15 ms·
Lithuanian university locks out students again for not using proprietary 2FA
- kotatsuyaki 3y agoPrevious discussion at https://news.ycombinator.com/item?id=35643915 https://news.ycombinator.com/item?id=35643915. The student was locked out again on 2023-04-26. Note that the link is a permalink, and if you're reading this in the future you may want to go to the master branch at https://gitlab.digilol.net/Siren/vgtu-article/-/blob/master/vgtu.md https://gitlab.digilol.net/Siren/vgtu-article/-/blob/master/....
- josephcsible 3y agoMaybe the EU should solve this by mandating that all 2FA implementations support TOTP, analogous to how they mandated USB-C for smartphones.
- hbogert 3y agoTOTP is kinda lame once you've used FIDO2/CTAP2. Please skip TOTP as a requirement.
- gondaloof 3y agoIt could happen, they recently forced banks to use 2FA for some operations if I remember correctly.
- ronsor 3y agoI genuinely didn't know there was a 2FA system that didn't support SMS/Email or TOTP.
- davchana 3y agoYandex key does. I have tried to scan the barcode & see the details, but its not standard TOTP. You need to have Yandex Key app installed.
- Aloha 3y agoI have to admire their energy and dedication, even if I perhaps think that energy and dedication would be better spent elsewhere.
- femto 3y agoI had a similar problem when I was required to use Outlook email. It turns out that outlook does support FIDO2 hardware keys (or app) in place of MS authenticator, but it is disabled by default. The Admin has to explicitly enable it. One then has to get though a number of roadblocks including: * The option to log in with a FIDO key does not show up in Firefox, only Chrome (and Edge?). Bugs? * MS only recognises keys from "Partner organisations". If you go an open source key, such as Solo, it probably won't be an MS partner and you will have to get the Admin to add AAGUID numbers for your type of key. * A "Temporary Access Pass" needs to be issued by the Admin for first sign-in, to boot the chain of trust. All in all it's a pain for the Admin compared to saying "Download MS Authenticator", hence it may be difficult to get an Admin to admit that the FIDO option is there.
- Symbiote 3y agoFirefox on Mac and Linux doesn't yet support the Pin-required version of FIDO2. MS365 requires this mode.
- lousken 3y agoThis is incredibly infuriating from Mozilla and very sad to see. Again their browser shows they just cannot stay in the enterprise environment. Such a shame.
- Symbiote 3y agohttps://bugzilla.mozilla.org/show_bug.cgi?id=1530370 https://bugzilla.mozilla.org/show_bug.cgi?id=1530370 This is the issue tracking it, and it looks to be nearing completion.
- TheNewsIsHere 3y agoSome of the things you mention here are organizational implementation, potentially making things more difficult to support. For example, attestation is not enabled by default. An admin enabled that, and didn’t automatically allow-list common AAGUIDs. TAPs can be programmatically generated in batches for a roll out.
- cyberpunk 3y agoTheyre whining about having to use Microsoft Authenticator. I get it, microsoft sucks. But they’re almost certainly using android or iPhones and so already use a bunch of proprietary software. What a stupid hill to die on.
- benatkin 3y agoI think it's a stupid hill for the university to die on.
- clnq 3y agoThe emails mention students only using FOSS. And while they are the minority, their point of view is reasonable. Studying should not involve handing over one’s data to MS or any other big tech corp without good reason.
- cyberpunk 3y agoYeah. I’m sure none of them have any device capable of watching Netflix or have a gmail address..
- clnq 3y agoTo me this looks like it’s about principle of not being denied education if you do not consent to big corp EULAs.
- benatkin 3y agoForeign big corp EULAs.
- totetsu 3y agoWhen I was a student last, I was using an Ubuntu laptop, and an android phone that was no longer receiving updates, so couldn't run any of the new versions of the apps required to do so many things.
- userbinator 3y agoIronic to link to a site that requires running proprietary JS to view static content (and it's not one of those where the content is visible in View Source either.) Even GitHub doesn't do that.
- juunpp 3y agoKeep up the fight. I've tried this with banks, who are keen on forcing Android/iPhone apps on everyone. Should hopefully be easier to get a public entity to provide non-proprietary 2fa implementations.
- gondaloof 3y agoTo be fair, it’s easier and more convenient to just tell the user to download their own app than having to set up any other 2FA service. Authentication has been a solved problem for decades but no bank is going to ask the general public to use their SSH keys.
- userbinator 3y agoThe question is whether something standard like TOTP is also offered as an option (regardless of how "dark-patterny" it is to get to the option --- I've seen services that will heavily push their own app, but if you look carefully you'll see TOTP too, often disguised as "Google Authenticator" or something else that doesn't explicitly say TOTP but actually is.) Authentication has been a solved problem for decades but no bank is going to ask the general public to use their SSH keys. Nor ask them to put their smartcard in the reader, although many banks will already have given one to their customers...
- Symbiote 3y agoBritish banks issued EMV card readers and used them for authentication from around 2005 to 2010, 2015-ish. It looks like some still provide this to customers who can't use other methods.
- NoZebra120vClip 3y agoYour bank allows apps? Luxury!
