Hacker News new | ask | show | jobs
by tough 2 hours ago
I would install the app on the shittiest iPhone backup i have (I must have like 10 iPhones by now, i dont sell old ones)

You can also perfectly use 2fa without a phone, unless your shitty company is using some shitty propietary 2fa, and even then, its just a "key" or "qr" they give you, that then you totally control and can use in mostly any 2fa compatible app, like Passwords. app from apple, 1Password, or Authy (RIP)

Installing shitty apps just cause your company tells you to is a great way to get your personal phone hacked too

Sames goes with all the MITM bullshit, If you want to install malware on my 6k macbook, you've gonna have to buy me your own "work macbook" for me to handle that shit. And i wont touch it for anything else than work. But installing spyware from work in my personal computer is a big NO NO.

1 comments

>You can also perfectly use 2fa without a phone, unless your shitty company is using some shitty propietary 2fa, and even then, its just a "key" or "qr" they give you, that then you totally control and can use in mostly any 2fa compatible app, like Passwords. app from apple, 1Password, or Authy (RIP)

Only if they're using RFC 6238 TOTP, and not some weird 2fa app. It's ironic you mention authy because they have their own weird TOTP scheme, along with push notification based approval system.

Authy is also EOL since it was acquired by twilio and tossed into the do not recycle bin it seems...

But yeah, things can get messy depending on the specifics, but not installing random apps on your personal phone seems like a pretty reasonable line to make.

I only mentioned Authy cause it was my go-to for 2fa before they got acquired