Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Harik
Sep 9, 2001

From the hard streets of Moscow
First dog to touch the stars


Plaster Town Cop

~Coxy posted:

Woke up to Win11 on my PC.

How do you prevent this from happening? I have zero interest in downgrading my OS from a functional one to whatever the gently caress malware/adware nonsense this thread is about.

Is "don't destroy my machine plz" enterprise-only?

Adbot
ADBOT LOVES YOU

Harik
Sep 9, 2001

From the hard streets of Moscow
First dog to touch the stars


Plaster Town Cop

AlexDeGruven posted:

JFC the hyperbole.

loving seriously.
have you even read this thread, lol?

Wife's laptop upgraded itself to 11 and it killed the onboard wifi so now she's got a loving wifi dongle just to use the drat thing. I have much better poo poo do do with my time than chasing down whatever stupid fuckups they've done now.

E: Oh lol you're an early adopter, posting from the start of this thread trying to figure out how to trick it into installing on your machine. Yeah, not gonna take an evangelist seriously on how wonderful the new ad-infested update is.

E2: Figured it out, have it blocked on my remaining w10 machines now.

Harik fucked around with this message at 18:57 on Mar 21, 2024

Harik
Sep 9, 2001

From the hard streets of Moscow
First dog to touch the stars


Plaster Town Cop

AlexDeGruven posted:

I was an early adopter on my old machine, went back to 10 because I didn't need it. I now have a 7950X and 7900XT system so I installed it fresh.

You're still being insanely hyperbolic about things that are mere annoyances.

The wifi thing is legit, and I won't fault anyone for complaining about an automatic update, especially when it breaks. But when you start using phrases like "malware" it just makes you one of *those* people that need to be tuned out.

Pop-up ads on your operating system that make changes if you don't stop and read them carefully to figure out which weasel-worded option is "gently caress off don't switch my search engine" are not "mere annoyances."

It installs without permission and can break your machine I'm not sure what the gently caress else to call it other than "malware".

It's the forced install that makes it bad. If you install it yourself then whatever, it's just the latest version of windows, but there's way too many people who've woken up to finding themselves with a broken machine and a tedious reinstall cycle.

Harik
Sep 9, 2001

From the hard streets of Moscow
First dog to touch the stars


Plaster Town Cop

cruft posted:

Really not looking forward to HQ pushing me onto Win11 after reading this thread. On the other hand, I heard it has Android emulation, which will let me run Microsoft Authenticator without having to pull out my personal Chromebook every time I want to get onto a federated SharePoint server. And I heard wsl2 won't require some bonkers kludge to use the right name server with our VPN client installed.

So kind of a mixed bag?

In closing, I miss having a Linux desktop.

Microsoft or Google Authenticator is just a Time-based One Time Password (TOTP) service, you can get that supported in various password managers. It's slightly more annoying to setup because you have to C&P rather than scanning a qrcode but it's a one-and-done deal.

I'm doing it with KeepassXC but most of them (not lastpass!) should support it. It's a hell of a lot easier than setting up a whole android emulator for it.

E: unless they're using phone sign-in and not the 6-digit code.

~Coxy posted:

This is genius.
(although it does seem to defeat the purpose of having multiple factors, not that I really care)

It's better than the authentication status quo of:
* Something you have
* Something you know
OR
* $20 to slip to a minimum wage worker at a kiosk for a SIM swap.

Harik fucked around with this message at 06:48 on Mar 22, 2024

Harik
Sep 9, 2001

From the hard streets of Moscow
First dog to touch the stars


Plaster Town Cop

cruft posted:

:actually:

The primary reason most businesses require Microsoft Autheniticator is because they're implementing a Microsoft product called "Entra". This sends a request to the cloud from the device trying to authenticate, which triggers a push notification to the enrolled Authenticator device, triggering a popup with (hopefully) a little map of the geoip location of the authenticating device, and a box to enter a 2-digit code, which is presented to the authenticating device by the cloud server. If you enter the code, you're in.

There is no explanation of why the map is there, so most people ignore it, which is why a type of proxy attack called "evilproxy" is making big waves right now. Nobody thinks anything of it if the map shows Indonesia, because it was never explained why the map mattered.

I don't know why Authenticator doesn't, at a minimum, compare the location against the phone's built-in location services, to at least ask "are they within 500 miles of each other", but I'm sure Microsoft has their reasons.

None of this is a problem that Webauthn (Fido U2F) suffers from, since it looks up a unique asymmetric key pair by hostname. If a malicious proxy server tries to authenticate, the Fido device doesn't know what keypair it's trying to trick out of the user, so it just fails. Bing bang, an entire class of attack sidestepped by a nice architecture.

Anyway. I still have to use Entra, which means I need to lug around my personal Chromebook while I'm on work travel. It's probably for the better, since it prevents me from doing any non-work stuff on the work laptop.

e: in closing, "something you know + something you have" is all well and good, but when your entire architecture is vulnerable by design to a man-in-the-middle attack, it's worthless.

lol that's so terrible and worthless, A++ at making this incredibly stupid system. Why can't you run microsoft authenticator on your phone, or is it something stupid like "it doesn't actually support anything useful on iphone but it exists just to confuse people"?
E: I should try reading to the end of the page next time, lol.

Adbot
ADBOT LOVES YOU

Harik
Sep 9, 2001

From the hard streets of Moscow
First dog to touch the stars


Plaster Town Cop

mobby_6kl posted:

I'm not so sure.

We have to use this poo poo at work and generally it'll just let me log in without even asking for a new token. Like I just click "login" and it goes right through, for weeks at a time.

E: there's also an option to send a code by SMS if the cloud poo poo isn't working for whatever reason

so it's a nuisance to use, not a sane standard and a "or has $20 to slip the teen at the kiosk" authentication? absolutely perfect. nothing to improve, security has reached its peak.

E: Theoretically it has the token on your machine that's tied with your IP and doesn't just let you login from anywhere in the world. Theoretically. Hopefully.

Harik fucked around with this message at 17:31 on Mar 24, 2024

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply