What To Do if You Must Use SMS
Despite everything we know about the risk of SIM hijacking as a vector of compromise, there’s no way that we can reasonably tell organizations to stop using SMS authentications.
29 Articles Found
Despite everything we know about the risk of SIM hijacking as a vector of compromise, there’s no way that we can reasonably tell organizations to stop using SMS authentications.
We’ve grown a lot as a company since then, and so has the web — and the technical standards we use to build our tools. As we plan for the future, we’re excited to announce a major initiative that will make the Duo authentication experience even easier and more effective for everyone.
Here at Duo, we think about authentication a lot. We’re constantly on the lookout for new techniques and technologies that will make it easier for users to authenticate, more difficult for attackers to impersonate a user, or both at once. WebAuthn is a great example of this. But in this article, we’d like to avoid focusing on bad auth, and instead focus on uncertain auth. We evaluate all the latest auth methods and their pros and cons.
Duo Labs is releasing an open-source Android library that serves as a WebAuthn authenticator, supporting hardware-backed keys and biometric user verification.