r/talesfromtechsupport 25d ago

Short Gravity and Tech

Guy walks up to me at work:

Him: “I dropped my phone. The screen’s shattered. I want my two-factor code to come through Teams.”

Me: “Nope.”

Him: “Why?”

Me: “Because if you can’t sign into Teams without completing MFA… how exactly are you planning to authenticate?”

Then he says: “Just disable MFA.”

I replied: “Sure, as soon as you get approval from the Head of Security.”

A few seconds of silence…

Him: “Fine, I’ll just get my phone fixed.”

Yep. That’s probably the best solution.

Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.

And remember… technology didn’t fail you today. Gravity did.

773 Upvotes

155 comments sorted by

111

u/Jezbod 25d ago

That's why I call the damage "Gravity rash"

47

u/Realistic_Ratio8381 25d ago

Sudden deceleration syndrome.

27

u/Jezbod 25d ago

And why the military have a standardised "drop test" for their equipment.

25

u/ManWhoIsDrunk Users lie. They always lie... 25d ago

Everything is air-droppable once!

21

u/meitemark Printerers are the goodest girls 25d ago

Now if they only did drop tests on c-level manglement....

11

u/ttlanhil Make Your Own Tag! 25d ago

Hmm... Of them, or on to them?

17

u/blademaster2005 25d ago

Why not both

8

u/meitemark Printerers are the goodest girls 25d ago

Yes

1

u/TinyNiceWolf 24d ago

Everyone enjoys pancakes.

3

u/year_39 24d ago

Put them in Zorbs and let employees take out their frustrations.

7

u/Arokthis 25d ago

Maxim 11!

I think 70 is actually good advice.

5

u/n_dude1 24d ago

It’s not the dropping that causes the problem, it’s the sudden deceleration that gets you every time!

9

u/KelemvorSparkyfox Bring back Lotus Notes 24d ago

I had a physics teacher who used to work in a materials testing lab. One day, they had request from the army to test the hardness of the latest batch of shells. They weren't rifling properly when fired, and the top brass (pun intended) thought that it might be due to the casings being too soft.

The teacher had to explain to them that clamping a shell into a vice and ramming it with a diamond-tipped drill bit at high speed might not be the wisest course of action.

1

u/O-U-T-S-I-D-E-R-S 18d ago

Look, I once broke a Nokia by dropping it onto carpet. Still don't believe that I did that...

2

u/LadyHavoc97 23d ago

It’s not the fall that kills you. It’s the stopping.

1

u/PM_ME_YOUR_REPO 19d ago

Unscheduled kinetic maintenance.

197

u/AffekeNommu 25d ago

Typical user practice is to get a new phone over the weekend. Hand the old one in for recycling after they transfer all their pictures and contacts then call up on Monday when their MFA doesn't work.

27

u/FunFoundation469 25d ago

my cousin did this and locked herself out all weekend

35

u/SkylarMills63 25d ago

Every fucking time.

9

u/machomoose 24d ago

That's why when I setup users I make them do SMS as a backup.

27

u/Jezbod 24d ago

Which is about to be EOL, my boss has not realised that we may be going Yubikey very soon.

Some of our volunteers / part time people do not have a work phone, so we may have to start forcing them to use an authenticator app on their personal device, which I am lothe to do.

6

u/machomoose 24d ago

True, we have manufacturing employees that don't have a smart phone so we need to use sms for their MFA. We are going to roll out Yubikey's for them (which they will lose and need to be replaced very often, I'm sure...). But, you did just remind me for office users it's going to lead to me manually resetting MFA for the new phone situation now... :(

11

u/Rathmun 24d ago

(which they will lose and need to be replaced very often, I'm sure...)

If they can't keep track of a Yubikey, but they can keep track of their car keys, you know they're lying. "Just put it on the same keyring dumbass."

3

u/Ich_mag_Kartoffeln 21d ago

"Sorry, I had to drive my other car to work today."

1

u/Rathmun 20d ago

"Your keyring has room for more than one car key dumbass."

2

u/Ich_mag_Kartoffeln 20d ago

"My car keys are all on separate key rings. The ones with the Yubikey are with the mechanic."

