Live data from Hacker News

DontDuo: Bypass 2FA with DTMF Tones

dontduo.com

51–60 of 60 posts

Re: DontDuo: Bypass 2FA with DTMF Tones

#51
post #50
post #49

Earlier quoted context omitted.

It doesn't support these at my institution. Maybe they haven't rolled out this version? (Technically you can get U2F to work, but they have a bright red warning that says it's unsupported when you do that.)

IT admins at your org can enable or disable 2FA methods allowed via the Duo administration console. Many US edus disable TOTP.

I think because they don’t want to deal with supporting the app and (almost) everyone has a phone that can receive calls.

Re: DontDuo: Bypass 2FA with DTMF Tones

#52

To explain what's going on here for the unaware — 1) Duo is a commercial service that offers multi-factor authentication through a variety of means, one of which is the Phone Call. 2) This site lets you register them as your Duo phone number, when demanded to do so by someone who's trying to protect your high-value access from being hijacked (such as your employer). 3) This site provides you a phone number that auto-…

I, personally, would absolutely push to fire anyone who thinks that phone calls (or SMS) are reasonable second factors.

Re: DontDuo: Bypass 2FA with DTMF Tones

#53

This is a horrible idea. I just can't. Why does this service even exist. I seriously hope duo figures out the numbers this site is using and blacklists them.

I agree, this is a site that shouldn't exist, it's security disaster. Duo should blacklist all their numbers. One easy way would be to detect which accounts consistently confirm instantly; since humans can't do that, those accounts almost certainly must be connected to a subverting bot like this.

Re: DontDuo: Bypass 2FA with DTMF Tones

#54
post #35

To explain what's going on here for the unaware — 1) Duo is a commercial service that offers multi-factor authentication through a variety of means, one of which is the Phone Call. 2) This site lets you register them as your Duo phone number, when demanded to do so by someone who's trying to protect your high-value access from being hijacked (such as your employer). 3) This site provides you a phone number that auto-…

It would help if Duo wasn't a closed off trash fire that no one should be forced to use. I'm not condoning bypassing it if it's something your employer has required, but there's really no excuse for not supporting an open method like TOTP and/or security keys.

How does this problem relate to the post topic at hand? I can’t find the connection between “Duo doesn’t support TOTP and security keys” and “Duo phone method bypass for $4/mo”.

(Incidentally, Duo does support OATH-TOTP and Yubikeys in native mode.)

Re: DontDuo: Bypass 2FA with DTMF Tones

#55
post #35

Earlier quoted context omitted.

It would help if Duo wasn't a closed off trash fire that no one should be forced to use. I'm not condoning bypassing it if it's something your employer has required, but there's really no excuse for not supporting an open method like TOTP and/or security keys.

How does this problem relate to the post topic at hand? I can’t find the connection between “Duo doesn’t support TOTP and security keys” and “Duo phone method bypass for $4/mo”. (Incidentally, Duo does support OATH-TOTP and Yubikeys in native mode.)

It's related because it's very easy to empathize with people wanting to bypass Duo, when Duo is a crappy proprietary app built on top of an open standard that people are forced to use.

Your "incidentally" comment is actually important: organizations have to enable these additional auth methods; mine does not support TOTP. If it was the case that people weren't forced to either answer the phone or use a crappy app to log in (and own a smartphone), there would be much less impetus to bypass it. The point is not bypassing 2FA. The point is bypassing Duo.

Re: DontDuo: Bypass 2FA with DTMF Tones

#56
post #41

Earlier quoted context omitted.

If it were free, I'd be pretty tempted to use it, and hope somebody would notice my protest. Duo is thrust upon me by my university. I don't want to install Duo's proprietary app for receiving pushes or generating codes (I effectively can't anyway because my phone is de-Googled), and getting cell reception to receive their call can be difficult in some buildings. The other day it took three calls until the system det…

It’s free for upto 10 users I actually use it on some of my machines, with the call back features disabled. There should be a URL that gives you a QR code for the TOTP/DuoPush enrollment.

Parent means the DontDuo service isn't free, not Duo itself.

Re: DontDuo: Bypass 2FA with DTMF Tones

#57

Earlier quoted context omitted.

