I like when you want to make a Microsoft account, it asks you to enter your exisiting e-mail first (you can enter one ending with
@outlook.com
or@hotmail.com
though, it will create new mail account). It’s like they don’t believe in their own products, lol.Get a yubi key then you have to find your keys
Our password manager requires logging in and using the authenticator every time the session times out, so we all started using a browser plug-in to keep the session alive all day.
Seconding the ask on the extension, I hate having to log into my secret store every 15 minutes while working on stuff
Session alive
Same issue. What’s the extension called?
I use session alive
Oh did you change your phone? Suffer bitch!!!
/s
As someone on the other side, in IT support, you can fix this yourself and I wish more people would.
Before your old phone gets wiped and sent to the graveyard, log in using authenticator, and go to “view account” from any of the online pages for Microsoft (if you’re unsure, try login.microsoft.com ). Go to your security options, and you should see all the info you need to remove the old authenticator and add a new one.
From here you can also add backups, which I encourage everyone to do.
It saves you from having to call IT all the time to fix it, and since you don’t have to go through the usual back and forth of verifying who you are, or whatever, and getting them to do a thing, you can take care of it for yourself, by yourself, without those unnecessary delays.
Your IT people will appreciate it, and you’ll have to talk to them a bit less as a result.
You should try Okta instead! It’s… blue.
Da ba dee da ba da
My company… runs both, for some reason.
Okay so I get this is a meme BUT I started using a yubikey instead of the auth app and it has done a world of good for my sanity.
I too have a yubikey. My advice, have something that functions as a backup.
Other than that, yes. It’s way better than alternatives.
I transitioned everything to Bitwarden. Password manager, passkeys, and MFA code generation all in one app that works on all of my devices.
And then I started to self-host it via Vaultwarden and transferred all the data.
A friendly FYI: having your passwords and MFA in one place partially defeats the purpose
Sure. But if your bitwarden is protected by a 50char password AND a yubikey, it’s not that big of a tradeoff imo. That’s what I do, but I have hundreds of MFA tokens and it was PAINFUL to auth a lot of the time when I was using an authenticator app.
True, but the alternatives generally are either a pain in the ass or require yet another syncing service to have sensitive info just so I can access things reliably anywhere.
It is still more secure than SMS and email based options.
Besides, my vaultwarden still needs an MFA code to access in the first place, and that’s handled by a separate generator.
I get that not everyone wants to set up something like Aegis in combination with e.g. Syncthing.
Of course it is still better than SMS and email, but I would recommend you check out Ente Auth and/or Proton Auth.
Both are end to end encrypted and you would at least have it in separate apps
I’m willing to accept the slight security difference in exchange for the convenience of having access on a single app 99.9% of the time.
To get into my Vaultwarden in the first place to get my info they’d first have to know my self-hosted server exists to target. And they’d need to compromise that MFA which is handled by a separate unrelated app.
That’s more than enough security for nearly everyone on the planet.
Perfectly valid, everyone has their own threat model and their own standards.
Bitwarden is just so awesome
Depends on your org. I have a yubikey, a phone app Authenticator, a pin and my regular SSO login/password. All of which I have to use constantly, because some dumbass did something dumb like two fucking years ago. So I can hardly get shit done. Plus the same dumbasses who probably fucked all this up are writing production code for an actual product. Please kill me.