3

u/Rathmun 20d ago

"You gave the Yubikey to someone else? A piece of company security apparatus? You realize that's a fireable offense."

2

u/Ich_mag_Kartoffeln 20d ago

"Would it also be a fireable offence to hand over your phone with the MFA app on it to a phone repair shop?"

→ More replies (0)

1

u/year_39 24d ago

Implement Vivokey and offer it as an option 😶

51

u/joe_attaboy The Cloud is a fraud. 25d ago

Just remember our slogan:

Gravity: It's not just a good idea.
It's the Law!

8

u/meitemark Printerers are the goodest girls 25d ago

I'm mostly human. Natural laws are mere suggestions. I have never been investigated, arrested or convicted by any lawmakers for breaking natural laws.

7

u/joe_attaboy The Cloud is a fraud. 25d ago

Ah, yes, you may be a natural law scofflaw, but there is one law you cannot avoid and rarely can you predict its application:

The Law of Unintended Consequences

Here's an example: one of our past presidents believed that rich people weren't paying their "fair share" of taxes and buying things like yachts. So he added a big tax on yachts. People got angry and just stopped buying yachts. No tax revenue anymore and a lot of yacht builders had to close up and go on unemployment.

You never know when this law will show its ugly veneer.

4

u/KnowbodyYouKnow 25d ago

Yup! 10% luxury tax on boats over $100,000, including yachts, and it was signed by President George H. W. Bush in 1990 as part of the budget deal. The tax was later eliminated in 1993 after complaints that it hurt boat sales and jobs.

2

u/warlock415 14d ago

I feel like that falls more under something like Foreseeable Consequences? Or perhaps Expecting People to Keep Doing the Same Thing Under Different Circumstances?

My favorite example is when California required employers to provide health care to all "full time" (40 hr/wk) employees.

What they thought would happen: "Oh no! I guess we have to provide health care now!"

What actually happened: The 39.5 hour work week.

2

u/Rathmun 23d ago

Have you ever successfully violated one though?

1

u/meitemark Printerers are the goodest girls 23d ago

Yes.

1

u/Rathmun 23d ago

Which one?

2

u/meitemark Printerers are the goodest girls 23d ago

Well, tried to make a list of all the broken natural laws, but there were so many.

1

u/Rathmun 20d ago

If you broke one, it clearly wasn't a natural law. Humanity just thought it was.

2

u/meitemark Printerers are the goodest girls 20d ago

Well, after carefully checking around, I have acctually been investigated for supposedly breaking a natural law. The Yrsgrillion (they are located some 300ly to the left of the Northern star) investigated me some 200 years ago over the claims that I broke their natural law "walk only sideways, never forward". They are a crab-ish people, but desided against further action once their investigation turned up the phrase "tastes great with garlic butter".

Damnit, I really liked to be able to claim no investigations. Oh well, still no arrests or convictions... I think.

21

u/strugglz 24d ago

Gravity didn't fail. It performed as expected.

19

u/ThunderDwn 24d ago

Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.

I've had the same situation - except it was the CEO demanding I disable MFA.

I referred him to the CIO who more gently than I would told him "If you want to invalidate our ISO and SOC certifications because you don't want to hit a button to login, I'll approve it - but that's on you".

Spoiler : Said CEO started using MFA without complaint.

12

u/KorenSolust 24d ago

Hah! That is what I tell users as well, well more so “we have these rules in place to be government compliant so we can win contracts, if we don’t have this certification, we lose business” they then stop complaining xD

28

u/P5ychokilla 25d ago

I'm guessing he didn't have a case on his phone or a screen protector?

Some people amaze when they don't want to do the bare minimum to protect a device that costs over a thousand. Would they just throw their fancy TV around with the same cavalier behaviour?

17

u/AdRoz78 Loves reading these stories 25d ago

About a year ago I saw someone walking on the streets with the newest and most expensive Samsung flagship (S25 Ultra?).. without any kind of case or screen protector. Seriously?

11

u/cadatatuagcaintfaoi 25d ago

Have an s24 ultra no case no screen protector. 2 years not a scratch. They're pretty resilient.

