Why Your MFA Authentication Method Matters
Thursday, January 9, 2025
Multi-Factor Authentication (MFA) has become an essential tool in cybersecurity for safeguarding online accounts. It ensures that only authorized users can access sensitive information by requiring multiple forms of verification. At Seton Hall University, all users are required to enroll in Duo Two-Factor Authentication (2FA) to add an extra layer of security. This additional step ensures that even if your password is compromised, your account remains protected.
When logging in with your Seton Hall credentials, Duo provides multiple options for verifying your identity, including push notification, text message, phone call or a passcode generated by the Duo app. However, not all methods offer the same level of security. The Department of Information Technology recommends that all Seton Hall University members set Duo push as their primary authentication method to strengthen account security.
Why Choose Duo Push Over SMS or Phone Calls?
Duo Push significantly minimizes the risk of cyber attacks through secure, app-based notifications instead of vulnerable SMS or call-based verification. SMS authentication, for example, transmits unencrypted 2FA codes via text messages, which can be compromised through tactics such as man-in-the-middle attacks and SIM swapping.
-
Man-in-the-Middle Attacks: Cybercriminals can intercept transmitted data over unencrypted Wi-Fi networks. If a user connects to a public or fake Wi-Fi network, attackers can eavesdrop, steal or modify internet traffic, including 2FA codes.
-
SIM Swapping: In a SIM swap scam, cybercriminals impersonate the victim to convince a mobile carrier to transfer the victim's phone number to a new SIM card. This allows attackers to receive the victim’s text messages and 2FA codes, potentially accessing sensitive accounts.
Benefits of Duo Push
Duo Push offers several advantages over SMS and phone calls.
-
Enhanced Security: Duo Push is less susceptible to interception and social engineering attacks compared to SMS and phone calls.
-
Convenience: A single tap on your mobile device is all it takes to approve a login, making it a user-friendly choice.
-
Speed: Duo Push method is faster, providing a seamless and efficient authentication experience.
-
Reliability: The Duo Mobile app functions even in areas with low signal strength, ensuring secure access wherever you are.
Switch to Duo Push Authentication
To switch your default authentication method to Duo Push:
-
Download the Duo Mobile App: Available on the App Store (iOS) or Google Play Store (Android).
-
Open the Duo Mobile App: Follow the instructions to add your Seton Hall University account.
-
Set Duo Push as Your Default Method: Ensure your account settings are configured to use Duo Push as the primary authentication method.
You can also manage your Duo settings directly from your PirateNet dashboard using the Duo 2FA app. The self-service app gives users the option to change authentication methods, reactivate Duo on an existing smartphone or enroll a new smartphone.
For step-by-step instructions on how to update device options to default to the Push method, please refer to the knowledgebase.
Categories: Science and Technology