Earlier quoted context omitted.
I assume this is referring to Duo Security, owned by Cisco: https://duo.com/
I was just as lost as OP. Can someone also explain how it uses DTMF tones? Is it using tones to deliver or receive 2FA codes? Scanned the above url but didn't see the info.
DontDuo: Bypass 2FA with DTMF Tones
21–30 of 60 posts
Re: DontDuo: Bypass 2FA with DTMF Tones
#22Re: DontDuo: Bypass 2FA with DTMF Tones
#23Earlier quoted context omitted.
Duo implements a proprietary setup layer over HOTP (counter based instead of time based, useful for hardware key generators that don't have a clock). I needed it for my University and internship, and was able to set it up on an Android emulator (or rooted device), copy the secret key and counter off of the app's config file, and then use it on my laptop. On the computer I have ~/.totp/ which contains files like `gith…
I have been doing the same on AOSP with the andOTP app. Can't get why large companies/universities have boners for proprietary crap like duo. A company comes along and says, "Here's some textbook standard stuff, and here we add our lock-in on top of it. Would you like the lock-in ?" And everyone says, "Yes please." For those suffering, this helps: https://github.com/puddly/android-otp-extractor Edit: Responding to yo…
Re: DontDuo: Bypass 2FA with DTMF Tones
#24Re: DontDuo: Bypass 2FA with DTMF Tones
#25Earlier quoted context omitted.
Duo implements a proprietary setup layer over HOTP (counter based instead of time based, useful for hardware key generators that don't have a clock). I needed it for my University and internship, and was able to set it up on an Android emulator (or rooted device), copy the secret key and counter off of the app's config file, and then use it on my laptop. On the computer I have ~/.totp/ which contains files like `gith…
I have been doing the same on AOSP with the andOTP app. Can't get why large companies/universities have boners for proprietary crap like duo. A company comes along and says, "Here's some textbook standard stuff, and here we add our lock-in on top of it. Would you like the lock-in ?" And everyone says, "Yes please." For those suffering, this helps: https://github.com/puddly/android-otp-extractor Edit: Responding to yo…
Re: DontDuo: Bypass 2FA with DTMF Tones
#26Earlier quoted context omitted.
I have been doing the same on AOSP with the andOTP app. Can't get why large companies/universities have boners for proprietary crap like duo. A company comes along and says, "Here's some textbook standard stuff, and here we add our lock-in on top of it. Would you like the lock-in ?" And everyone says, "Yes please." For those suffering, this helps: https://github.com/puddly/android-otp-extractor Edit: Responding to yo…
It's not just universities, it's basically any Windows centric place that seems to gravitate towards packaged solutions rather than understanding or implementing the tech piecemeal.
Re: DontDuo: Bypass 2FA with DTMF Tones
#27Re: DontDuo: Bypass 2FA with DTMF Tones
#28Earlier quoted context omitted.
It's not just universities, it's basically any Windows centric place that seems to gravitate towards packaged solutions rather than understanding or implementing the tech piecemeal.
I feel that at least public universities have some responsibility to not peddle garbage like this. I don't know if there are laws about this, but requiring students/staff to use play services and blobs to access university infrastructure (all paid for by taxes and fees) shouldn't be a thing.
Re: DontDuo: Bypass 2FA with DTMF Tones
#29I got the trial. Gave me a 201 area code number. Called it and it waited some seconds after answering, played a DTMF tone and hung up. No, I didn't test it with Duo (lol). Every time this number receives a phone call it increments a login counter on the dashboard.
Re: DontDuo: Bypass 2FA with DTMF Tones
#30This is a horrible idea. I just can't. Why does this service even exist. I seriously hope duo figures out the numbers this site is using and blacklists them.
I think the point is that relying on phone calls and DTMF tones for two factor authentication is trivial to bypass. Anyone can record DTMF tones in a voicemail message and forward calls to that number.