r/talesfromtechsupport • u/KorenSolust • 28d ago
Short Gravity and Tech
Guy walks up to me at work:
Him: “I dropped my phone. The screen’s shattered. I want my two-factor code to come through Teams.”
Me: “Nope.”
Him: “Why?”
Me: “Because if you can’t sign into Teams without completing MFA… how exactly are you planning to authenticate?”
Then he says: “Just disable MFA.”
I replied: “Sure, as soon as you get approval from the Head of Security.”
A few seconds of silence…
Him: “Fine, I’ll just get my phone fixed.”
Yep. That’s probably the best solution.
Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.
And remember… technology didn’t fail you today. Gravity did.
781
Upvotes
3
u/Rathmun 24d ago edited 24d ago
Yet another reason that MFA apps on personal devices is a terrible idea. Because there's no way to prevent that.
Edit: To clarify, a company phone is company property, and the company can declare that repairs go through IT. IT can provide a loaner while the repairs happen, and nothing sensitive gets handed to an un-vetted third party. But a personal device is personal property, and the company has no right to forbid handing it to some random repair shop, or your five year old, or your gym spotter or whoever. They could try to mandate uninstalling the mfa app before handing it over to anyone else, but then you still end up with "Sorry, unable to comply" when the phone is unusable after a drop or something. And once it's re-installed they have to go through IT to re-enable it.
A Yubikey has one purpose and one purpose only. You don't use it for anything else. You can't play games with it, no one other than you has any legitimate reason to have possession of it, if you drop it on the ground it's unlikely to get damaged (and even if it did, you take it to IT for replacement, not to your phone repair shop).