Hacker News new | ask | show | jobs
by Raed667 2110 days ago
My work requires a smartphone for multi-factor authentication and to unlock the office door (if we ever go back to the office)
2 comments

It makes me so mad that companies require phones for MFA. I get distracted by my phone easily and when I tried switching to a yubikey, they told me that my business case for switching wasn't good enough. So frustrating
For multi-factor, could you use an Android emulator running on your PC?

Obviously, that does not work for the doorlock.

This will depend on the solution - a common Enterprise solution, RSA SecureID SoftToken, includes the ability to IMEI lock the app on the user (I am not sure if this is required or optional, I'm an end-user not RSA admin) to ensure it only runs on company provisioned mobiles (many companies use further solutions such as MobileIron on all provisioned devices for fleet management).
Running it on the same machine would defeat much of the purpose.

A better idea is to just turn it on for 2FA, then turn it off again.

That was my point. Using a mobile phone as a second factor seems more like an inconvenience.

Other sibling mentioned IMEI pinning, but I assume the emulator can spoof IMEI.

I am all for a separate physical device, just not a phone.

A phone is just a computer, just like any other device. What do you have specifically against it? You can just keep it turned off except when you need to use it for 2FA.