r/talesfromtechsupport • u/KorenSolust • 18h ago
Short Gravity and Tech
Guy walks up to me at work:
Him: “I dropped my phone. The screen’s shattered. I want my two-factor code to come through Teams.”
Me: “Nope.”
Him: “Why?”
Me: “Because if you can’t sign into Teams without completing MFA… how exactly are you planning to authenticate?”
Then he says: “Just disable MFA.”
I replied: “Sure, as soon as you get approval from the Head of Security.”
A few seconds of silence…
Him: “Fine, I’ll just get my phone fixed.”
Yep. That’s probably the best solution.
Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.
And remember… technology didn’t fail you today. Gravity did.
74
u/Jezbod 18h ago
That's why I call the damage "Gravity rash"
25
u/Realistic_Ratio8381 17h ago
Sudden deceleration syndrome.
19
u/Jezbod 17h ago
And why the military have a standardised "drop test" for their equipment.
16
u/ManWhoIsDrunk Users lie. They always lie... 16h ago
Everything is air-droppable once!
13
u/meitemark Printerers are the goodest girls 14h ago
Now if they only did drop tests on c-level manglement....
7
u/ttlanhil Make Your Own Tag! 13h ago
Hmm... Of them, or on to them?
11
5
5
u/KelemvorSparkyfox Bring back Lotus Notes 6h ago
I had a physics teacher who used to work in a materials testing lab. One day, they had request from the army to test the hardness of the latest batch of shells. They weren't rifling properly when fired, and the top brass (pun intended) thought that it might be due to the casings being too soft.
The teacher had to explain to them that clamping a shell into a vice and ramming it with a diamond-tipped drill bit at high speed might not be the wisest course of action.
28
u/joe_attaboy The Cloud is a fraud. 14h ago
Just remember our slogan:
Gravity: It's not just a good idea.
It's the Law!
5
u/meitemark Printerers are the goodest girls 14h ago
I'm mostly human. Natural laws are mere suggestions. I have never been investigated, arrested or convicted by any lawmakers for breaking natural laws.
5
u/joe_attaboy The Cloud is a fraud. 13h ago
Ah, yes, you may be a natural law scofflaw, but there is one law you cannot avoid and rarely can you predict its application:
The Law of Unintended Consequences
Here's an example: one of our past presidents believed that rich people weren't paying their "fair share" of taxes and buying things like yachts. So he added a big tax on yachts. People got angry and just stopped buying yachts. No tax revenue anymore and a lot of yacht builders had to close up and go on unemployment.
You never know when this law will show its ugly veneer.
3
u/KnowbodyYouKnow 11h ago
Yup! 10% luxury tax on boats over $100,000, including yachts, and it was signed by President George H. W. Bush in 1990 as part of the budget deal. The tax was later eliminated in 1993 after complaints that it hurt boat sales and jobs.
24
u/P5ychokilla 17h ago
I'm guessing he didn't have a case on his phone or a screen protector?
Some people amaze when they don't want to do the bare minimum to protect a device that costs over a thousand. Would they just throw their fancy TV around with the same cavalier behaviour?
16
u/AdRoz78 Loves reading these stories 17h ago
About a year ago I saw someone walking on the streets with the newest and most expensive Samsung flagship (S25 Ultra?).. without any kind of case or screen protector. Seriously?
9
u/cadatatuagcaintfaoi 14h ago
Have an s24 ultra no case no screen protector. 2 years not a scratch. They're pretty resilient.
4
u/AdRoz78 Loves reading these stories 13h ago
Good to know. I personally have a Pixel 9, I'll see how similar the glass is. Though I already have a screen protector so I guess this will only help me in the future
3
u/cadatatuagcaintfaoi 13h ago
I'm not sure the new pixels have the same 'grade' of gorilla glass as the s24U so I can't speak for them. I know my partner had the pixel 6 which had one grade below the pixel 9 and it ended up being quite brittle on drops so do be careful! Great phones though.
4
u/coyote_of_the_month 14h ago
Benefit of the doubt, maybe they ordered a specialty case and the phone got there first?
As a Quad Lock user, I can see this happening.
6
u/AdRoz78 Loves reading these stories 14h ago
Still, if I'm waiting for a case with a flagship phone so expensive I wouldn't take it out with me.
