Using a less secure Duo method? - News - University IT (2024)

Using Duo as 2FA (Two-Factor Authentication) adds an extra layer of security to university application access. Unfortunately, like any technology, some individuals have learned to exploit it. Hackers have used phishing and malware to fake SMS messages and phone calls to obtain Duo access. Due to this danger, the university strongly recommends using only Duo’s Push and/or YubiKey as Duo response methods.

What does this mean to me?

If you currently use SMS or Duo phone calls to respond to Duo prompts, please change to one of the two more secure methods below:

  • Duo Push: Duo instantly sends a prompt to the Duo app installed on your smartphone.

You can verify your identity and gain access with just a quick tap. No more hassle with calls and texts – DUO Push streamlines the authentication process, providing an additional layer of security without sacrificing user convenience. Your peace of mind is our priority, and we believe DUO Push is the key to achieving a perfect balance between security and usability.

How to setup the Duo Mobile app push method:

Navigate to Manage Devices beginning at Step 6a.

  • Yubikey hardware key: Yubikey is a hardware USB device similar in size to a USB thumb drive.

Insert the Yubikey into your computer, verify your identity, and gain access with just a quick tap.

A Yubikey hardware key can be purchased through the UR Tech Store.

How to setup the Duo Mobile app push method:

Navigate to Enroll in Duo Using a YubiKey

Why are phones and SMS being discouraged

While better than relying solely on passwords, SMS and phone-based Two-Factor Authentication (2FA) methods have certain vulnerabilities that make them less secure than other authentication methods.

Here are some reasons why SMS and phone call-based 2FA can be considered less secure:

  • Phishing Attacks
    • Phishing attacks can trick users into providing their 2FA codes. For example, attackers may send fake messages pretending to be a legitimate service requesting the user to provide the code for verification.
  • SIM Swapping Attacks
    • Attackers can perform SIM swapping, where they trick a mobile carrier into transferring the victim’s phone number to a SIM card under the attacker’s control. Once they gain control of the victim’s phone number, they can receive the 2FA codes sent via SMS.
  • Man-in-the-Middle Attacks
    • Attackers can intercept SMS messages or phone calls containing 2FA codes through man-in-the-middle attacks. This involves intercepting and possibly altering communication between two parties without their knowledge.
  • Social Engineering
    • Social engineering techniques can convince mobile carriers to transfer a phone number to a new SIM card or to convince individuals to disclose their 2FA codes. Attackers may use personal information gathered through various means to manipulate individuals.
  • Device Theft
    • If a mobile device is stolen or lost, an unauthorized person may gain access to 2FA codes sent via SMS if the device is not properly secured.
  • Dependence on Single Factor (Phone Number)
    • SMS and phone call-based 2FA rely heavily on the security of the associated phone number. If an attacker gains control of the phone number, they can potentially compromise multiple accounts tied to that number.
  • No Biometric Verification
    • SMS and phone call-based 2FAs usually lack biometric verification, making them susceptible to unauthorized access by someone who has physical possession of the phone.
  • Inherent Insecurity of SMS
    • SMS itself is not a highly secure communication channel. Messages can be intercepted, and the protocol was not designed with security as a primary consideration.

For more information on SMS and phone attacks, check out the article:

https://tech.rochester.edu/news-item/attacking-our-house-phishing-and-cyber-security-attacks-against-the-university/

Using a less secure Duo method? - News - University IT (2024)
Top Articles
NEXO Wallet | Ledger
What Is an ACH Withdrawal? How Do ACH Withdrawals Work?
Using GPT for translation: How to get the best outcomes
Summit County Juvenile Court
Affidea ExpressCare - Affidea Ireland
Amtrust Bank Cd Rates
Farmers Branch Isd Calendar
Flat Twist Near Me
Rochester Ny Missed Connections
Ladyva Is She Married
WWE-Heldin Nikki A.S.H. verzückt Fans und Kollegen
Funny Marco Birth Chart
Flights To Frankfort Kentucky
Belle Delphine Boobs
Bowlero (BOWL) Earnings Date and Reports 2024
7543460065
Aldi Süd Prospekt ᐅ Aktuelle Angebote online blättern
Invert Clipping Mask Illustrator
G Switch Unblocked Tyrone
50 Shades Of Grey Movie 123Movies
Icivics The Electoral Process Answer Key
Atdhe Net
Sea To Dallas Google Flights
Best Nail Salons Open Near Me
Highmark Wholecare Otc Store
Bennington County Criminal Court Calendar
Litter Robot 3 RED SOLID LIGHT
Darrell Waltrip Off Road Center
Unable to receive sms verification codes
1979 Ford F350 For Sale Craigslist
2015 Kia Soul Serpentine Belt Diagram
1964 Impala For Sale Craigslist
Courtney Roberson Rob Dyrdek
Kiddie Jungle Parma
Trebuchet Gizmo Answer Key
AP Microeconomics Score Calculator for 2023
Oreillys Federal And Evans
Waffle House Gift Card Cvs
Maxpreps Field Hockey
Hebrew Bible: Torah, Prophets and Writings | My Jewish Learning
Second Chance Apartments, 2nd Chance Apartments Locators for Bad Credit
Gifford Christmas Craft Show 2022
Live Delta Flight Status - FlightAware
Beaufort SC Mugshots
VDJdb in 2019: database extension, new analysis infrastructure and a T-cell receptor motif compendium
Powerspec G512
Powerboat P1 Unveils 2024 P1 Offshore And Class 1 Race Calendar
How to Install JDownloader 2 on Your Synology NAS
Craigslist St Helens
Sam's Club Gas Price Sioux City
Diesel Technician/Mechanic III - Entry Level - transportation - job employment - craigslist
Round Yellow Adderall
Latest Posts
Article information

Author: Kerri Lueilwitz

Last Updated:

Views: 5577

Rating: 4.7 / 5 (47 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Kerri Lueilwitz

Birthday: 1992-10-31

Address: Suite 878 3699 Chantelle Roads, Colebury, NC 68599

Phone: +6111989609516

Job: Chief Farming Manager

Hobby: Mycology, Stone skipping, Dowsing, Whittling, Taxidermy, Sand art, Roller skating

Introduction: My name is Kerri Lueilwitz, I am a courageous, gentle, quaint, thankful, outstanding, brave, vast person who loves writing and wants to share my knowledge and understanding with you.