Today, we're announcing support for a new authentication method and FIDO Ready™ U2F devices.
U2F: What is it?
A new phishing-resistant, strong authentication method has been introduced by FIDO Alliance and Google. This hardware-based authenticator works via an emerging, open authentication standard called universal two-factor authentication (U2F), initially developed by Google, and now managed by the FIDO Alliance. We’re one of the first authentication software providers to support U2F devices, and we’re offering this new authentication method to our customers.
The FIDO (Fast IDentity Online) Alliance is a new industry group that emerged with the intention of getting more widespread adoption of online authentication. Duo Security, as a member of the FIDO Alliance, worked with Google to offer U2F support to new and existing Duo Security business customers.
The goal of U2F is to simplify the two-factor authentication process, with the idea that the simpler and easier authentication is, the more people will use it. In order to streamline the process, U2F devices require only a supported web browser, eliminating the need for special drivers. One of the most notable security improvements of the U2F standard is is that it allows implementors, like Duo Security, to completely prevent one of the most common credential attacks today, phishing.
How does it work?
Our goal at Duo is to enable organizations of all sizes to adopt multifactor authentication within their solutions platform. By offering support for U2F and other hardware tokens, we continue to democratize two-factor for everyone.
“As a co-creator of the FIDO U2F protocol, we are excited to introduce this new high security authentication method to the end-user. With FIDO U2F, one single device can be used to authenticate with any number of online services, with no user information and encryption secrets shared between the service providers,” said Stina Ehrensvard, CEO and Founder, Yubico, Inc. “As a maker of FIDO U2F devices that are successfully deployed within large online services, we are proud to partner with Duo Security offering enterprise server solutions supporting U2F.”
Read more at our U2F page.