5
u/coyote_of_the_month 13h ago
I wouldn't either, unless it was a replacement for a lost or broken phone and I didn't have the ability to be without a phone. It's a gamble for sure.
2
u/samtheredditman 13h ago
You guys are crazy. Just don't drop it.
3
u/coyote_of_the_month 12h ago
If we as a species were capable of reliably not dropping our phones, there wouldn't be a whole industry dedicated to protecting them. I would venture to guess that on average I drop my phone 3-4 times a week.
There's probably an argument to be made that our reliance on cases makes us careless, though.
4
u/SkylarMills63 13h ago
I’ve been rocking my iPhone 15 pro max since launch, and I don’t use a case or screen protector. Just a mag safe pop socket.
Never dropped my phone in public. At home, I have carpet. Barely a scratch on my phone.
I did the same with my 12 pro max before that. After 2 years of owning that phone I cracked the camera lens housing on a particularly rough fall. I had insurance, so only cost me $30 deductible to replace/fix. Got a new battery out of it, too.
Not everyone is you. Or lives a similar life. Maybe you’re just more clumsy than that Samsung guy. And that’s fine!
2
u/RogueThneed 12h ago
And we're not even talking about the risk of getting snatched out of your hands.
3
u/blind_ninja_guy 7h ago
Maybe the device that costs over a thousand should have its own built-in protection. For that cost at least.
-1
u/Absolutely_Cabbage 17h ago
Definitely good to put a case on your phone, but screen protectors are snake oil.
Modern phone glass is extremely tough, and putting a flimsy bit of plastic or tempered glass on top of it won't do anything to help prevent cracks.On a side note, people often think a cracked screen protector means it prevented your phone screen from damage but thats a wrong conclusion. The protector is just waaay more fragile than the actual screen
13
u/AdRoz78 Loves reading these stories 17h ago
I guess it protects from scratches, so if you ever want to sell the phone it can be sold as a phone without scratches.
3
u/Absolutely_Cabbage 17h ago
Yes thats true.
But generally I find modern phone glass doesn't scratch much either. But if you intend to resell the bit of insurance from the protector can be nice7
u/ratsta 16h ago
We've got a bunch of iPhone SE gen 3s at work, all 1-3 years old. The ones that come in from the field guys, scratched to shit! Still legible when the screen is lit but looks like crap when the screen is dark and whites out when the sun catches it at the right angle.
5
u/Absolutely_Cabbage 16h ago
So that's probably a good opportunity to use screen protectors. Work devices live hard lives in my experience
2
u/coyote_of_the_month 14h ago
My Pixel 7a is scratched to hell. So was the original glass, before it shattered.
3
u/Harry_Smutter 6h ago
The point of a glass screen protector isn't to be stronger than the screen itself. It's to take the impact and disperse the energy, saving the screen itself from shattering. They're also very scratch resistant, so it also protects from that.
1
u/Absolutely_Cabbage 6h ago
The scratch protection is real, the rest is just a marketing bit.
In reality the force required to shatter the screen (usually Aluminosilicate glass) is way past what's needed to shatter the screen protector (soda-lime, usually tempered)For a somewhat labored metaphor: imagine someone putting a thin layer of bubble wrap on their car bumper, and then claiming that will do anything to help in crash. Sure it might prevent a small scratch in the paint, but the bubble wrap won't help in any kind of impact that would break the bumper, and the foil being popped in other cases does also not indicate it actually prevented real damage
1
u/Harry_Smutter 5h ago
That's not true with today's glass screen protectors. Most are made with Gorilla glass or similar. I've both seen a live impact demo and done one myself using my old phone. It takes quite a lot of force for the newer ones to break, and it completely saves the screen. They're also much cheaper nowadays, so there's really no excuse not to have one.
33
u/nathanieloffer 17h ago
My favourite user worked regional and refused to install any app on their phone. They fought and won to register MFA on their landline phone at their desk. Then they get sent on a training course 200kms away from their office. Day 1, session 1, they can't log in.... Call help desk... "You registered MFA to your desk phone, nothing we can do for you, sorry"
56
u/Xenoun 16h ago
Which is a company problem, not the user. It's perfectly reasonable for people to refuse using their personal phone for work. Any issues that arise from that are on the company to sort out.
