news.volyx.in

Flaw has Microsoft Authenticator overwriting MFA accounts, locking users out (csoonline.com)

497 points by miles · 722 days ago · 311 comments on HN

Article summary

A design flaw in Microsoft Authenticator causes it to overwrite existing multi-factor authentication (MFA) accounts when a new account is added via QR code, resulting in users being locked out of their accounts. This issue has been present since 2016 and has been reported by multiple users, but Microsoft has not fixed it, instead blaming users and companies for the problem. The issue can be avoided by using a different authenticator app or manually entering the code instead of scanning the QR code. Microsoft has stated that it is working on enhancing its products, but a fix for this specific issue is not guaranteed.

Main themes

  • Microsoft Authenticator flaw
  • Multi-factor authentication
  • User experience
  • Security vulnerabilities
  • Authentication apps
  • Design flaws

What commenters say

  • The design flaw in Microsoft Authenticator is a significant security risk that can cause users to lose access to their accounts, and it is Microsoft's responsibility to fix it.
  • The issue is not just a technical problem, but also a usability issue that can lead to frustration and confusion for users.
  • Using alternative authentication methods, such as YubiKeys or FIDO, can provide better security and usability than Microsoft Authenticator.
  • Regulatory inertia and industry standards can drive the implementation of security policies that are not effective or user-friendly.
  • Engineers and developers have a responsibility to push back against security policies that are not well-designed or effective.
  • The use of password managers and secure password practices can help mitigate the risks associated with password security.
  • There is a need for a professional consensus on password reset policies to stop arbitrary password resets and promote better password security practices.
  • Microsoft's response to the issue, blaming users and companies, is not satisfactory and does not address the root cause of the problem.