What is DUO? A Q&A with UA’s Chief Information Security Officer

This semester, the Office of Information Technology introduced a new tool to further protect the sensitive data held in myBama accounts: DUO.

DUO is a two-factor authentication program that adds a second layer of security to a user’s myBama account. It’s a relatively new concept for many UA students, faculty and staff.  UA’s Chief Information Security Officer Ashley Ewing answers some frequently-asked questions to give the campus a better understanding of DUO.

What is DUO?
DUO is a two-factor authentication program that adds another layer of security to your myBama account.

How does it work?
DUO’s two factors are based on something you know — your username and password — and then something you have: your smartphone. Once DUO is installed, you will login to your myBama account as you normally would, and then see the DUO prompt. From that prompt, you can then tell DUO to send a notification to your smartphone. Open the notification on your phone, check the green box, and then you’re in. The entire process takes less than three seconds.

There are many other notification options such as a phone call or passcodes; however, most users find the smartphone notification the easiest.

Why does UA need this?
Passwords are simply not enough to protect sensitive data. Users do not change their passwords as often as they should, they use the same password for multiple accounts, and their passwords are not strong. DUO is the answer to all of these problems. With DUO, a hacker would have to have your username, password and smartphone to get into your account.

Is it hard to use?
DUO is easy to use and takes about 30 seconds to install. Once installed, it takes about three seconds to use.

Who can use DUO?
DUO is available to UA students, faculty and staff.

Is it required?
At this time, DUO is not required, although it is strongly encouraged. Cyber security threats are getting more sophisticated, and phishing emails are getting harder to detect. It’s crucial that we do everything in our power to protect ourselves against malicious actors on the web.

How do I get started?
Visit www.duo.ua.edu and follow the prompts to activate your account. If you have any questions about DUO, check out our website.