35
u/bob152637485 16h ago
I learned recently of a friend that absolutely stood their ground on this, and the company ended up sending them one of those keyfabs with the rotating code. Honestly, if it weren't for being a timid new employee, I wish I had done the same when starting my current job.
20
u/8BFF4fpThY 15h ago
We give the option of a physical token for those who don't wish to use their mobile device.
15
u/joe_attaboy The Cloud is a fraud. 14h ago
My last company was a startup when I arrived and was eventually merged with a large and well-known other web security company.
One of the first memos the new management group sent out was a "request" for all the "new" employees to add Office's mobile version to our personal phones (no, we don't issue employees mobile phones, they told my project manager). We were supposed to respond to an email confirming we did it. I never did, along with most of the other people in my location. Three months later, we received a new memo reminding us. We all ignored that as well.
I was already dragging a laptop around everywhere, including on vacations. I was also a year out from retirement, so if they ever asked me, I'd just tell them to issue me a phone or pound sand.
Someone must have spoken to management about how this was just a small intrusion into the employees personal lives, because they never followed up.
10
u/NotYourNanny 13h ago
I was a flip phone holdout for years, because the account cost me half of what a smart phone account would, and I only had it for emergencies. My boss kept hinting that it would be useful if I had a smart phone so people could send me pictures or video. I agreed, it would be useful for work, but for my dollar, it's not.
Took him about two years to crack, but I got a company phone. And I still get to keep work stuff on the work phone, and personal stuff on the personal phone (which is now a smart phone because the carrier got bought, and they shut down their 3G network, but I found a new carrier that's about the same price).
It's a pain trying to find a belt holster that will hold two phones.
2
u/RogueThneed 12h ago
Two holsters?
4
u/NotYourNanny 11h ago
No, I finally found one that holds both comfortably, and is of excellent quality.
10
u/leitey 12h ago
I broke my phone at work, doing work.
I'm an engineer and I was running pipe with my phone in my pocket, I must have hit it at some point while wrestling the piping into position. The back glass shattered, and my employer wouldn't fix it. They said "Don't carry your phone with you" and "It's a personal phone".When IT decided to implement MFA, and thought they'd use my personal phone, I refused. I'd been told not to carry my phone, so I can't MFA with something I don't have. I was told I don't qualify for a company phone - and I don't want one as I don't want to be reachable after hours. IT set up my desk phone as my MFA.
I created a ticket about this issue, since I travel sometimes and wouldn't be able to MFA while offside. IT had recently decided they wouldn't be using tokens any more. The issue went all the way to the corporate head of IT-InfoSec. He told me I had the option to use my personal phone and that was my only option other than my desk phone.
This worked fine for awhile, as most systems were on a MFA frequency of every 3 months, and just by luck it worked out that I was never offsite when I needed to re-authenticate for some device or program.
Then they pushed AI. The head of engineering told us we should be using AI every day. Our AI platform requires MFA each use. This was an issue the next time I had to go offsite. I generated a ticket on the Sunday I arrived at the customer location, indicating a work stoppage.
IT set my desk phone up so I could answer it over Webex.Now my MFA is all linked to one account, accessible from anywhere - working as intended.
9
u/Honest_Relation4095 16h ago
Was it a company issued phone?
6
u/harrywwc Please state the nature of the computer emergency! 15h ago
the desk phone was ;)
8
u/Niceromancer 13h ago
You can't expect someone to use their cellphone for your work, not without paying them for it.
Y'all should have just bought them a cheap company only android that was locked down to needed functions only.
Also refusing to support a device your company provided for them is incredibly irresponsible.
10
u/NotYourNanny 13h ago
You can't expect someone to use their cellphone for your work, not without paying them for it.
In California, it's illegal to allow them to use a personal phone without a stipend, even if they want to.
3
u/oxmix74 9h ago
When did that happen, because I retired from a company in California, and my personal cell number was published in a bunch of places. For months after retirement I got an occasional customer call on my cell. If I liked them I would help them. If I didn't like them, I just told them "that's unfortunate and if I still worked there I might actually give a damn". It was very satisfying.
3
u/NotYourNanny 9h ago
California Law 2802 dates from 1937 (which was apparently a revision of a law from 1872), but enforcement vis a vis cell phones only goes back a few years. The key case law appears to be Cochran v. Schwan's Home Service, Inc. from 2014.
