• nelson@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 days ago

    Agree for personal use.

    Professionally I’ve had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app. :(

    I even used freeotp+ for my ORG 2FA and aegis for my personal so I could easily keep them split ( and you can export / securely store the backups somewhere ).

    Time to get corps to ditch Microsoft >.>

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      3 days ago

      Professionally I’ve had situations where Ms authenticator was the only option because the only 2FA they allow is push notifications on the authenticator app.

      If a company requires me to install specific apps that may or may not work on my device, I expect that company to provide me with a device that can be set up for their stuff. Or an alternative, like a hardware RSA token.

      I’ve run two separate phones for nearly 15 years now: my personal phone, and a work-issued phone. The work phone is turned off and left on my night stand as soon as I get home, and only turned on again when I’m getting ready to go back to work. I don’t carry it 24/7 as some have been led to believe, for some reason. It’s really nice to have that separation. And work pays for it.

    • besbin@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 days ago

      We do need to get corps to move away from closed source protocols like MS, Google, Meta and others push notifications though. Those are not in anyway safer and are just basically trap to force people to use their apps