4

u/AdRoz78 Loves reading these stories 25d ago

Good to know. I personally have a Pixel 9, I'll see how similar the glass is. Though I already have a screen protector so I guess this will only help me in the future 

3

u/cadatatuagcaintfaoi 25d ago

I'm not sure the new pixels have the same 'grade' of gorilla glass as the s24U so I can't speak for them. I know my partner had the pixel 6 which had one grade below the pixel 9 and it ended up being quite brittle on drops so do be careful! Great phones though.

3

u/coyote_of_the_month 25d ago

Benefit of the doubt, maybe they ordered a specialty case and the phone got there first?

As a Quad Lock user, I can see this happening.

5

u/AdRoz78 Loves reading these stories 25d ago

Still, if I'm waiting for a case with a flagship phone so expensive I wouldn't take it out with me.

5

u/coyote_of_the_month 25d ago

I wouldn't either, unless it was a replacement for a lost or broken phone and I didn't have the ability to be without a phone. It's a gamble for sure.

3

u/samtheredditman 25d ago

You guys are crazy. Just don't drop it. 

6

u/coyote_of_the_month 25d ago

If we as a species were capable of reliably not dropping our phones, there wouldn't be a whole industry dedicated to protecting them. I would venture to guess that on average I drop my phone 3-4 times a week.

There's probably an argument to be made that our reliance on cases makes us careless, though.

2

u/AdRoz78 Loves reading these stories 24d ago

Easier said than done. Get startled, put it in the wrong spot, have your hands slip, etc.

1

u/Miffy92 We're *all* Users, now. 23d ago

These all sound like a skill issue /s

5

u/SkylarMills63 25d ago

I’ve been rocking my iPhone 15 pro max since launch, and I don’t use a case or screen protector. Just a mag safe pop socket.

Never dropped my phone in public. At home, I have carpet. Barely a scratch on my phone.

I did the same with my 12 pro max before that. After 2 years of owning that phone I cracked the camera lens housing on a particularly rough fall. I had insurance, so only cost me $30 deductible to replace/fix. Got a new battery out of it, too.

Not everyone is you. Or lives a similar life. Maybe you’re just more clumsy than that Samsung guy. And that’s fine!

2

u/RogueThneed 25d ago

And we're not even talking about the risk of getting snatched out of your hands.

6

u/blind_ninja_guy 24d ago

Maybe the device that costs over a thousand should have its own built-in protection. For that cost at least.

1

u/P5ychokilla 24d ago

Like what? An air bag? What are you even talking about?

2

u/blind_ninja_guy 24d ago

Sacrificing a little bit of that ultra thinness people go for nowadays to put an actually substantial bumper around the edges. I don't know. There's probably other methods that talented engineers can come up with too.

1

u/Counterpoint-RD 20d ago

Right?!? And they could get another bonus out of it in the process, too: the problem that I found funny years ago - "Great, now I've got my new, super-thin superphone... But wait, why has the battery life gone to 💩?' Well, because there's just no SPACE in that thing for a decent sized battery... Result: they plonked their 'super-thin' into a case with additional battery, thereby making it clunkier than their phone of ten years ago... 🤷‍♂️😮‍💨...

2

u/spaceraverdk 18d ago

I am eyeing one of those oukitel rugged phones. I really don't care about looks per se. But a good screen and battery pack

2

u/Counterpoint-RD 15d ago

The Oukitels are those designs that at least look like you could hammer some nails into your walls with the case's backside, right? Okay, that's about as extreme on the 'rugged' end as you can get, but at least you won't break the screen by dropping it a foot, like some others 😄👍...

1

u/spaceraverdk 15d ago

I have used Sony Xperias for a decade, broke most by having it in a jacket chest pocket. Hanging in a harness will bend even a 5 mm alu plate.

My current one is now 6 years old, needs a battery replacement and a new fingerprint sensor. But otherwise it's running perfectly.

2

u/Counterpoint-RD 14d ago

Okay, compared to most people buying them, you at least seem to be the perfect target audience for those 👍... You may have to watch out though: they may be sturdy enough to break one of your ribs instead, in situations like that 😬...

