DUO's latest news on 2factor authentication and how it

New Post Public Reply Private Reply Replies (0) Message Board
CyberC
661


DUO's latest news on 2factor authentication and how it works. Remember, they boast of having 500 million plus authentications each month. As soon as StrikeForce prevails in its battle to secure its IP in it's appeal to the Supreme Court, they will be paying StrikeForce monthly for their use of StrikeForce's Patented IP.


INDUSTRY NEWS
MARCH 20TH, 2019
Two-Factor Authentication: The Basics
There’s no getting around it: the password as we know it is dead. The information we keep online is too important to only safeguard with a single string of characters. Our security methods must evolve.
We’ve seen that evolution begin over the last decade or so. Users and system administrators have gradually moved beyond passwords to implement complex, dynamic approaches to security like zero-trust architectures. In the past, one only needed a password to gain access. Now, administrators and users can use a combination of tools and policies that allow seamless authentication while still safeguarding against the most common types of attacks.
Essentially, web security has moved from the Captain America approach — using one shield for self-defense: a password — to the Batman approach, where a utility belt of tools contains options for a variety of situations.
One of the most important resources in that utility belt is two-factor authentication (2FA). It’s a cost-effective measure that protects against key threat vectors (and it’s fairly simple to roll out). Let’s dig in to 2FA: why it’s important, how it works, and how you can get started.
Why 2FA is an Essential Part of Web Security
Two-factor authentication means that whatever application or service you’re logging in to is double-checking that the request is really coming from you by confirming the login with you through a separate venue.
You’ve probably used 2FA before, even if you weren’t aware of it. If a website has ever sent a numeric code to your phone for you to enter to gain access, for instance, you’ve completed a multi-factor transaction.
2FA is essential to web security because it immediately neutralizes the risks associated with compromised passwords. If a password is hacked, guessed, or even phished, that’s no longer enough to give an intruder access: without approval at the second factor, a password alone is useless.
2FA also does something that’s key to maintaining a strong security posture: it actively involves users in the process of remaining secure, and creates an environment where users are knowledgeable participants in their own digital safety. When a 2FA notification comes to a user, they have to answer the question, “Did I initiate that, or is someone attempting to access my account?” This underlines the importance of security with each transaction. While most other web security methods are passive, and don’t involve end users as collaborators, 2FA creates a partnership between users and administrators.
How Does 2FA Work
Different 2FA methods use varying processes, but they all rely on the same underlying workflow.
Typically, a 2FA transaction happens like this:
The user logs in to the website or service with their username and password.
The password is validated by an authentication server, and if correct, the user becomes eligible for the second factor.
The authentication server sends a unique code to the user’s second-factor device.
The user confirms their identity by approving the additional authentication from their second-factor device.
While the basic processes behind multi-factor authentication are generally the same across providers, there are many different ways to implement it, and not all methods are created equal. Let’s dive into the various types of 2FA.
Types of 2FA
Generally, multi-factor authentication systems rely on at least one of the following approaches.
Authenticator Apps. Authenticator apps are exactly what they sound like: smartphone apps that handle the second-factor approval process as standard notifications. Authenticator apps such as Duo Mobile use internet connectivity to deliver login approval requests, which is more secure than using phone lines.
U2F devices. Universal Second-Factor (U2F) devices are similar to tokens: they’re small physical devices used exclusively to verify logins. Instead of attaching to a keychain like a token, however, U2F devices are designed to fit in an open USB slot. (Older models use USB-A ports, newer versions fit in USB-C slots.) When a user enters their password on a computer with a U2F device plugged in, they’re prompted to tap the physical U2F device to gain access. U2F devices are popular because they’re so easy to use — a simple tap and you’re done — but using one means giving up an available USB port, which isn’t always an option for all users.
Passcodes. Passcodes are the most common form of 2FA, and usually consist of a short string of numbers sent to a smartphone. Passcodes definitely count as 2FA. Since they rely on phone lines, however — which can be compromised — they represent the least secure method. Passcodes aren’t a real hit with users, either: each code must be manually entered, which can be a nuisance.
Tokens. Many web security teams opt to arm their users with tokens. These typically are small keychain fobs that generate codes for users to enter as their second factor. Tokens are more secure than cellular-delivered passcodes, as they don’t rely on phone lines, but they don’t address the annoyance of entering codes. (In fact, they may make that worse, as you can’t copy and paste a code from a token.) Tokens are attractive because they are affordable and don’t require system administrators to collect phone numbers — but they’re battery-operated, and batteries die. Using tokens will mean dealing with the headache of timing replacements to avoid users losing access to crucial systems.
Phone callbacks. Phone callbacks are one of the less popular versions of 2FA, but they’re an effective — if time-consuming — way to implement a second factor. In a phone callback setup, once a user logs in, they receive an automated phone call that prompts them to approve or deny the access request.
TOTP. Time-based One-Time Passcodes, better known as TOTP, are similar to passcodes. Instead of a service sending the user a series of numbers, however, an app generates a one-time-use passcode that will quickly expire. Doing it this way means users can still use their authenticator app (which will generate TOTPs on demand), and no insecure phone lines get involved.
Keep in mind that in most cases, system administrators opt for a variety of approaches and typically give users a few options to best fit the given need. So, for example, if your work laptop has a U2F device attached, you could use that as your second factor throughout the day. Logging in to an application off-hours from your smartphone, however, might require that you use an authentication app. And while this kind of flexibility may not seem like a big deal, your users will definitely appreciate it, making them stronger allies of your security efforts.
Getting Started with 2FA
Because 2FA is a cloud-based service, it’s relatively easy to implement and can be rolled out gradually to your organization. The basic process for getting started goes like this:
Determine which 2FA service you’ll be using. Take advantage of our Two-Factor Evaluation Guide to get a handle on all of the things you can (and should) get from a web security product that includes 2FA. Remember: 2FA shouldn’t be your only security approach. A strong security platform will both make it easy to set-up multi-factor access with your most important apps and provide other avenues of defense, like customizable access policies. If you have ambitions of someday moving to a zero-trust model, a coordinated approach that includes, but isn’t limited to, 2FA is essential. We’ve designed Duo Beyond to meet these needs, and you can learn more about that here.

Establish a proof of concept with a small group of users in a low-stakes environment. Before you roll out 2FA to your entire organization, test it out first and address any issues you identify. Get a small group of users who will be communicative about the process and work with them ahead of time to understand how it will work for them.

Enable 2FA using integrations for each service or application you’re protecting. To set up a specific application or service to work with 2FA, you’ll need an integration — a means of getting the application or service to work with 2FA. For example, Duo Beyond includes integrations for everything from larger systems like Salesforce CRM to smaller applications like Slack. (We also have a web-based integration that can be customized to work with any application for which there isn’t a specific integration.) However you choose to move forward, make sure you’ve got a plan for integrating each of your critical systems with your 2FA service.
Conclusion
In the post-password world, strong web security relies on a dynamic approach built from a variety of tools and policies. It’s important to never rely on any single method for comprehensive protection. That means two things: (1) if you’re currently relying on passwords alone, it’s time to evolve, and using 2FA is a solid first step; and (2) 2FA is an essential security tool, but it becomes even more effective when it’s used as part of a coordinated strategy of security applications and policies.

Zerify Inc (ZRFY) Stock Research Links

ZRFY Board Company Profile Buy Rating Time & Sales News Filings Financials
Scroll down for more posts ▼

Top 10 Most Recent News Articles

ePlus Wins Big: First Ambassador Partner for Everpure

Updated Category News Views 2

ePlus Breaks Ground with Everpure There's a new chapter unfolding in the tech sector, and ePlus has carved its name on the marquee. Achieving the exclusive Ambassador Partner Status with Everpure, ePlus becomes the first in North America to hit this high note. In the crowded room of tech partnerships, this isn't just a pat on the back—it's a gold star that screams...

Continue Reading
Herzog Joins Greenberg Traurig: A Litigation Powerhouse

Updated Category News Views 4

Greenberg Traurig Welcomes David M. Herzog to the Team Ah, the rat race of litigation just got a bit fiercer with Greenberg Traurig's latest acquisition: David M. Herzog. This isn’t just another lawyer joining the ranks; Herzog's a dynamo, coming in hot from the U.S. Attorney's Office, right onto the battlefield of corporate litigation. Why Herzog's Move Matters...

Continue Reading
Tahoe Truckee Life TV Series Elevates Local Flavor

Updated Category News Views 2

Meet “Tahoe Truckee Life” Kane Schaller, the face of the Tahoe Truckee Life series, is giving folks a front-row seat to the lives and landscapes that make the Reno-Tahoe region buzz. Now, I've seen shows trying to pull this off, but this one might just spark something genuine if done right. The Real Deal on Reno-Tahoe The show airs on the REAL Shows Network—a...

Continue Reading
Little Sunshine's Opens New School in Peoria, AZ

Updated Category News Views 1

Betting On Early Childhood Education Little Sunshine's Playhouse breaks ground on a fresh hub of learning in Peoria, Arizona, and this is no small playdate. It's the dawn of another preschool institution aiming to mold the early years of countless kiddos. The gears turning behind this development are impressive by themselves, but it's what it means for Peoria's families...

