Comment on Daily discussion thread: đŚ Monday, May 13, 2024
Gibsonisafluffybutt@aussie.zone â¨5⊠â¨months⊠agoInteresting! Iâve been hearing that two factor isnât enough anymore is that true?
This job, itâs linked to the courts, so everything is still on prem. Although, maybe if I get this job I can start an initiative to move to the cloud.
TinyBreak@aussie.zone â¨5⊠â¨months⊠ago
Correct, mfa ainât enough. Especially in sensitive settings like the courts. Government gets twitchy about data going out of the country. You might even find dealing with the courts the mandate IS on prem.
But Iâve had clients/customers/whatever click on links and have their auth token stolen from the browser, allowed an attacker to come in totally bypassing mfa. Iâve also had customers have their phone number ported away to steal the sms auth. Shit is scary.
Gibsonisafluffybutt@aussie.zone â¨5⊠â¨months⊠ago
Pretty sure the court is mandated to be on prem if I recall from the interview. Browser stuff can be mitigated to a degree, but how the fuck do you stop number porting and Sim cloning?
TinyBreak@aussie.zone â¨5⊠â¨months⊠ago
So MS are dropping SMS auth totally. MFA requires an app, or it will. Its a VERY slow rollout.