> A company comes along and says, "Here's some textbook standard stuff, and here we add our lock-in on top of it. Would you like the lock-in ?" And everyone says, "Yes please." That's not the sales pitch, _at all_, and you belie your inexperience in this understanding. Perhaps if you tried working for a big company or a university and began to understand the scale of the things they deal with in regards to identity a…

Your response is too long, so I'll address only a few points: >Perhaps if you tried working for a big company or a university and began to understand the scale of the things they deal with in regards to identity and access management I manage my lab's freeipa setup. It lets you manage TOTP tokens. I think it also allows yubikeys, but I haven't checked. It may not be as full-fledged as other offerings, but you can man…

> Your response is too long

Rude. Go ahead and run your small computer lab and pretend you're dealing with issues on the scale that companies with thousands or tens of thousands of employees do. They're absolutely choosing the cheaper option when going with a managed provider vs. your hacked-together TOTP solution.

Re: DontDuo: Bypass 2FA with DTMF Tones

#58

Earlier quoted context omitted.

Your response is too long, so I'll address only a few points: >Perhaps if you tried working for a big company or a university and began to understand the scale of the things they deal with in regards to identity and access management I manage my lab's freeipa setup. It lets you manage TOTP tokens. I think it also allows yubikeys, but I haven't checked. It may not be as full-fledged as other offerings, but you can man…

> Your response is too long Rude. Go ahead and run your small computer lab and pretend you're dealing with issues on the scale that companies with thousands or tens of thousands of employees do. They're absolutely choosing the cheaper option when going with a managed provider vs. your hacked-together TOTP solution.

There is nothing hacked together in this. If you are not aware, freeipa (called idm downstream by RedHat) is a pretty full featured solution with is more or less a replacement for AD if your clients are unix based. And RedHat will absolutely support your scale requirements. It is mostly that AD is a lock-in in itself due to windows, and duo will work better with AD, whereas idm/freeipa does not have a standalone 2fa product that would work with AD.

Re: DontDuo: Bypass 2FA with DTMF Tones

#59

Earlier quoted context omitted.

> Your response is too long Rude. Go ahead and run your small computer lab and pretend you're dealing with issues on the scale that companies with thousands or tens of thousands of employees do. They're absolutely choosing the cheaper option when going with a managed provider vs. your hacked-together TOTP solution.

There is nothing hacked together in this. If you are not aware, freeipa (called idm downstream by RedHat) is a pretty full featured solution with is more or less a replacement for AD if your clients are unix based. And RedHat will absolutely support your scale requirements. It is mostly that AD is a lock-in in itself due to windows, and duo will work better with AD, whereas idm/freeipa does not have a standalone 2fa…

> more or less a replacement for AD if your clients are unix based

Few people are lucky (?) enough to support a purely unix environment. AD is not expensive when it comes to enterprise-scale projects and plenty of things simply require it for proper support, so I've never seen an enterprise that doesn't have it. I have seen enterprises with classic non-AD pre-Windows-2000 LDAP integrated alongside AD, but usually just as a legacy thing that's too hard to remove.

Considering the amount of resources available to help with AD vs. the amount you'd need to be able to support a 3rd party solution, it should be no surprise MS still has a stranglehold on this. What's more surprising is how badly they've fumbled the use of Azure AD, SSO, ADFS, etc. as real solutions compared to the cloud-first vendors like OneLogin, Duo, Centrify, etc.

Re: DontDuo: Bypass 2FA with DTMF Tones

#60
post #30

Earlier quoted context omitted.

What do you mean trivial to bypass? If I have an account secured with a password and with Duo, then I give you my password, can you get into my account? How?

A "sim hijacking" attack is where an attacker calls your phone company and pretends to be you. They claim to have lost their phone, and get a new sim card issued to them with your phone number. when they put the sim in their phone, the duo authentication message goes to their phone instead of yours. any 2-factor system based on the phone system is no more secure than your phone company's willingness to give away your…

i worked at a voip company and we were once slammed by another voip company who stole a block of 1500 of our phone numbers. It took 3 days to get them back.

POTS telephones are a mess and should just be deprecated.

Post reply on HN