I deal with relatively higher volumes of information that must remain secure.
With google, I have hardware authentication device and 10 codes.
Every 30 days or so it asks me to plug in the hardware device. Randomly it asks me more often - I have no idea why but no objection. My password is secure as well and only used on google but THANKFULLY I do not need to change it all the time and so I don't have to write it down. This feels like a reasonably secure approach.
No SMS text option. The idea that your phone number is the key that allows you to reset all your passwords (no matter how complicated / securing no matter how much sensitive info) is ridiculous.
Agreed. My Twitter account was recently hacked thanks to T-Mobile's incompetence. [0]
[0]: https://medium.com/@simon/mobile-twitter-hacked-please-help-...
They stole your SIM. SMS option was now in their control.
SMS is not a secure 2FA option. sure its better than not having 2FA but only a little better.
I'm becoming convinced this is a pervasive fallacy (perhaps not for all users in all cases, but for many). Having SMS as your 2FA potentially makes your phone, phone line, and everything linked to it an attack target. So you might lose a heck of a lot more than you would if they were all unlinked. It depends kind of on what your current security practices are, but I think for many it can well be indirectly risking more damage than it's preventing.
Most hackers never have physical access to people. The intersection between the 2 sets - hackers and pickpockets - approaches zero.
That they may have friends who they accidentally do this for?
That they may not detect the fake ID some random person with your name and number shows them?
Etc etc. None of this requires getting your phone.
Only if the provider doesn't decide to be "helpful" and start allowing password resets via SMS on your 2FA number.
"Two is one and one is none," as the Special Operations folks will explain.
Sure, the math is squirrely; but the sentiment is real.
(password AND SMS) OR (password AND app) OR SMS --> Get in!
Then it would be obvious that the password is sort of redundant and it's really less secure than 1FA. It would also be clear what you have to lose to be locked out yourself. Only having 2 factors is not great because that's twice as many ways to get locked out. You really need 3 or more but it's never clear if that's reducing security to 1FA level or not because they don't clearly show you what the account recovery options are.
The ability to do this would not mitigate Microsoft’s responsibilities here, but at least it would allow some people to help themselves.
That's an interesting point. Maybe an unlisted burner that you don't use for anything else could be your SMS backup number. At least that adds one small layer of security.
It's like being in an episode of The Wire just to stay semi-secure online ;-).
Not sure how that works if they (Microsoft) don’t have your phone number.
My Account > Security & Privacy > Additional Security Verification > Update Your Phone Numbers Used for Account Security
And then setting the preferred method to "use verification code from app". Once you finish setting up the authenticator app you can delete your phone number from the 2fac list.
At the end of that process you should be left with only having the app authenticator as a 2fac option.
See https://docs.microsoft.com/en-us/azure/active-directory/user... for some details, but the MSFT documentation on this isn't very good in general.
If You are able to remove it, I’m wondering if there is some sort of policy or limitation our VAR is adding to our instance.
edit - added quotes to the error message