Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Duo's two factor auth can be bypassed by someone with access to Duo's systems. This is interesting... why?


Use the source, Luke: https://github.com/duosecurity/duo_unix/blob/master/lib/duo....

Authorization is done by making a POST request to a Duo-controlled server. If the response is the string "allow", it lets you in; if it's "deny", it doesn't. Duo can make that server return whatever they want.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: