Using a less secure Duo method? - News - University IT (2024)

Using Duo as 2FA (Two-Factor Authentication) adds an extra layer of security to university application access. Unfortunately, like any technology, some individuals have learned to exploit it. Hackers have used phishing and malware to fake SMS messages and phone calls to obtain Duo access. Due to this danger, the university strongly recommends using only Duo’s Push and/or YubiKey as Duo response methods.

What does this mean to me?

If you currently use SMS or Duo phone calls to respond to Duo prompts, please change to one of the two more secure methods below:

  • Duo Push: Duo instantly sends a prompt to the Duo app installed on your smartphone.

You can verify your identity and gain access with just a quick tap. No more hassle with calls and texts – DUO Push streamlines the authentication process, providing an additional layer of security without sacrificing user convenience. Your peace of mind is our priority, and we believe DUO Push is the key to achieving a perfect balance between security and usability.

How to setup the Duo Mobile app push method:

Navigate to Manage Devices beginning at Step 6a.

  • Yubikey hardware key: Yubikey is a hardware USB device similar in size to a USB thumb drive.

Insert the Yubikey into your computer, verify your identity, and gain access with just a quick tap.

A Yubikey hardware key can be purchased through the UR Tech Store.

How to setup the Duo Mobile app push method:

Navigate to Enroll in Duo Using a YubiKey

Why are phones and SMS being discouraged

While better than relying solely on passwords, SMS and phone-based Two-Factor Authentication (2FA) methods have certain vulnerabilities that make them less secure than other authentication methods.

Here are some reasons why SMS and phone call-based 2FA can be considered less secure:

  • Phishing Attacks
    • Phishing attacks can trick users into providing their 2FA codes. For example, attackers may send fake messages pretending to be a legitimate service requesting the user to provide the code for verification.
  • SIM Swapping Attacks
    • Attackers can perform SIM swapping, where they trick a mobile carrier into transferring the victim’s phone number to a SIM card under the attacker’s control. Once they gain control of the victim’s phone number, they can receive the 2FA codes sent via SMS.
  • Man-in-the-Middle Attacks
    • Attackers can intercept SMS messages or phone calls containing 2FA codes through man-in-the-middle attacks. This involves intercepting and possibly altering communication between two parties without their knowledge.
  • Social Engineering
    • Social engineering techniques can convince mobile carriers to transfer a phone number to a new SIM card or to convince individuals to disclose their 2FA codes. Attackers may use personal information gathered through various means to manipulate individuals.
  • Device Theft
    • If a mobile device is stolen or lost, an unauthorized person may gain access to 2FA codes sent via SMS if the device is not properly secured.
  • Dependence on Single Factor (Phone Number)
    • SMS and phone call-based 2FA rely heavily on the security of the associated phone number. If an attacker gains control of the phone number, they can potentially compromise multiple accounts tied to that number.
  • No Biometric Verification
    • SMS and phone call-based 2FAs usually lack biometric verification, making them susceptible to unauthorized access by someone who has physical possession of the phone.
  • Inherent Insecurity of SMS
    • SMS itself is not a highly secure communication channel. Messages can be intercepted, and the protocol was not designed with security as a primary consideration.

For more information on SMS and phone attacks, check out the article:

https://tech.rochester.edu/news-item/attacking-our-house-phishing-and-cyber-security-attacks-against-the-university/

Using a less secure Duo method? - News - University IT (2024)
Top Articles
The Financial Aid Award Letter: When Will I Know How Much Aid I’ll Get?
Why Is Housing So Expensive? Becoming a Homeowner in This Market
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Free Atm For Emerald Card Near Me
Craigslist Mexico Cancun
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Select Truck Greensboro
Things To Do In Atlanta Tomorrow Night
Non Sequitur
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Craigslist In Flagstaff
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Walgreens Alma School And Dynamite
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Facebook Marketplace Marrero La
Nobodyhome.tv Reddit
Topos De Bolos Engraçados
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hampton In And Suites Near Me
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Bedbathandbeyond Flemington Nj
Otter Bustr
Selly Medaline
Latest Posts
Article information

Author: Kerri Lueilwitz

Last Updated:

Views: 5577

Rating: 4.7 / 5 (47 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Kerri Lueilwitz

Birthday: 1992-10-31

Address: Suite 878 3699 Chantelle Roads, Colebury, NC 68599

Phone: +6111989609516

Job: Chief Farming Manager

Hobby: Mycology, Stone skipping, Dowsing, Whittling, Taxidermy, Sand art, Roller skating

Introduction: My name is Kerri Lueilwitz, I am a courageous, gentle, quaint, thankful, outstanding, brave, vast person who loves writing and wants to share my knowledge and understanding with you.