3 ms·
To defend Redmond here, Entra is an enterprise system. If the company you work for or are interfacing with wants to enforce attestation, that's their business.
by frameset 1y ago
To defend Redmond here, Entra is an enterprise system. If the company you work for or are interfacing with wants to enforce attestation, that's their business.
B2C I would expect more latitude on requiring attestation.
- technion 1y agoI would counter argue being the person pushing passkeys in an enterprise: noone in the business knows what attestation is, but we're going to do it because the interface recommends it.
- jrockway 1y agoI'm not sure it's the standards committee's fault that your employer hires people that don't know how to do their job. I think it's reasonable to have attestation for the corporate use case. If they're buying security devices from a certain vendor, it's reasonable for their server to check that the person pretending to be you at the other end is using one of those devices. It's an extra bit of confidence that you're actually you.
- ori_b 1y agoIt's the standards committees job to design standards that are difficult to misuse.
- raxxorraxor 1y agoThe most common fault of committees is that they overengineer processes and specs wander out of scope. The result is that users (dev & consumers) either neglect the bad parts or the spec doesn't get used at all.
- eadmund 1y agoDon’t put in place systems which encourage lock-in, even at the B2B level.
- lmz 1y agoAren't those usually used inside an enterprise vs B2B between enterprises?
- Zak 1y agoA problem is that once a thing like that exists, it ends up on security audit checklists and then people do it without knowing whether they have any reason to.
- clickety_clack 1y agoExactly. For personal authentication, you are at least personally incentivized to do the right things. For corporate auth, people will do whatever it takes to skip any kind of login. I once knew a guy who refused to let his office computer go to sleep just to avoid having to enter his password to unlock his computer. He was a really senior guy too, so IT bent to allow him do this. What finally made him lock his computer was a colleague sending an email to all staff from his open outlook saying “Hi everyone, it’s my birthday today and I’m disappointed because hardly anyone has come by to wish me happy birthday”. The sheer mortification made him change his ways.
- tonyhart7 1y agolol this is funny, why he didn't want to sign in more often tho???
- clickety_clack 1y agoHe was completely non technical and I guess he figured that IT should be able to work the security system around him.
- adam_hn 1y agoThe most common human trait ever.... laziness
- projektfu 1y agoA culture of harmlessly pranking computers left unlocked goes a long way. ThoughtWorks veterans know what I mean.