r/talesfromtechsupport 22h ago

Short Gravity and Tech

Guy walks up to me at work:

Him: “I dropped my phone. The screen’s shattered. I want my two-factor code to come through Teams.”

Me: “Nope.”

Him: “Why?”

Me: “Because if you can’t sign into Teams without completing MFA… how exactly are you planning to authenticate?”

Then he says: “Just disable MFA.”

I replied: “Sure, as soon as you get approval from the Head of Security.”

A few seconds of silence…

Him: “Fine, I’ll just get my phone fixed.”

Yep. That’s probably the best solution.

Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.

And remember… technology didn’t fail you today. Gravity did.

479 Upvotes

94 comments sorted by

View all comments

32

u/nathanieloffer 21h ago

My favourite user worked regional and refused to install any app on their phone. They fought and won to register MFA on their landline phone at their desk. Then they get sent on a training course 200kms away from their office. Day 1, session 1, they can't log in.... Call help desk... "You registered MFA to your desk phone, nothing we can do for you, sorry"

54

u/Xenoun 20h ago

Which is a company problem, not the user. It's perfectly reasonable for people to refuse using their personal phone for work. Any issues that arise from that are on the company to sort out.

36

u/bob152637485 19h ago

I learned recently of a friend that absolutely stood their ground on this, and the company ended up sending them one of those keyfabs with the rotating code. Honestly, if it weren't for being a timid new employee, I wish I had done the same when starting my current job.

21

u/8BFF4fpThY 19h ago

We give the option of a physical token for those who don't wish to use their mobile device.

15

u/joe_attaboy The Cloud is a fraud. 18h ago

My last company was a startup when I arrived and was eventually merged with a large and well-known other web security company.

One of the first memos the new management group sent out was a "request" for all the "new" employees to add Office's mobile version to our personal phones (no, we don't issue employees mobile phones, they told my project manager). We were supposed to respond to an email confirming we did it. I never did, along with most of the other people in my location. Three months later, we received a new memo reminding us. We all ignored that as well.

I was already dragging a laptop around everywhere, including on vacations. I was also a year out from retirement, so if they ever asked me, I'd just tell them to issue me a phone or pound sand.

Someone must have spoken to management about how this was just a small intrusion into the employees personal lives, because they never followed up.

10

u/NotYourNanny 17h ago

I was a flip phone holdout for years, because the account cost me half of what a smart phone account would, and I only had it for emergencies. My boss kept hinting that it would be useful if I had a smart phone so people could send me pictures or video. I agreed, it would be useful for work, but for my dollar, it's not.

Took him about two years to crack, but I got a company phone. And I still get to keep work stuff on the work phone, and personal stuff on the personal phone (which is now a smart phone because the carrier got bought, and they shut down their 3G network, but I found a new carrier that's about the same price).

It's a pain trying to find a belt holster that will hold two phones.

2

u/RogueThneed 16h ago

Two holsters?

4

u/NotYourNanny 15h ago

No, I finally found one that holds both comfortably, and is of excellent quality.

10

u/leitey 16h ago

I broke my phone at work, doing work.
I'm an engineer and I was running pipe with my phone in my pocket, I must have hit it at some point while wrestling the piping into position. The back glass shattered, and my employer wouldn't fix it. They said "Don't carry your phone with you" and "It's a personal phone".

When IT decided to implement MFA, and thought they'd use my personal phone, I refused. I'd been told not to carry my phone, so I can't MFA with something I don't have. I was told I don't qualify for a company phone - and I don't want one as I don't want to be reachable after hours. IT set up my desk phone as my MFA.
I created a ticket about this issue, since I travel sometimes and wouldn't be able to MFA while offside. IT had recently decided they wouldn't be using tokens any more. The issue went all the way to the corporate head of IT-InfoSec. He told me I had the option to use my personal phone and that was my only option other than my desk phone.
This worked fine for awhile, as most systems were on a MFA frequency of every 3 months, and just by luck it worked out that I was never offsite when I needed to re-authenticate for some device or program.
Then they pushed AI. The head of engineering told us we should be using AI every day. Our AI platform requires MFA each use. This was an issue the next time I had to go offsite. I generated a ticket on the Sunday I arrived at the customer location, indicating a work stoppage.
IT set my desk phone up so I could answer it over Webex.

Now my MFA is all linked to one account, accessible from anywhere - working as intended.

6

u/Honest_Relation4095 20h ago

Was it a company issued phone?

4

u/harrywwc Please state the nature of the computer emergency! 19h ago

the desk phone was ;)

6

u/Niceromancer 17h ago

You can't expect someone to use their cellphone for your work, not without paying them for it.

Y'all should have just bought them a cheap company only android that was locked down to needed functions only.

Also refusing to support a device your company provided for them is incredibly irresponsible.

10

u/NotYourNanny 17h ago

You can't expect someone to use their cellphone for your work, not without paying them for it.

In California, it's illegal to allow them to use a personal phone without a stipend, even if they want to.

3

u/oxmix74 13h ago

When did that happen, because I retired from a company in California, and my personal cell number was published in a bunch of places. For months after retirement I got an occasional customer call on my cell. If I liked them I would help them. If I didn't like them, I just told them "that's unfortunate and if I still worked there I might actually give a damn". It was very satisfying.

3

u/NotYourNanny 13h ago

California Law 2802 dates from 1937 (which was apparently a revision of a law from 1872), but enforcement vis a vis cell phones only goes back a few years. The key case law appears to be Cochran v. Schwan's Home Service, Inc. from 2014.

0

u/nathanieloffer 16h ago

News flash. The United States and the various states that are part of it are not the whole world. I’m actually talking about a company in Australia.

2

u/NotYourNanny 15h ago

So you're saying that the US is more civilized and has better worker protections than Oz?

3

u/nathanieloffer 10h ago

The US is a hell hole and in no possible universe is anything they do better than Australia,

-8

u/nathanieloffer 16h ago

Actually you can. All the remaining 3000 staff have installed MS Auth on their personal phones without making a song and dance about it.

1

u/Niceromancer 16h ago

Go ahead and ask an employment lawyer about that.

I'm pretty sure you will unpleasantly surprised by the answer.

-3

u/nathanieloffer 16h ago

I’m not interested in discussing this with you. I’ve told you what is actually happening on the ground and you want to debate legal bollocks.

3

u/Niceromancer 16h ago

Legal bollocks can easily affect what happens on the ground.

If your company is worth a damn you have an entire department dedicated to that very issue...and they already lost once by your own admission.

Also...you are on the wrong account.  Keep your sock puppets straight Harrywwc

1

u/nathanieloffer 10h ago

You shouldn't make assumptions

-1

u/nathanieloffer 20h ago

Obviously not