Continue Reading
Kroger's Strategic Shift: Ibbotson's Bold New Charge

Updated Category News Views 5

Kroger Welcomes a Seasoned Retail Veteran Change often arrives with the dawn of new leadership. As Kroger takes a page from the playbook of large-scale retail transformation, they've enlisted Mark Ibbotson. Effective September 14, Ibbotson will step in as Executive Vice President and Chief Store Operations Officer. It's a roll of the dice that could either accelerate...

Continue Reading
Capricor Faces Lawsuit: Investors Should Take Note

Updated Category News Views 4

Capricor Therapeutics: A Rough Road Ahead If you've got skin in the game with Capricor Therapeutics, these latest developments might have you feeling a bit queasy. Forget the greasy diner fare today; this situation calls for some serious contemplation and maybe a bit of antacid. Over at NASDAQ:CAPR, the air is hot with allegations, stock price nosedives, and looming legal...

Continue Reading
Sports CIOs Tackle Venue Tech Ownership Challenges

Updated Category News Views 2

Untangling the Mess Behind Game Day Ever wonder why getting to your seat at a sports event feels seamless? It's like magic with your ticket appearing as a barcode on your phone, the concession stand knowing your order from last week's game, and sponsor ads personalized just for you. This is no easy feat. Behind the scenes, though, it's akin to a game of Twister. The...

Continue Reading
Potassium Fluoride Market Growth Sparks Interest

Updated Category News Views 1

Here's a story you might not have expected—potassium fluoride is finding its spotlight! With the market projected to tick upwards from USD 0.43 billion in 2026 to USD 0.51 billion by 2032, there's more here than meets the eye. A steady CAGR of 2.9% might not scream excitement, but steady growth often does the trick in chemicals. Why the Buzz Around Potassium Fluoride?...

Continue Reading
MemoryDriver Relaunches with Navigation Challenge

Updated Category News Views 2

MemoryDriver's Relight: A Blazing New Course in Brain Health Look at this: Evon Medics is back with a bang, and they're handing us more than just another mind-numbing app update. On September 15, they're flipping the switch on MemoryDriver, their revamped brain-training gig, with a national 'Beat the Clock' Challenge. It’s up for grabs, totally free, and full of...

Continue Reading
Médunik Canada Boosts Dravet Syndrome Support with Biocodex

Updated Category News Views 0

Breaking Down the Exclusive Médunik-Biocodex Partnership Listen, when a company like Médunik Canada, firmly rooted in Blainville, QC, throws its weight behind a rare disease drug like Diacomit®, folks in the industry take notice. Their recent handshake with Biocodex isn't just small talk; it opens doors to change how Dravet syndrome is managed across Canada. This new...

Continue Reading

Top 5 Most Recently Viewed Articles

Riding the Wave: AI's Impact on the Growing Beer Market

Updated Category News Views 336

The Future of the Beer Market: An AI-Driven Revolution The global beer market is poised for exciting growth, projected to increase by USD 152.3 billion from 2025 to 2029. This expansion reflects a compound annual growth rate (CAGR) of 3.7%. Rising demand in emerging economies is a significant factor propelling this growth. As trends evolve, the landscape of the industry...

Continue Reading
Crypto Firms Unite for Education: A New Era in Support

Updated Category News Views 297

Crypto Firms Collaborate for Educational Growth In a remarkable initiative, the dynamic crypto industry in New York City is coming together to make a significant difference for local schools. This collaboration aims to enhance the educational experience for students in underserved communities through a new program. The ground-breaking effort is embodied in the launch of...

Continue Reading
UGRO's 78% Surge: Merger Spark or Recovery Trap?

Updated Category News Views 206

urban-gro Inc. (NASDAQ:UGRO) surged a staggering 77.71% in after-hours trading to hit $5.74 on Tuesday, riding high on the news of its merger with U. S.-based Flash Sports and Media, Inc. But here’s the kicker—just hours earlier, UGRO closed down 10.03% at $3.23 during regular trading. You know how it goes when the desks see a double whammy like that; you gotta wonder...

Continue Reading
SJW Group Welcomes Douwe Busschops as New CIO

Updated Category News Views 114

SJW Group Welcomes Douwe Busschops as New CIO SJW Group, a prominent water and wastewater utility, has appointed Douwe Busschops as its Chief Information Officer (CIO). This strategic move will play a crucial role in optimizing and integrating technology systems across the organization, enhancing efficiency and customer experience. Douwe Busschops Brings Vast Experience...

Continue Reading
M&A Class Actions: The Stakes and Skepticism

Updated Category News Views 66

Unveiling the M&A Frenzy: Is Everything as It Seems? The corporate world never sleeps, does it? Right when you think things are settling, the mergers and acquisitions scene heats up yet again. Recently, Monteverde & Associates PC, a name not new to those who've navigated shareholder waters, has been turning up the volume on the legal side of things. And let me tell you,...

Continue Reading