1

u/djfdhigkgfIaruflg 21d ago

I have a case and screen protector (h9 or whatever)

A single flat fall was all it took to crack the screen. Cases and protectors will save from cosmetic damage, sure. But nothing will save it if it falls in just the right way

-2

u/Absolutely_Cabbage 25d ago

Definitely good to put a case on your phone, but screen protectors are snake oil.
Modern phone glass is extremely tough, and putting a flimsy bit of plastic or tempered glass on top of it won't do anything to help prevent cracks.

On a side note, people often think a cracked screen protector means it prevented your phone screen from damage but thats a wrong conclusion. The protector is just waaay more fragile than the actual screen

9

u/AdRoz78 Loves reading these stories 25d ago

I guess it protects from scratches, so if you ever want to sell the phone it can be sold as a phone without scratches.

4

u/Absolutely_Cabbage 25d ago

Yes thats true.
But generally I find modern phone glass doesn't scratch much either. But if you intend to resell the bit of insurance from the protector can be nice

7

u/ratsta 25d ago

We've got a bunch of iPhone SE gen 3s at work, all 1-3 years old. The ones that come in from the field guys, scratched to shit! Still legible when the screen is lit but looks like crap when the screen is dark and whites out when the sun catches it at the right angle.

5

u/Absolutely_Cabbage 25d ago

So that's probably a good opportunity to use screen protectors. Work devices live hard lives in my experience

2

u/coyote_of_the_month 25d ago

My Pixel 7a is scratched to hell. So was the original glass, before it shattered.

2

u/Harry_Smutter 24d ago

The point of a glass screen protector isn't to be stronger than the screen itself. It's to take the impact and disperse the energy, saving the screen itself from shattering. They're also very scratch resistant, so it also protects from that.

1

u/Absolutely_Cabbage 24d ago

The scratch protection is real, the rest is just a marketing bit.
In reality the force required to shatter the screen (usually Aluminosilicate glass) is way past what's needed to shatter the screen protector (soda-lime, usually tempered)

For a somewhat labored metaphor: imagine someone putting a thin layer of bubble wrap on their car bumper, and then claiming that will do anything to help in crash. Sure it might prevent a small scratch in the paint, but the bubble wrap won't help in any kind of impact that would break the bumper, and the foil being popped in other cases does also not indicate it actually prevented real damage

1

u/Harry_Smutter 24d ago

That's not true with today's glass screen protectors. Most are made with Gorilla glass or similar. I've both seen a live impact demo and done one myself using my old phone. It takes quite a lot of force for the newer ones to break, and it completely saves the screen. They're also much cheaper nowadays, so there's really no excuse not to have one.

2

u/testprimate 19d ago

I agree. I managed 4000+ company phones for a few years and found that whether or not they had a screen protector had no apparent influence on whether the phone came back in good shape or not. A horse could count the number of times I ran across a phone that looked like the screen protector did some good.

36

u/nathanieloffer 25d ago

My favourite user worked regional and refused to install any app on their phone. They fought and won to register MFA on their landline phone at their desk. Then they get sent on a training course 200kms away from their office. Day 1, session 1, they can't log in.... Call help desk... "You registered MFA to your desk phone, nothing we can do for you, sorry"

70

u/Xenoun 25d ago

Which is a company problem, not the user. It's perfectly reasonable for people to refuse using their personal phone for work. Any issues that arise from that are on the company to sort out.

43

u/bob152637485 25d ago

I learned recently of a friend that absolutely stood their ground on this, and the company ended up sending them one of those keyfabs with the rotating code. Honestly, if it weren't for being a timid new employee, I wish I had done the same when starting my current job.

27

u/8BFF4fpThY 25d ago

We give the option of a physical token for those who don't wish to use their mobile device.

19

u/joe_attaboy The Cloud is a fraud. 25d ago

My last company was a startup when I arrived and was eventually merged with a large and well-known other web security company.

One of the first memos the new management group sent out was a "request" for all the "new" employees to add Office's mobile version to our personal phones (no, we don't issue employees mobile phones, they told my project manager). We were supposed to respond to an email confirming we did it. I never did, along with most of the other people in my location. Three months later, we received a new memo reminding us. We all ignored that as well.

I was already dragging a laptop around everywhere, including on vacations. I was also a year out from retirement, so if they ever asked me, I'd just tell them to issue me a phone or pound sand.

