP is kinda lame once you've used FIDO2/CTAP2. Please skip TOTP as a requirement.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#64

Earlier quoted context omitted.

Security of what though? MS email and onedrive. I don't get it either, unless the critique isn't actually limited to the 2fa app.

The security of their personal devices on which they must install Microsoft spyware and accept it's terms, before being allowed to complete their education.

Ah ok. The 2fa isn't the important part, nor the service, it's the fact that it's an app of any kind that they otherwise would not choose to install on their personal property, and shouldn't have to in order to do something like simply be in school. I completely agree with that.

I'd say if the school isn't willing to modify their server configs to allow generic 2fa, they should be obligated to provide devices to run that app if they really insist on that app alone. Then maybe with that choice they might decide it makes more sense to reconsider simply having one admin do about an hour's research and setting some service options.

Re: Lithuanian university locks out students again for not using proprietary 2FA

#65

It's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the let…

TOTP phishing? Like, MITMing TOTP requests or something?
Post reply on HN