3 ms·
What a fun term "MFA fatigue". One day I counted the number of times I needed to authenticate in order connect to my client's web server. The count was 8. 1 U
by DrBoring 5y ago
What a fun term "MFA fatigue".
One day I counted the number of times I needed to authenticate in order connect to my client's web server. The count was 8.
1 Unlock my PC
2 Login to client corp VPN
3 Unlock my phone
4 Enter PIN to MFA app to confirm login to VPN
5 Login to client corps' credentials generation app.
6 Unlock my phone again (screen lock has timed out by now)
7 Enter PIN to MFA app to confirm login to credentials generation app.
8 Login to client's server.
It reminds me of the "8 different bosses" scene from the film Office Space.
- nwallin 5y agoYup. We're at the point where people optimize their passwords for how easy they are to type in. One of my coworkers' passwords is a number and a capital letter followed by asdfghjkl;' (the Enter key at the end of the home row is then the keyboard press) Every 60 days when the password update thing nags him he changes the initial letter or number. He just zips his finger across the keyboard to type in the whole home row; once early in the pandemic during an online meeting the characteristic sound of his finger zipping across the keyboard came in over the mic and someone said, "What the heck was that?" and someone else replied, "Oh that was just John entering his password". Whatever this is it ain't security.
- Beltalowda 5y agoI once worked as a consultant for $BigEnterprise. They had a big sales department, and some their staff had these laptops they brought with them to their customers. To actually use them they had to enter a Disk encryption password, Windows login password, VPN password. All in all there were 3 or 4 passwords. They all had to be different. They all had to cycle every 60 or 90 days. They all very strict "security settings". Every single one of those laptops I saw had a little post-it note on it with all the passwords. The password cycles especially are just hard to deal with.
- Frost1x 5y agoI started to list out the amount of MFA and frequency I do regularly and it exhausted me just writing it out. Suffice it to say I'm forced through all sorts of MFA with various passwords, PINs, Yubi keys, phone authenticators, and even an RSA token daily combined with other hidden information like varied usernames or paths to things. I probably do hundreds of auth steps in a day. In addition we have all sorts of paranoid levels of security with network filters and local security software you have to frequently disable to accomplish tasks, using MFA of course, opening temporary windows that have to be opened later. I'm at a point now where being insecure isn't even insecure because if my info is compromised an attacker wouldn't even know where to find or how to do anything. If they did they'd probably give up. I only deal with it because I get paid well to deal with it.