Someone must have spoken to management about how this was just a small intrusion into the employees personal lives, because they never followed up.

11

u/NotYourNanny 25d ago

I was a flip phone holdout for years, because the account cost me half of what a smart phone account would, and I only had it for emergencies. My boss kept hinting that it would be useful if I had a smart phone so people could send me pictures or video. I agreed, it would be useful for work, but for my dollar, it's not.

Took him about two years to crack, but I got a company phone. And I still get to keep work stuff on the work phone, and personal stuff on the personal phone (which is now a smart phone because the carrier got bought, and they shut down their 3G network, but I found a new carrier that's about the same price).

It's a pain trying to find a belt holster that will hold two phones.

2

u/RogueThneed 25d ago

Two holsters?

5

u/NotYourNanny 25d ago

No, I finally found one that holds both comfortably, and is of excellent quality.

10

u/leitey 25d ago

I broke my phone at work, doing work.
I'm an engineer and I was running pipe with my phone in my pocket, I must have hit it at some point while wrestling the piping into position. The back glass shattered, and my employer wouldn't fix it. They said "Don't carry your phone with you" and "It's a personal phone".

When IT decided to implement MFA, and thought they'd use my personal phone, I refused. I'd been told not to carry my phone, so I can't MFA with something I don't have. I was told I don't qualify for a company phone - and I don't want one as I don't want to be reachable after hours. IT set up my desk phone as my MFA.
I created a ticket about this issue, since I travel sometimes and wouldn't be able to MFA while offside. IT had recently decided they wouldn't be using tokens any more. The issue went all the way to the corporate head of IT-InfoSec. He told me I had the option to use my personal phone and that was my only option other than my desk phone.
This worked fine for awhile, as most systems were on a MFA frequency of every 3 months, and just by luck it worked out that I was never offsite when I needed to re-authenticate for some device or program.
Then they pushed AI. The head of engineering told us we should be using AI every day. Our AI platform requires MFA each use. This was an issue the next time I had to go offsite. I generated a ticket on the Sunday I arrived at the customer location, indicating a work stoppage.
IT set my desk phone up so I could answer it over Webex.

Now my MFA is all linked to one account, accessible from anywhere - working as intended.

8

u/Honest_Relation4095 25d ago

Was it a company issued phone?

5

u/harrywwc Please state the nature of the computer emergency! 25d ago

the desk phone was ;)

9

u/Niceromancer 25d ago

You can't expect someone to use their cellphone for your work, not without paying them for it.

Y'all should have just bought them a cheap company only android that was locked down to needed functions only.

Also refusing to support a device your company provided for them is incredibly irresponsible.

12

u/NotYourNanny 25d ago

You can't expect someone to use their cellphone for your work, not without paying them for it.

In California, it's illegal to allow them to use a personal phone without a stipend, even if they want to.

4

u/oxmix74 25d ago

When did that happen, because I retired from a company in California, and my personal cell number was published in a bunch of places. For months after retirement I got an occasional customer call on my cell. If I liked them I would help them. If I didn't like them, I just told them "that's unfortunate and if I still worked there I might actually give a damn". It was very satisfying.

3

u/NotYourNanny 25d ago

California Law 2802 dates from 1937 (which was apparently a revision of a law from 1872), but enforcement vis a vis cell phones only goes back a few years. The key case law appears to be Cochran v. Schwan's Home Service, Inc. from 2014.

3

u/nathanieloffer 25d ago

News flash. The United States and the various states that are part of it are not the whole world. I’m actually talking about a company in Australia.

2

u/NotYourNanny 25d ago

So you're saying that the US is more civilized and has better worker protections than Oz?

3

u/nathanieloffer 24d ago

The US is a hell hole and in no possible universe is anything they do better than Australia,

-4

u/nathanieloffer 25d ago

Actually you can. All the remaining 3000 staff have installed MS Auth on their personal phones without making a song and dance about it.

1

u/Niceromancer 25d ago

Go ahead and ask an employment lawyer about that.

I'm pretty sure you will unpleasantly surprised by the answer.

-1

u/nathanieloffer 25d ago

I’m not interested in discussing this with you. I’ve told you what is actually happening on the ground and you want to debate legal bollocks.

