I have never used "duo" and it has taken me a few reads of this to understand exactly what this is, but I think it's worth pointing out that your own personal 'dontduo' service would be trivially simple to set up in a simple twiml bin, at twilio.
I think it would look something like this:
<?xml version="1.0" encoding="UTF-8"?>
<Response>
<play digits="1w2w3w4"></play>
<Hangup />
</Response>
"Include w to introduce a 0.5s pause between DTMF tones. For example, 1w2 will tell Twilio to pause 0.5s before playing DTMF tone 2. To include 1s of pause, simply add ww."https://www.twilio.com/docs/voice/twiml/play#attributes-digi...
any 2-factor system based on the phone system is no more secure than your phone company's willingness to give away your phone number, and they're usually pretty willing. I actually had this happen to me, in a benign way: my employer started paying my phone bill, they transfered my phone number from my personal plan on one carrier to the company plan with a different carrier. Somebody at the office just handed me a new sim card and told me my old SIM didn't work anymore - it required no interaction on my part to transfer my number to a new plan with a new company. that's apparently just normal procedure.
POTS telephones are a mess and should just be deprecated.
2FA is one of those things that is nice when you want it but a huge PITA when it’s forced on you.
How do you give a person secret knowledge that they need to provide you to authenticate but can’t provide to something else?
Pretty sure a dev made this for themself and decided to share
Services like Duo and Okta are enabling your least favorite IT admin to put users in ‘S’SO hell.