Duo Outage
status.duo.com
status.duo.com
Like the popular password vault says in the name… 1Password for everything. If everything can stand alone in 1Password, it ain’t MFA.
However, I'm not sure if GT's Duo service is self-hosted or is hooked into Duo's service "in the cloud".
Millions of students coming online, textbooks are digital now, SSO all the things. Perfect storm.
I spent 20 minutes trying to figure out what new cookie I needed to grey-list for the half dozen redirections in the M365 auth flow to not bork before I thought to check if it was generally broken.
Great success.
To be honest, their useR experience is pretty slick compared to most two factor solutions. I am happy for them, (and their users) that they have been successful, selling into large organizations – good user experience usually isn’t found in large enterprise software due in part to the principal agent problem.
And, yes, Duo is normally a great solution for us.
Just want to add another data point: Dartmouth was a relatively early adopter, and while a bit annoying, it chugged along just fine.
I am in the physics program
We do have an app that lets faculty exempt students from 2FA, but it's mostly for students who need the exception when taking tests etc.
You are going to see a big change in the tech at UC very soon. The old guard is getting the boot.
Yes, altough I did not get affected that much. I was just trying to renew overdue book from the library system. But I'm sure ~45k student got affected harshly in their first day of the semester.
> We do have an app that lets faculty exempt students from 2FA, but it's mostly for students who need the exception when taking tests etc.
It would be better if there is an option to allow graduate students who do research (PhD candidates) to be treated differently as they are not students anyway. And Duo is annoying. I understand that this is not something that will happen specially with the reputition of UC IT department (sorry but you problably know)
> You are going to see a big change in the tech at UC very soon. The old guard is getting the boot.
This is something I have been hearing since I joined but without the old guard getting the boot part. Each year with increasing student enrollment, we can't even provide stable internet connection. I still remember two years ago the outage of the auth server for wifi system on the first day of classes (after covid) and this stayed the case for almost a week.
I was among the last to have to use dial-up from off-campus (which required a specialty ISP @ 26.6k or some awful speed). Fortunately, they upgraded their system while I was there, so I could use the “much” faster DSL. Still not as nice as on-campus internet.
There are two products called Google Meet now. The web interface for the former Google Duo is duo.google.com, just rebranded to Google Meet. The former Google Meet still exists on meet.google.com. Both also have their own Android apps - one called Meet and other Meet (original). Both products have a different set of features and neither completely replaces the other.
The original Duo app was named "Meet (original)" on Android phones, but the old Duo icon remained until you launched the app (so it could inform you about the name change). Then the Google Meet app was introduced. This resulted in phones having three icons ("Duo", "Meet", "Meet (original)") for the same service.
And before that, I thought Duolingo was a crowdsourced translation app, that doubled as a language learning app.
Duo is a multi-factor authentication/single sign-on platform owned by Cisco
This is also a huge vulnerability that has been exploited.
https://www.theregister.com/2022/11/03/mfa_fatigue_enterpris...
Okta offers a similar feature. So much easier to click a confirmation on my phone than to scroll through dozens of 2FA codes (some of which might be orphaned).
But not everyone uses such technologies, and a certain percentage of population is going to find the hurdle to adopt these technologies/apps too high.
So, not for us, but I understand why they do it.
Source: I used to work for Duo.
In this case, it is an external service. However, I also suspect that the Duo outage is probably shielding other on-campus services from load surges that would probably be causing them to get crashy.
I guess I don't know how we could ever prevent such incidents. Given that the first day of classes is a well-kept secret /s.
But I have no idea what the difference is between DUO1, DUO2, etc. through DUO73. I feel like they should have a better way to clarify which users are affected.
> Increased load on DUO1 due to significantly increased adoption and simultaneous peak usage across multiple larger customers led to authentication failures.
tech solutions in the field tend to be incredibly low risk given the size and make-up of the anticipated users (enterprise services with thousands of employees and tens of thousands of students). For public institutions, there's the added element of public sector risk avoidance.
Shibboleth is kind of an outlier here, due to its age/maturity and position as a very old-school piece of foundational tech that got implemented when academic IT salaries were quite a bit easier to live on than they are today.
The disparity between tech salaries in academic institutions and FAANG/SaaS corps has grown immensely in the past 20 years. Most of the people who do the real work at academic institutions have been employed there for 25-40 years. Most of the young people can't stick around for long because they need to earn more money to build a stable life.
Duo has positioned itself as an industry leader in MFA and is one of the safe bets when implementing that feature.
This isn’t exclusive to schools, either.
Not a super productive morning