4 ms·
I was always curious why Duo cloud 2FA was chosen over traditional offline 2FA codes in education.
by harrego 3y ago
I was always curious why Duo cloud 2FA was chosen over traditional offline 2FA codes in education.
- ihattendorf 3y agoUser experience is nicer: click confirm prompt from lockscreen vs. having to find and open app, select correct site, and enter code.
- lolinder 3y ago> click confirm prompt from lockscreen This is also a huge vulnerability that has been exploited. https://www.theregister.com/2022/11/03/mfa_fatigue_enterprise_threat/ https://www.theregister.com/2022/11/03/mfa_fatigue_enterpris...
- harrego 3y agoFrom the student side I end up carrying an extra 2FA app that only works with my college vs. Google Auth (and similar) that carry my other 15 sites.
- SkyPuncher 3y agoIt's simply so much easier. Okta offers a similar feature. So much easier to click a confirmation on my phone than to scroll through dozens of 2FA codes (some of which might be orphaned).
- cute_boi 3y agowell apps like 1password makes it easy to fill those 2fa codes from computer and phones easily.
- janejeon 3y agoAbsolutely. For me, I don't think I would use anything other than 1PW/Yubikey for 2FA codes. But not everyone uses such technologies, and a certain percentage of population is going to find the hurdle to adopt these technologies/apps too high. So, not for us, but I understand why they do it.
- harrego 3y agoThis implementation sounds better. Though for me I still have to manually input a code from the Duo app (that doesn't auto refresh after code entry since it's not time based).
- jmholla 3y agoHaving the do the manual entry and the lack of refresh is a choice of your security team/administrator. Duo supports push notifications and auto-refreshing TOTPs. Source: I used to work for Duo.
- acedTrex 3y agoOffline 2fa codes seems like a nightmare to roll out to an academic campus
- reaperman 3y agoIndeed. They are generally understaffed and salaries are very low so they're very lucky to get any "1x-5x" developers who stick around long enough to understand the infrastructure. Outsourcing as much as possible makes a lot of sense in that environment, it does create major single points of failure but "roll-your-own" would likely fail more often anyways.
- thesuitonym 3y agoPeople really don't understand 2FA codes. Imagine trying to tell thousands of students to get the code from their 2FA app (Which app?). What happens when a student goes home over the summer and gets a new phone, but doesn't transfer the app info? Duo offers a level of management that other apps don't. If a student is struggling, you can send them a text with a direct link to the app they need to download. You can temporarily bypass 2FA from the Duo console. For the longest time, it was the only 2FA app that offered any kind of management. Okta has it now, too, but most higher ed already has a different SSO provider, so switching to Okta just to get 2FA management (And I'm not sure it's as good as Duo's) is probably an impossible task to get off the ground.
- Spooky23 3y agoIt’s two-step auth, not MFA.