Transcript

A wafrn woot (post) by @tinker@infosec.exchange saying “Microsoft Authenticator needs me to validate with Authenticator in order to log in with Authenticator to use it to authenticate another app with Authenticator. Here is the app telling me to open itself to validate itself with itself. #infosec #iHateComputers” It has a screenshot showing the microsoft authenticator app.

  • TrickDacy@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    8 months ago

    Yeah I had a beautiful moment trying to use Google’s find my phone feature in another country when it asked me to use MFA on…my fucking phone. Turned off Google MFA forever after that near nightmare. Luckily another kind tourist found and turned in my phone to the nearest worker at the place I was visiting

    • hdnsmbt@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 months ago

      Yeah, I also had a beautiful moment trying to use Google’s find my phone feature in another country when I didn’t know my password. Used “password123” after that near nightmare.

      Security works best when it’s really easy to get into my account even though I don’t remember my credentials.

      • TrickDacy@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        8 months ago

        No the best system is if you try to find your phone without having your phone, a cybernetic lifeform should track you down and rip your spine out for trying to find your phone. Then some dipshit on the Internet without a shred of humanity can feel smugly superior about it

        • hdnsmbt@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          8 months ago

          some dipshit on the Internet without a shred of humanity

          Fuck right off, buddy. You confessed to making dumb security choices on the internet and got mocked for it, yeah. This has nothing to do with “oh the humanity!”

      • TrickDacy@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        8 months ago

        I guess using strong and unique passwords on every account is the mark of a moron but true genius? That’s a company with some of the supposed best engineers in the world who needs you to have your fucking phone to find your fucking phone. What a great system! All hail Google and flawless security practice!

        • hdnsmbt@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          8 months ago

          Believe it or not, the best engineers in the world can’t help if you lose your backup codes. You know, the ones that you can use when you need MFA but don’t have your phone? Removing MFA because you had trouble one time “is the mark of a moron but true genius”.

          • TrickDacy@lemmy.world
            link
            fedilink
            arrow-up
            0
            ·
            8 months ago

            Believe it or not, some people are only better with their security practices than 99.99% of humans instead of 99.999%. pfft, total idiots, right? Now let us pretend we are 100% muahahhahah so smart

            • hdnsmbt@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              8 months ago

              I have no idea what you’re trying to tell me, sorry. I do assume it was something totally devastating, though, so consider me totally devastated. You can stop the hostility now, I just made a joke at your expense, it’s not a big deal, honestly.

              Also, I highly recommend reactivating MFA on your account. It’s a good thing to have, generally. Yeah, it can suck when it doesn’t work but now you know how hard it is for someone unauthorized to get into your account.

              • TrickDacy@lemmy.world
                link
                fedilink
                arrow-up
                0
                ·
                8 months ago

                There are multiple other security measures in place on my account thanks.

                It does seem like you were a little upset by my joke. Probably because the imagery of a Terminator coming to kill a person over a find my phone request is an actual joke. Not just sarcasm designed to shame someone. Whatever, jerky weirdo.

                • hdnsmbt@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  8 months ago

                  RIght, you just happened to forget about those when you really needed them. But yeah, I apologize for giving you advice. That was obviously wrong of me.

                  Also, yes, incredibly bothered by your joke that definitely wasn’t sarcasm designed to shame me at all since you apparently meant that “imagery of a Terminator” literally. OK. I get it. You take jokes really well. Can we be done now?

    • Trainguyrom@reddthat.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      7 months ago

      This is where you’re supposed to run the find my phone from another device where you’re already signed in, such as your laptop at the hotel room. Or alternatively have one of your partner’s accounts as a backup 2FA method since your partner probably didn’t lose their phone at the same time.

      If anyone can sign into the account and lock the phone as lost with just a username and password then the moment your username and password are breached/guessed your entire account is as good as gone

      • TrickDacy@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        7 months ago

        A lot of people here are treating me like I’m stupid when my only point really is that Google knows the one way I cannot recover my phone was with the phone itself so it’s not a smart design to offer that. Carrying more devices isn’t a real option either, so I get that technically it’s possible, but smarter people than I should’ve come up with something better by now. No one can carry or afford a backup phone.