Using a less secure Duo method? - News - University IT (2024)

Using Duo as 2FA (Two-Factor Authentication) adds an extra layer of security to university application access. Unfortunately, like any technology, some individuals have learned to exploit it. Hackers have used phishing and malware to fake SMS messages and phone calls to obtain Duo access. Due to this danger, the university strongly recommends using only Duo’s Push and/or YubiKey as Duo response methods.

What does this mean to me?

If you currently use SMS or Duo phone calls to respond to Duo prompts, please change to one of the two more secure methods below:

  • Duo Push: Duo instantly sends a prompt to the Duo app installed on your smartphone.

You can verify your identity and gain access with just a quick tap. No more hassle with calls and texts – DUO Push streamlines the authentication process, providing an additional layer of security without sacrificing user convenience. Your peace of mind is our priority, and we believe DUO Push is the key to achieving a perfect balance between security and usability.

How to setup the Duo Mobile app push method:

Navigate to Manage Devices beginning at Step 6a.

  • Yubikey hardware key: Yubikey is a hardware USB device similar in size to a USB thumb drive.

Insert the Yubikey into your computer, verify your identity, and gain access with just a quick tap.

A Yubikey hardware key can be purchased through the UR Tech Store.

How to setup the Duo Mobile app push method:

Navigate to Enroll in Duo Using a YubiKey

Why are phones and SMS being discouraged

While better than relying solely on passwords, SMS and phone-based Two-Factor Authentication (2FA) methods have certain vulnerabilities that make them less secure than other authentication methods.

Here are some reasons why SMS and phone call-based 2FA can be considered less secure:

  • Phishing Attacks
    • Phishing attacks can trick users into providing their 2FA codes. For example, attackers may send fake messages pretending to be a legitimate service requesting the user to provide the code for verification.
  • SIM Swapping Attacks
    • Attackers can perform SIM swapping, where they trick a mobile carrier into transferring the victim’s phone number to a SIM card under the attacker’s control. Once they gain control of the victim’s phone number, they can receive the 2FA codes sent via SMS.
  • Man-in-the-Middle Attacks
    • Attackers can intercept SMS messages or phone calls containing 2FA codes through man-in-the-middle attacks. This involves intercepting and possibly altering communication between two parties without their knowledge.
  • Social Engineering
    • Social engineering techniques can convince mobile carriers to transfer a phone number to a new SIM card or to convince individuals to disclose their 2FA codes. Attackers may use personal information gathered through various means to manipulate individuals.
  • Device Theft
    • If a mobile device is stolen or lost, an unauthorized person may gain access to 2FA codes sent via SMS if the device is not properly secured.
  • Dependence on Single Factor (Phone Number)
    • SMS and phone call-based 2FA rely heavily on the security of the associated phone number. If an attacker gains control of the phone number, they can potentially compromise multiple accounts tied to that number.
  • No Biometric Verification
    • SMS and phone call-based 2FAs usually lack biometric verification, making them susceptible to unauthorized access by someone who has physical possession of the phone.
  • Inherent Insecurity of SMS
    • SMS itself is not a highly secure communication channel. Messages can be intercepted, and the protocol was not designed with security as a primary consideration.

For more information on SMS and phone attacks, check out the article:

https://tech.rochester.edu/news-item/attacking-our-house-phishing-and-cyber-security-attacks-against-the-university/

Using a less secure Duo method? - News - University IT (2024)
Top Articles
What Is the Standard Size Of a Challenge Coin?
Should I Invest In Damien Hirst Guide? | MyArtBroker | Article
Washu Parking
His Lost Lycan Luna Chapter 5
Ds Cuts Saugus
How to change your Android phone's default Google account
Braums Pay Per Hour
Tugboat Information
Rainfall Map Oklahoma
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
PGA of America leaving Palm Beach Gardens for Frisco, Texas
What Was D-Day Weegy
Items/Tm/Hm cheats for Pokemon FireRed on GBA
Aces Fmc Charting
Healing Guide Dragonflight 10.2.7 Wow Warring Dueling Guide
Grab this ice cream maker while it's discounted in Walmart's sale | Digital Trends
Busby, FM - Demu 1-3 - The Demu Trilogy - PDF Free Download
1-833-955-4522
Candy Land Santa Ana
Libinick
Cbssports Rankings
Jeffers Funeral Home Obituaries Greeneville Tennessee
Myql Loan Login
Kabob-House-Spokane Photos
Coindraw App
When His Eyes Opened Chapter 3123
Horses For Sale In Tn Craigslist
Guinness World Record For Longest Imessage
Japanese Emoticons Stars
What does wym mean?
Chicago Pd Rotten Tomatoes
Emily Katherine Correro
Kltv Com Big Red Box
Adecco Check Stubs
Vitals, jeden Tag besser | Vitals Nahrungsergänzungsmittel
Old Peterbilt For Sale Craigslist
Senior Houses For Sale Near Me
No Hard Feelings Showtimes Near Tilton Square Theatre
Western Gold Gateway
Walgreens Agrees to Pay $106.8M to Resolve Allegations It Billed the Government for Prescriptions Never Dispensed
888-333-4026
All Obituaries | Sneath Strilchuk Funeral Services | Funeral Home Roblin Dauphin Ste Rose McCreary MB
Swoop Amazon S3
Holzer Athena Portal
Frontier Internet Outage Davenport Fl
Syrie Funeral Home Obituary
Adams-Buggs Funeral Services Obituaries
Product Test Drive: Garnier BB Cream vs. Garnier BB Cream For Combo/Oily Skin
Mkvcinemas Movies Free Download
Myhrkohls.con
91 East Freeway Accident Today 2022
Https://Eaxcis.allstate.com
Latest Posts
Article information

Author: Kerri Lueilwitz

Last Updated:

Views: 5577

Rating: 4.7 / 5 (47 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Kerri Lueilwitz

Birthday: 1992-10-31

Address: Suite 878 3699 Chantelle Roads, Colebury, NC 68599

Phone: +6111989609516

Job: Chief Farming Manager

Hobby: Mycology, Stone skipping, Dowsing, Whittling, Taxidermy, Sand art, Roller skating

Introduction: My name is Kerri Lueilwitz, I am a courageous, gentle, quaint, thankful, outstanding, brave, vast person who loves writing and wants to share my knowledge and understanding with you.