2 ms·
The service was designed to isolate trust to only secondary login verification via a user-enrolled device. If any part of the system (including the user's phone
by tuebor 15y ago
The service was designed to isolate trust to only secondary login verification via a user-enrolled device. If any part of the system (including the user's phone) were to be compromised or disabled, an attacker would still need to have stolen your primary credentials to log in.
The choice of being locked out or not on Duo failure is a configuration option ("failmode"), with a fail-safe default.
In any usable system, security is never absolute, but a calculated abatement of risk (you still use HTTPS anyway, right? ;-). Two-factor auth protects against the most common path to account takeover today (credential theft), and Duo's approach intends to make it actually usable and deployable.