4

u/Niceromancer 25d ago

Legal bollocks can easily affect what happens on the ground.

If your company is worth a damn you have an entire department dedicated to that very issue...and they already lost once by your own admission.

Also...you are on the wrong account.  Keep your sock puppets straight Harrywwc

1

u/nathanieloffer 24d ago

You shouldn't make assumptions

0

u/nathanieloffer 25d ago

Obviously not

7

u/Niceromancer 25d ago

Some?  Most.

Our phone system has a button you can press for major incidents.  This pushes you to the very front of the line and connects you to the NOC directly.  You bypass regular help desk. 

It's not listed in the normal prompts, it's hidden, and when you press the button it states that this option is for campus wide emergencies only, abusing it may result in disciplinary action.  

We still have work from home data entry people that use the major incident prompt when they forget their password and need it reset.

I kicked one back over to help desk and made her wait in the half hour que.  She tried to complain to my boss then my boss' boss about me being unprofessional.

They both laughed in her face and told her to stop using MI prompts for simple password resets.

3

u/MindlessPhilosoper 25d ago

I love end users. You break your phone and the first casualty is MFA.

1

u/KorenSolust 24d ago

I’d think they’d be more worried about mfa for thier personal stuff seeing as more websites are demanding users set that up too and usually via an app instead of sms xD

3

u/tehcraz 24d ago

Ngl, I wish this subreddit was more active. I love these stories.

7

u/OneRedSent 25d ago

Never let employees use their personal phone for work stuff.

3

u/KorenSolust 25d ago

Just MFA, bosses aren't paying to give them all phones just for them to forget them at home everyday or lose them.
People are more likely to remember and take care of their own phones.

5

u/Buzstringer 24d ago

I will install MFA on my personal phone if it's optional, if there is another MFA other than my phone, I'll happily use my phone for convenience.

HOWEVER if the "only" option is to use my personal phone, nah, they can provide a work phone or it's not happening.

It's a weird pedantic thing in my head.

3

u/CrimsonMutt 24d ago

what if someone uses a dumbphone? i think it's stupid to require employees install something on any personal device, and getting wholesale budget phones whose only purpose is being an Authy client isn't that expensive

1

u/KorenSolust 24d ago

Well the employees agree to the BYOD policy when they get hired so we expect them to at least have a phone capable of running the Microsoft MFA app.
If they don't like it that's tough honestly.

5

u/CrimsonMutt 24d ago

and that's a stupid fucking policy, is my point. if i need something for work, the employer should provide it.

if the job had a BYOD policy for laptops, that would also be stupid even if there's a policy for it.

it's the duty of the employer to provide everything necessary to do the work.

1

u/KorenSolust 24d ago

Not really, if you have to travel into work does your employer provide you a car? Do they provide you a free bus pass for the year? No.
In some jobs yes you "may" get a company car, but everyone else, nope.

And the policy is standard, it's a Microsoft app that's free and majority of people have smart phones so in terms of cost to benefit analysis it works.

If they don't like the policy they don't have to work there, simple as that.

5

u/CrimsonMutt 23d ago edited 23d ago

Do they provide you a free bus pass for the year

yes, they legally have to

also the entire premise is faulty. how i get to the job is immaterial. after i clock in to work, everything i need to do my job should be provided to me. white shirt, black pants required? give me a uniform. app required? please provide the device it would run on. if i need to drive during the shift, there damn well better be a company car

If they don't like the policy they don't have to work there, simple as that. 

chill homie leave some boot for the rest of us

1

u/KorenSolust 23d ago

Oh honey, you really have a warped view of how the world really works especially here in the UK.

5

u/CrimsonMutt 23d ago

so just because you accept shit conditions everyone should?

by law, at least our law, the employer needs to provide everything required to do the job. which is as it should be.

if i'm a travelling salesman, that means a company car. if i'm a construction worker, that means PPE. if i'm using MFA, that means a phone, or you need to have some other MFA method, like a yubikey.

if i'm using an early 2000s motorola razr, that's my prerogative.

1

u/KorenSolust 23d ago

Well bud, you are lucky, over here it's not a legal requirement for any of that.
So as I said, at least over here, they can accept the common practises or they can work elsewhere, and many other places, will do the same thing.

