Transcript
A wafrn woot (post) by @tinker@infosec.exchange saying “Microsoft Authenticator needs me to validate with Authenticator in order to log in with Authenticator to use it to authenticate another app with Authenticator. Here is the app telling me to open itself to validate itself with itself. #infosec #iHateComputers” It has a screenshot showing the microsoft authenticator app.
Yeah, I also had a beautiful moment trying to use Google’s find my phone feature in another country when I didn’t know my password. Used “password123” after that near nightmare.
Security works best when it’s really easy to get into my account even though I don’t remember my credentials.
No the best system is if you try to find your phone without having your phone, a cybernetic lifeform should track you down and rip your spine out for trying to find your phone. Then some dipshit on the Internet without a shred of humanity can feel smugly superior about it
Fuck right off, buddy. You confessed to making dumb security choices on the internet and got mocked for it, yeah. This has nothing to do with “oh the humanity!”
You admitted to being a huge asshole so you get a response reflecting that and now you’re crying about it
Someone made you the butt of a joke on the internet. Please get over it and don’t go shoot up your school.
FuCk RiGhT oFf
You’re overreacting a tiny bit, maybe?
Regarding you? I think they’ve been quite restrained.
Yeah, they’re a true hero for throwing insults over a joke. You as well, for being huffy on their behalf.
Bit of a shit take there really, that’s not the same thing at all.
No, it’s not the same thing at all. It’s an analogous thing. Reducing account security because you lost your credential isn’t very smart and that’s the common denominator in both examples.
The commenter above you had lost their phone and was supposed to log in using this same phone.
They only got access to the account again due to chance, i.e. someone else found their phone.
(There likely is some sort of backup mechanism, but apparently it’s sufficiently well hidden.)
Yeah, I read the story, so I’m aware of the plot.
My comment was aimed at removing MFA completely because OP had a problem once. That is a bad idea and I expressed that by making a joke about using a very bad password because I couldn’t remember my actual password which is also a bad idea.
Google (as any other provider) used the phone option for MFA first because that’s what OP had been using multiple times before they lost their phone. OP wasn’t “supposed to log in using the same phone”, Google just offered the default way that had been used before. OP didn’t see the other login options and went on the internet to tell everybody how stupid Google is and proceeded to smugly proclaim they removed MFA entirely due to Google’s stupidity which inadvertantly revealed OP’s less smart decision I made fun of.
The “Try another way” option is literally right below the input field and one of two links displayed at this point (try it out, go to google.com in a private window and enter your password. The other link is “Resend it”.). It’s not hidden at all and OP had more choices than a stranger finding their phone but they never realized it. But again, that’s not my point. My point is that removing MFA because you had trouble logging in without your phone one time is a bad idea which is why I made a joke about that.
Yeah you know everything, asshole. Including when my story occurred and that nothing has changed about the UI since. You also know that panicking that your trip being ruined by a lost phone is no reason to have trouble using a shitty UI which is so densely created that it mirrors the post we are commenting on.
The way you said everything in this thread assures everyone you’re a prick. I’m glad you feel so good about it though
I guess using strong and unique passwords on every account is the mark of a moron but true genius? That’s a company with some of the supposed best engineers in the world who needs you to have your fucking phone to find your fucking phone. What a great system! All hail Google and flawless security practice!
Believe it or not, the best engineers in the world can’t help if you lose your backup codes. You know, the ones that you can use when you need MFA but don’t have your phone? Removing MFA because you had trouble one time “is the mark of a moron but true genius”.
Believe it or not, some people are only better with their security practices than 99.99% of humans instead of 99.999%. pfft, total idiots, right? Now let us pretend we are 100% muahahhahah so smart
I have no idea what you’re trying to tell me, sorry. I do assume it was something totally devastating, though, so consider me totally devastated. You can stop the hostility now, I just made a joke at your expense, it’s not a big deal, honestly.
Also, I highly recommend reactivating MFA on your account. It’s a good thing to have, generally. Yeah, it can suck when it doesn’t work but now you know how hard it is for someone unauthorized to get into your account.
There are multiple other security measures in place on my account thanks.
It does seem like you were a little upset by my joke. Probably because the imagery of a Terminator coming to kill a person over a find my phone request is an actual joke. Not just sarcasm designed to shame someone. Whatever, jerky weirdo.