- kensai 3y agoI know it will be an unpopular answer, but given there are two options (namely: Microsoft Authenticator or using the SMS option) what is the problem? If the SMS option is such an attack to your privacy, use a cheapo phone with a prepaid SIM registered to your dog. Not all countries permit this, but it's a start.
- deleted 3y ago[deleted]
- shjake 3y ago> registered to your dog. Not all countries permit this In Lithuania you don’t even need to register anything. You can just buy a bag full of sim cards in any supermarket completely anonymously.
- jcrawfordor 3y agoIt's kind of hard to follow the moral stance here. The university is apparently a Microsoft 365 customer. The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? It's hard to understand how 2FA is the thing that crosses the line, when the university has already entrusted Microsoft with everything else. And as they say in the letter, MS Authenticator (which is not even really a 2FA system but a passwordless authentication product, likely the best on the market right now) is not even mandatory as SMS is also an option. Setting downsides of SMS 2FA aside, they are not actually being required to use proprietary software, but instead seem to have bundled two mostly unrelated concerns together. I mean, they're objecting to having to share their phone number with MS... In order to access their email that MS hosts. The privacy boundary they're making this stand over is just a very strange one. TOTP isn't really a drop in replacement either, as MS Authenticator is intended to protect against a couple of classes of attacks that TOTP doesn't, most importantly 2FA interactive phishing, which TOTP remains vulnerable to. Following the Okta attacks a number of organizations have prohibited TOTP, as interactive phishing of TOTP tokens is becoming pretty common such that TOTP 2FA is no longer substantial protection against this extremely common attack vector. FIDO is another good option but frankly the usability of FIDO remains very poor and it produces a much higher volume of support issues than app-based interactive verification.
- coffeeling 3y agoTOTP phishing? Like, MITMing TOTP requests or something?
- nsajko 3y ago> The objection of the students here seems to be that... They are being required to use a Microsoft product in order to access a Microsoft product? The objection is that they're being required to compromise their security, either by installing Microsoft's spyware or enabling SMS 2FA.
- Brian_K_White 3y agoSecurity of what though? MS email and onedrive. I don't get it either, unless the critique isn't actually limited to the 2fa app.
- tintedfireglass 3y agoMy Indian university does this and I'm powerless. Emailing then or convincing them didn't help. Atleast Europeans care about privacy. Everyone looked at me like I was retarded when I tried to explain the issue to them.
- deleted 3y ago[deleted]
- patrakov 3y agoYou are powerless because there is no law that makes you right. Maybe find someone who can change that?
- tintedfireglass 3y agoI've tried but there's not enough momentum on this issue. Nobody cares. Can't find anyone who cares about the issue AND has the power/ability to cause change. There's no law too against this AFAIK. so there's no way forward that I can see.
- runnerup 3y agoMost likely you are correct. I suspect most citizens of India put “right to privacy” far, far below many other issues. So many are still affected daily by clean water and electricity shortages, lack of economic opportunities, and inconsistent (corrupt) governance. Europe is afforded the luxury to spend energy on issues like this that are well higher on Maslow’s hierarchy. However, due to prevailing issues between religions and castes in India, perhaps some would be interested in a blanket “right-to-privacy” in order to better hide their affiliations. This doesn’t seem to be the direction they’re heading but it’s a small fulcrum for change perhaps.
- KronisLV 3y ago> To use TOTP we need to reconfigure more than one system because they work differently or 2FA was not thought of when they were designed. This thought is repeated in the correspondence, does anyone have any idea what they actually mean by that? After all, if they're using Azure Active Directory, then surely the type of 2FA shouldn't matter that much to most of the software that's integrated with it, right? Why wouldn't the suggestions presented in the e-mails work? Go to Security > Multifactor Authentication > Additional cloud-based multifactor authentication settings. Tick the checkboxes like in the attached image. Presumably along the lines of: https://learn.microsoft.com/en-us/azure/active-directory-b2c/multi-factor-authentication?pivots=b2c-user-flow#verification-methods https://learn.microsoft.com/en-us/azure/active-directory-b2c... Other than that, it feels like repeated back and forth, with either a lack of mutual understanding of what's actually being used sometimes, or the repeated statement above, which is unfortunate to see. Props to the person for standing their ground due to what they believe in, but I feel that many would (unfortunately?) just get a cheap Android device for something like this, if their daily driver was something else.
- counttheforks 3y agoThe school should be providing phones if the students require them. I strongly believe 2fa is important, but it is even more important to acknowledge that not everyone owns the gadgets that you do. And they may not want to. So if a service requires 2fa they should also supply the necessary hardware to all of their users.
- KronisLV 3y ago> The school should be providing phones if the students require them. I agree in principle, but doubt that our reality matches up with that. It's easier for them to blame the minority of people, especially if nobody will stand up for them. In their own words: >> If your phone doesn’t support Microsoft Authenticator, you need to use “Call to phone”, if you don’t want that method to use, you need to change your phone, which support Microsoft. They can just say: "Most people use phones with a mainstream OS, don't be a weirdo and just use a phone like that, like the rest of the people." Same unfortunate situation across the board, with plenty of software being Windows/Mac-only, drivers not being open source and for the most part almost nobody caring. What's worse, in this case it seems like TOTP should be able to be supported, with relatively few issues, unless there is indeed something major I'm missing.