Salta al contenuto principale


Tell me if I'm being unreasonable.

A number of my developers have asked to be assigned a company phone because we occasionally need to connect to customers' databases and need 2FA to do it.

"I don't have an authenticator app," one said.

"Install one," I said.

"I don't want to install anything on my personal phone."

😡😠😡

WTF?!

I know I shouldn't ask anyone to use their personal property for work stuff, but how the hell can you work in tech and not have an authenticator app?!

in reply to David Njoku

I'm with the "difficult" developers here. I also don't use an authenticator app on my phone. I do have a TOTP store (using pass-otp) on my laptop (which runs Debian) though. Still, I do find it abusive that people expect employees / students to install specific software from vendors with pretty bad security records (yes, I include Microsoft and Google for various combinations of malice and incompetence) on their own devices. Heck, even expecting people to own a particular kind of device seems something that needs to be negotiated. My employment contract doesn't (yet) say must own Android or iOS device.
in reply to David Njoku

@David Njoku I also work in tech and don't have an authenticator app on my phone (I also use pass-otp on my Debian pc, where it's accessed only after 2fa-ing with my gpg card, so maybe it still qualifies as 2fa?)

but I agree that if work has requirements on things that need to be installed on devices, it should be either clearly stated before signing the contract, or it should provide said devices, no matter how common those things are.

Questo sito utilizza cookie per riconosce gli utenti loggati e quelli che tornano a visitare. Proseguendo la navigazione su questo sito, accetti l'utilizzo di questi cookie.

⇧