Transcript
A wafrn woot (post) by @tinker@infosec.exchange saying “Microsoft Authenticator needs me to validate with Authenticator in order to log in with Authenticator to use it to authenticate another app with Authenticator. Here is the app telling me to open itself to validate itself with itself. #infosec #iHateComputers” It has a screenshot showing the microsoft authenticator app.
I use Aegis.
https://f-droid.org/packages/com.beemdevelopment.aegis
I just switched to aegis when authy went to light mode. I like it.
Enteauth is also pretty good
One of the main feature of MS Authenticator is native integration with the MS authentication system. Aegis doesn’t have such integration
I’ve honestly found in my professional experience that Microsoft Authenticator has random times it just fails to register (usually on iPhones specifically) as well as other occasional problems which are annoying as heck when you’re just trying to get someone signed in. Personally it just seems a lot cleaner to just use a TOTP 2FA and call it a day, but for end users I’ll stick to the company line and direct them to Microsoft Authenticator
That sounds like a bug in waiting honestly. I don’t trust Microsoft that much
That’s kind of the point…
The less of their stuff I have in my life, the better.
funny to me when people are like “I need that integration to automatically approve all auth requests because typing that six digit number in is JUST TOO MUCH MAN!!!”