5 ms·
Let's note that this very concerning problem is only one if organizations take an allowlist approach to this "context aware authorization" requirement. Detecti
by Signez 5y ago
Let's note that this very concerning problem is only one if organizations take an allowlist approach to this "context aware authorization" requirement.
Detecting changes — and enforcing escalation in that case — can be enough, e.g. "You always uses Safari on macOS to connect to this restricted service, but now you are using Edge on Windows? Weird. Let's send an email to a relevant person / ask for a MFA confirmation or whatever."
- deleted 5y ago[deleted]
- dathinab 5y agoIf something like that is good enough to fulfill the requirements, that would be good. Some services already thinks like that, like I think discord.
- hansvm 5y agoSomebody made the front page here a few days ago because they were locked out of Google with no recourse from precisely that kind of check.
- freedomben 5y agoIt wasn't I, but this has been an absolute plague on an organization I work with. There are only 3 people, and we all have need to access some accounts but they are personal accounts. Also, the boss travels a lot, often to international destinations. Every time he flies I can almost guarantee we'll face some new nightmare. The worst is "we noticed something is a tiny bit different with you but we won't tell you what it is. We've emailed you a code to the email account that you are also locked out of because something is a tiny bit different with you. Also we're putting a flag on your account so it raises holy hell the next 36 times you log in."
- sciurus 5y agoThree people sharing a personal account, with one of them frequently traveling internationally, is such an unusual usage pattern that I'd be really disappointed with a service provider if they _didn't_ flag it for extra verification.
- freedomben 5y agoThe frustrating thing to me is that as a user they don't give us any tools to help ourselves. I would gladly make it a "team" account and login individually if we could. I would gladly do a shared TOTP, or whitelist login locations, or anything like that. Or at least give us the option to accept the risk and disable whatever anomaly detection they are applying. But no, that's not how the software world works anymore. Extreme paternalism mode is the only option as a user.
- throwaway48375 5y agoWhy do you need to all access the same account though? Can't you grant access to whatever resource you need to multiple accounts?
- freedomben 5y agoFor some of them we can, for others no. Sadly it seems as though supporting this sort of thing is not a priority for most SaaS
- blackrobot 5y agoWhy don't you share a TOTP between all of you? Just take a screenshot of the authenticator QR code, or save it to a shared 1password secret. Google's login protection mechanisms seem to be satisfied by TOTP usage, and you won't be locked out anymore (or at least much less likely to be).
- freedomben 5y agoYou're right that would totally work with Google. In our case the boss is quite computer illiterate and trying to get him to use LastPass was hard enough. He will tolerate a lot of pain from getting locked out before he'll be willing to learn TOTP :-( And for many of the SaaS that we use, TOTP doesn't help you avoid the security lock outs.
- pagnol 5y agoHave you considered using the same Proxy or VPN? I work remotely and sometimes access services through a VPN based in the country my coworkers are at specifically to avoid this kind of annoyance.
- freedomben 5y agoThis is a great idea, although the boss is pretty technically challenged so getting him set up on it might be interesting. It's been extremely difficult just to teach him to use LastPass. Much appreciate the suggestion!
- _RafaelKr 5y agoI recently setup a WireGuard VPN and it was surprisingly easy (compared to other VPN solutions) and works very reliable for me.
- pagnol 5y agoThere are also a number of browser extensions which may be easier to set up and use for non-technical folks, for example FoxyProxy seems to offer one. I've never tried any myself, though.
- dpatterbee 5y agoI feel like the issue with the post you mention was the absence of recourse rather than the locking out itself.
- joe-collins 5y agoAbsolutely. The escalation chain is its own attack vector, but it should exist.
- hansvm 5y agoThat definitely exacerbates the issue, but I don't think it's fair to claim that the absence of recourse is the _only_ problem. If you have limited cell service, limited connectivity, or limited time, then the account being locked can be a significant burden that completely blocks whatever opportunity you were trying to take advantage of. Note that the response time even for newsworthy account locking events is still on the order of hours to days.
- tata71 5y agoThis is the difference between "Log in by tapping Yes on my phone" and actually using a FIDO2 USB key.
- pishpash 5y agoWho gets to decide what changes are kosher? Sounds like bureaucratic behavior modeling.
- pas 5y agoThe cheapest vendor that was selected, obviously.