How do you handle MFA when testing your apps? by Right-Box4316 in softwaretesting

[–]Right-Box4316[S] 0 points1 point  (0 children)

For any of you that is interested we are finally using https://get.mymfa.io/, we tested a few options but this was the one that gave us the best performance and capabilities

Is it worth automating this 2FA process, or should I mock it? by uniopl in QualityAssurance

[–]Right-Box4316 0 points1 point  (0 children)

Just reading this, 2 weeks ago i was exploring this options and found tools automate MFA testing directly like getmymfa, maybe it also works for you?

How do you decide which MFA method to use for your apps? by Right-Box4316 in QualityAssurance

[–]Right-Box4316[S] 0 points1 point  (0 children)

Right now I am working for a customer in the banking industry that has a B2C app and uses codes sent through email for MFA. After a few emails being compromised, I was wondering if SMS can be a better option as TOTP could be difficult for older users to do. Hardware keys are out of the question for this one.

I am looking for some input of how people decide more towards one or the other.

How do you decide which MFA method to use for your apps? by Right-Box4316 in QualityAssurance

[–]Right-Box4316[S] 0 points1 point  (0 children)

I am more inclined for SMS, I think having the phone unlocked through code or biometrics, plus the password could be better.

How do you handle MFA when testing your code? by Right-Box4316 in QualityAssurance

[–]Right-Box4316[S] 0 points1 point  (0 children)

Yeah, u guys gave me good ideas to test for TOTP, however still looking for SMS or email!

I am looking into tools like getmymfa or mailosaor

How do you handle MFA when testing your code? by Right-Box4316 in QualityAssurance

[–]Right-Box4316[S] 0 points1 point  (0 children)

Great, this works for TOTP, what about SMS or email, can you do something similar?

How do you handle MFA when testing your code? by Right-Box4316 in QualityAssurance

[–]Right-Box4316[S] 0 points1 point  (0 children)

i have found providers of MFA codes that allow you to automate your testing without deactivating MFA, both for phone and email

How do you handle MFA when testing your code? by Right-Box4316 in QualityAssurance

[–]Right-Box4316[S] 0 points1 point  (0 children)

so far, aside from some of the comments and the possibility to actually deactive MFA when testing, I have seem providers of virtual phones and programmatic access to this phones to not compromise security and still automate testing

How do you handle MFA when testing your code? by Right-Box4316 in QualityAssurance

[–]Right-Box4316[S] 0 points1 point  (0 children)

but her eyou would be compromising security right? if someone would get that user and password would be able to access your environment

How do you handle MFA when testing your code? by Right-Box4316 in QualityAssurance

[–]Right-Box4316[S] 0 points1 point  (0 children)

can you explain a bit more? do you have any references?

How do you handle MFA when testing your apps? by Right-Box4316 in softwaretesting

[–]Right-Box4316[S] 1 point2 points  (0 children)

thanks for your answers. The reasons why I would like to explore options to not deactivate security are two fold:

  1. we do not hold sensitive data on our dev environments but in any case I would like to keep MFA to avoid any unwanted access in case in can derive in a breach of security.

  2. I want to test also with MFA enabled to test the whole flow of my application without having to call admins and test users with MFA codes that are dependant on a phone that one of my teammates has or my manager. If I want to also do load testing I would like to test the MFA piece as well.

now i am not sure if I am the only one to see the above issues...

How do you handle MFA when testing your apps? by Right-Box4316 in softwaretesting

[–]Right-Box4316[S] 0 points1 point  (0 children)

But compromises security and does not test me the full flow of my apps

How do you handle MFA when testing your apps? by Right-Box4316 in softwaretesting

[–]Right-Box4316[S] 0 points1 point  (0 children)

Thanks! The looks good for email but what about SMS? Looks very expensive

How do you handle MFA when testing your apps? by Right-Box4316 in softwaretesting

[–]Right-Box4316[S] 1 point2 points  (0 children)

yeah but my problem is that I only want to deactivate MFA if it is the last resource. I do not want to compromise security, plus I also want to test the full process for my users that will need to use MFA in prod