Home

Duo Security Advances Two-Factor Authentication

Comments | Max Cherney, BYTE | June 05, 2012 08:00 AM

Category: Tablets, Smartphones

After his pitch at a recent juried technology competition in Silicon Valley, CEO Dug Song of Duo Security handed a business card to two of the three judges. The third judge said he'd already traded cards with Song the night before at a networking event. That's how excited the Valley was to hear about Duo's token-less two-factor authentication technology, and it's no surprise the company took home the judge's choice award for mobile access.

Duo's token-less--really two-factor authentication via mobile device--was on BYTE's radar back in February. But evidently, everyone's excited about it. The reason: mobile devices make two-factor authentication technology possible to deploy easily at low cost. Doing so eliminates "... the high cost of provisioning, replacing, revoking, and managing physical tokens [that] has been a barrier to widespread implementation," Matt Sarrel of BYTE wrote.

Dug Song of Duo Security presenting at Under The Radar, introduced by TechWeb's David Berlind.

As Sarrel explains in the article, most two-factor mobile authentication technologies use a call, SMS message, or application to verify a login attempt with the user. Duo's technology is different largely because it's versatile. System administrators can deliver Duo's authentication via smart phones, standard cell phones, land lines, and existing hardware tokens, the company claims. If users do not have reception when they need the key, the company says users can ask the system to generate one-time passcodes deliverable via SMS prior to needing the code. Users also can generate one-time passcodes with Duo's mobile app.

Duo Security offers a wide variety of notification methods for the second factor. The company built free apps for Android, Blackberry, and iPhone.

Duo's service looks relatively expensive. Rates start at $3 per user per month, and drop with volume above 500 users. Compared with the competition mentioned in BYTE's February article, at the 100-user mark, that's expensive. For example, for 100 licenses Trustwave charges $1,417 per year, according to the company website, versus Duo's rate of $3600. PhoneFactor doesn't list pricing information on its website but a company representative said 100 licenses would average about $2,500 a year, depending on the features selected by the client.

An impressive claim Duo made at the competition is that its clients credentials are more secure than RSA's. "Even if we were to be breached," CEO Song said, "There'd be no way to for an attacker to go and impersonate all the clients, all the end users, because they don't have the private key that's actually on the user's phone." The technology uses a patented system that combines public and private encryption and prevents sharing secrets, he said.

The claim was in response to the judge's question about the widely reported heist on RSA's data centers last March. RSA reported the breach cost $66 million in restitution to clients. For the firms using RSA's two-factor authentication technology, it was a mess to clean up. For example, CRN.com reported that, "... Lockheed [Martin] had to shut down its computer systems and reissue tokens to many of its employees, while requiring a password reset for its 120,000 workers."

A demo of Duo Security's software.

Duo also is interesting investors. Steve Coplan of 451 Research wrote in a recent report that Duo looks a lot like its competitors, until you dig deeper. "... Duo is moving toward shaking up the market with some fairly radical ideas." Google Ventures led a funding round in February that included True Ventures, and Resonant Venture Partners. The trio gave Duo $5 million in funding.

Max A. Cherney is a Contributing Editor for BYTE. Follow Max A. Cherney and BYTE on Twitter and Google+:



Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events