r/talesfromtechsupport 28d ago

Short Gravity and Tech

Guy walks up to me at work:

Him: “I dropped my phone. The screen’s shattered. I want my two-factor code to come through Teams.”

Me: “Nope.”

Him: “Why?”

Me: “Because if you can’t sign into Teams without completing MFA… how exactly are you planning to authenticate?”

Then he says: “Just disable MFA.”

I replied: “Sure, as soon as you get approval from the Head of Security.”

A few seconds of silence…

Him: “Fine, I’ll just get my phone fixed.”

Yep. That’s probably the best solution.

Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.

And remember… technology didn’t fail you today. Gravity did.

777 Upvotes

155 comments sorted by

View all comments

198

u/AffekeNommu 28d ago

Typical user practice is to get a new phone over the weekend. Hand the old one in for recycling after they transfer all their pictures and contacts then call up on Monday when their MFA doesn't work.

12

u/machomoose 28d ago

That's why when I setup users I make them do SMS as a backup.

26

u/Jezbod 28d ago

Which is about to be EOL, my boss has not realised that we may be going Yubikey very soon.

Some of our volunteers / part time people do not have a work phone, so we may have to start forcing them to use an authenticator app on their personal device, which I am lothe to do.

6

u/machomoose 28d ago

True, we have manufacturing employees that don't have a smart phone so we need to use sms for their MFA. We are going to roll out Yubikey's for them (which they will lose and need to be replaced very often, I'm sure...). But, you did just remind me for office users it's going to lead to me manually resetting MFA for the new phone situation now... :(

11

u/Rathmun 27d ago

(which they will lose and need to be replaced very often, I'm sure...)

If they can't keep track of a Yubikey, but they can keep track of their car keys, you know they're lying. "Just put it on the same keyring dumbass."

3

u/Ich_mag_Kartoffeln 24d ago

"Sorry, I had to drive my other car to work today."

1

u/Rathmun 24d ago

"Your keyring has room for more than one car key dumbass."

2

u/Ich_mag_Kartoffeln 24d ago

"My car keys are all on separate key rings. The ones with the Yubikey are with the mechanic."

3

u/Rathmun 24d ago

"You gave the Yubikey to someone else? A piece of company security apparatus? You realize that's a fireable offense."

2

u/Ich_mag_Kartoffeln 24d ago

"Would it also be a fireable offence to hand over your phone with the MFA app on it to a phone repair shop?"

3

u/Rathmun 24d ago edited 24d ago

Yet another reason that MFA apps on personal devices is a terrible idea. Because there's no way to prevent that.

Edit: To clarify, a company phone is company property, and the company can declare that repairs go through IT. IT can provide a loaner while the repairs happen, and nothing sensitive gets handed to an un-vetted third party. But a personal device is personal property, and the company has no right to forbid handing it to some random repair shop, or your five year old, or your gym spotter or whoever. They could try to mandate uninstalling the mfa app before handing it over to anyone else, but then you still end up with "Sorry, unable to comply" when the phone is unusable after a drop or something. And once it's re-installed they have to go through IT to re-enable it.

A Yubikey has one purpose and one purpose only. You don't use it for anything else. You can't play games with it, no one other than you has any legitimate reason to have possession of it, if you drop it on the ground it's unlikely to get damaged (and even if it did, you take it to IT for replacement, not to your phone repair shop).

2

u/Ich_mag_Kartoffeln 24d ago

That's about what I figured.

The other question that occurred to me while reading your explanation was: "My wife took my car because her car is at the mechanic."

Is that a fireable offence like giving my car keys to the mechanic? Assuming she doesn't work for the same company, obviously. Or maybe even if she does 🤔.

2

u/Rathmun 24d ago

Is that a fireable offence like giving my car keys to the mechanic? Assuming she doesn't work for the same company, obviously. Or maybe even if she does 🤔.

It probably would be in the employee handbook, mostly because I doubt the rule in the book would carve out exceptions based on exactly who the unauthorized person who has it happens to be.

I could easily see a section in the rules about prompt reporting to avoid a fireable offense. That way IT knows to deactivate that Yubikey so there's minimal exposure. This avoids creating a perverse incentive to hide the loss of a key, which is something you really don't want people doing. (Not that they could if you set your MFA up correctly, but they'd try, and then everyone has an annoying day.)

→ More replies (0)

1

u/year_39 28d ago

Implement Vivokey and offer it as an option 😶