@GossiTheDog@cyberplace.social
1. We're talking about big orgs with zillion-dollar budgets. They can afford smart card infrastructure.
2. Trusting random employees' smartphones to serve as authentication tokens is hilariously stupid.
3. Employees who do know the first thing about security aren't gonna be thrilled installing Microsoft apps on their phones.
4. MFA is the exact opposite of “minimal friction”.
5. If you must use a phone as a hardware token, then at least do it properly: NFC, QR code, etc.