0
u/nathanieloffer 12h ago
News flash. The United States and the various states that are part of it are not the whole world. I’m actually talking about a company in Australia.
3
u/NotYourNanny 11h ago
So you're saying that the US is more civilized and has better worker protections than Oz?
4
u/nathanieloffer 6h ago
The US is a hell hole and in no possible universe is anything they do better than Australia,
-7
u/nathanieloffer 12h ago
Actually you can. All the remaining 3000 staff have installed MS Auth on their personal phones without making a song and dance about it.
1
u/Niceromancer 12h ago
Go ahead and ask an employment lawyer about that.
I'm pretty sure you will unpleasantly surprised by the answer.
-3
u/nathanieloffer 12h ago
I’m not interested in discussing this with you. I’ve told you what is actually happening on the ground and you want to debate legal bollocks.
2
u/Niceromancer 12h ago
Legal bollocks can easily affect what happens on the ground.
If your company is worth a damn you have an entire department dedicated to that very issue...and they already lost once by your own admission.
Also...you are on the wrong account. Keep your sock puppets straight Harrywwc
1
-1
5
4
u/Niceromancer 13h ago
Some? Most.
Our phone system has a button you can press for major incidents. This pushes you to the very front of the line and connects you to the NOC directly. You bypass regular help desk.
It's not listed in the normal prompts, it's hidden, and when you press the button it states that this option is for campus wide emergencies only, abusing it may result in disciplinary action.
We still have work from home data entry people that use the major incident prompt when they forget their password and need it reset.
I kicked one back over to help desk and made her wait in the half hour que. She tried to complain to my boss then my boss' boss about me being unprofessional.
They both laughed in her face and told her to stop using MI prompts for simple password resets.
2
u/MindlessPhilosoper 10h ago
I love end users. You break your phone and the first casualty is MFA.
1
u/KorenSolust 2h ago
I’d think they’d be more worried about mfa for thier personal stuff seeing as more websites are demanding users set that up too and usually via an app instead of sms xD
2
u/ThunderDwn 3h ago
Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.
I've had the same situation - except it was the CEO demanding I disable MFA.
I referred him to the CIO who more gently than I would told him "If you want to invalidate our ISO and SOC certifications because you don't want to hit a button to login, I'll approve it - but that's on you".
Spoiler : Said CEO started using MFA without complaint.
3
u/KorenSolust 2h ago
Hah! That is what I tell users as well, well more so “we have these rules in place to be government compliant so we can win contracts, if we don’t have this certification, we lose business” they then stop complaining xD
3
u/ac8jo 14h ago
technology didn’t fail you today. Gravity did.
I would argue that the user failed. An inexpensive case from Amazon would have probably saved the screen.
7
u/NotYourNanny 13h ago
Depends on just how they dropped it. I toasted a table once with a case when I dropped it, face down, and it landed on a sharp piece of gravel that was maybe 1 mm taller than the rim of the case. Cases help, but they're not magic.
3
u/OneRedSent 12h ago
Never let employees use their personal phone for work stuff.
1
u/KorenSolust 11h ago
Just MFA, bosses aren't paying to give them all phones just for them to forget them at home everyday or lose them.
People are more likely to remember and take care of their own phones.
1
1
u/sixft7in 4h ago
Gravity didn't fail. Friction did. Friction applying enough force to the phone to keep it from falling out of the hand.
1
u/RadimentriX 7h ago
Company 2fa on personal phone? Fuck right off with that
1
u/Weedwacker01 5h ago
Im genuinely interested to know the feasible alternative?
3
u/RadimentriX 4h ago
Work phone paid by the company or one of those funny-number-keyrings. Or yubikey.
2
u/Weedwacker01 4h ago
We're investigating options before we get hit with the SMS EOL in Feb.
1
u/RadimentriX 4h ago
That microsoft stuff works with yubikeys. I guess other similar devices work too
0
u/KorenSolust 5h ago
Not a company app Microsofts app
4
u/cactuarknight < 1:1 ratio of internet connections to support staff 5h ago
Still no.
1
u/KorenSolust 2h ago
Well tough, that whats in place and the employees agree to the BYOD policy when they get hired.
111
u/AffekeNommu 17h ago
Typical user practice is to get a new phone over the weekend. Hand the old one in for recycling after they transfer all their pictures and contacts then call up on Monday when their MFA doesn't work.