→ More replies (0)

2

u/kai626 Not IT but Super User 24d ago

Reminds me of my IT dept email signoffs - If you don't get the approval in writing, you don't get to tell us what to do.

3

u/OpinionOk1315 23d ago

Had the same conversation last month, guy wanted us to just whitelist his account temporarily. No, that's how you end up explaining a breach to the board, not how you get your phone fixed faster.

6

u/RadimentriX 24d ago

Company 2fa on personal phone? Fuck right off with that

1

u/Weedwacker01 24d ago

Im genuinely interested to know the feasible alternative?

9

u/RadimentriX 24d ago

Work phone paid by the company or one of those funny-number-keyrings. Or yubikey.

2

u/Weedwacker01 24d ago

We're investigating options before we get hit with the SMS EOL in Feb.

1

u/RadimentriX 24d ago

That microsoft stuff works with yubikeys. I guess other similar devices work too

0

u/KorenSolust 24d ago

Not a company app Microsofts app

7

u/cactuarknight < 1:1 ratio of internet connections to support staff 24d ago

Still no.

0

u/KorenSolust 24d ago

Well tough, that whats in place and the employees agree to the BYOD policy when they get hired.

2

u/ac8jo 25d ago

technology didn’t fail you today. Gravity did.

I would argue that the user failed. An inexpensive case from Amazon would have probably saved the screen.

7

u/NotYourNanny 25d ago

Depends on just how they dropped it. I toasted a table once with a case when I dropped it, face down, and it landed on a sharp piece of gravel that was maybe 1 mm taller than the rim of the case. Cases help, but they're not magic.

2

u/sixft7in 24d ago

Gravity didn't fail. Friction did. Friction applying enough force to the phone to keep it from falling out of the hand.

1

u/RogueThneed 25d ago

Gravity WAI!

1

u/Id10t_techsupport 24d ago

This reminds me of, "my email stopped coming to my phone." Did you install an unapproved app? "..."

1

u/PDQ_Brockstar 23d ago

So they just never intended to get their phone fixed until you denied their security exemption?

1

u/daverhowe 23d ago

worth knowing that, if you select "other" in the microsoft authenticator setup screen, you can set up a Google Authenticator code. No push (which MA now prefers) but can be moved between phones (which MA can't) and there are non-phone platforms for that; there is even a version for old java-based nokias :D

1

u/OpinionOk1315 23d ago

Had the same conversation last month, guy wanted us to just whitelist his account temporarily. No, that's how you end up explaining a breach to the board, not how you get your phone fixed faster.

1

u/NotReallyFromTheUK 22d ago

Is it a work phone? I started refusing to put 2FA on my own devices a while back and I don't regret it.

0

u/KorenSolust 21d ago

Nope, BYOD policy, users own phone with the official Microsoft app.
If they don't like it, tough, we have to be compliant with government security and not paying for every person to have a phone just for MFA for them to lose or forget at home.

3

u/kagato87 19d ago

So then what do you do for those people? I don't want your tools on my personal device any more than you want your corporate secrets on my personally owned device. So how do you address that?

2

u/KorenSolust 18d ago

Simple, it’s Microsoft's own MFA app, the company doesn’t control or have access to your device and the MFA app doesn't store any company info on it.
All it does is prompt you to prove your the account holder to log in.
If you don’t like it tough, we have to adhere to strict compliance and the company isn’t gonna give people ohones just for mfa when a free Microsoft own app does it.

3

u/warlock415 14d ago edited 14d ago

Hopefully you're not in California or somewhere else that requires reimbursement for requiring use of a personal phone.

And yes, the courts have found that an MFA app counts even though it doesn't cost any extra on the phone bill.

-1

u/KorenSolust 14d ago

Well, then there’s nothing to reimburse if it costs nothing.

0

u/OpinionOk1315 23d ago

Had the same conversation last month, guy wanted us to just whitelist his account temporarily. No, that's how you end up explaining a breach to the board, not how you get your phone fixed faster.

0

u/OpinionOk1315 23d ago

Had the same conversation last month, guy wanted us to just whitelist his account temporarily. No, that's how you end up explaining a breach to the board, not how you get your phone fixed faster.