Skip to main content

Phishing-Resistant MFA

What does “phishing-resistant MFA” mean?

“Phishing-resistant MFA” refers to multi-factor authentication (MFA) that’s designed to keep working even if someone tries to trick you with a fake website or message. It helps protect against common phishing tactics such as lookalike websites and “adversary-in-the-middle” attacks.

What are my phishing-resistant options for logging in?

  • Most phishing-resistant: Passkeys, hardware security keys, and biometrics on mobile devices 
  • Strong, but vulnerable to phishing: Authenticator apps and push notifications with number matching, such as Duo Mobile and Duo Verified Push 
  • Less secure: Moderate and weak forms of two-factor authentication, including push notifications without number matching, SMS codes, and voice calls 
  • Not secure: A login that only requires a password, without a second factor

 

Security Key (YubiKey) Basics

What is a security key or YubiKey?

A security key is a small physical device that you can connect to your computer or mobile device to use as a form of multi-factor authentication (MFA). Security keys connect to your device via a USB port or using Near Field Communication (NFC) and provide better protection against phishing attacks than other two-factor options. YubiKey is one brand of security key.

Do I have to use a security key?

Some applications or access levels may require the use of a security key. Contact your local IT support provider for more information. If you would like to maintain a high security posture, a security key or other form of passkey is recommended.

How do I get a security key?

Faculty and staff may be able to obtain a security key through their school or center. Personal purchases should take place through a trusted retailer. Contact your local IT support provider for more information.

How do I register my security key to my PennKey account?

Use ISC's Security Key (YubiKey) Enrollment Instructions to register one or more security keys to your PennKey account.

Are there any limitations to using security keys?

Yes, there are a few limitations. Not every application may support the use of a YubiKey or other security key. Additionally, use of security keys requires you are physically present at the computer you are using—they will not work for remote sessions such as RDP or virtual desktops.

Can I register more than one security key?

Yes, it is recommended that you register more than one security key so you have backup options. Remember that you need to have your security key with you in order to use it, so leaving it at home could result in being unable to access required systems.

Does a security key need to remain in the USB port the entire time, or can it be removed after I log in?

A security key does not need to stay plugged in after you log in. However, if you are using a small security key such as the YubiKey Nano, it’s recommended that you leave it in your device to avoid losing it.

Will a security key work on my mobile device?

Yes, but you need to be mindful of available ports on your device. Many security keys use USB-C connections and will work with adapters. Some keys offer Near Field Communication (NFC) technology, which doesn’t require a physical connection, but your device needs to be capable of receiving NFC transmissions. The use of NFC may be impacted by your phone case or where you place the key on the device. You may need to experiment for the key to work correctly.

Will a security key work when I'm traveling internationally?

Security keys will function while traveling internationally. Travel has its own risks and implications for data security. Please refer to ISC's guidance on Data Security on Foreign Travel and work with your local IT support provider to make sure your devices and data are secure and in compliance with any travel restrictions.

Do I need to set a PIN on my security key? What if I forget my PIN?

You should set a PIN/password on any sensitive device to protect against theft or other unauthorized access. If you are having trouble with your PIN, do not try using it too many times or you run the risk of resetting or wiping the key.  Seek assistance from your local IT support provider.

I have more questions about using a security key. Who should I ask?


 

Troubleshooting Security Keys

Do all applications work with security keys?

There have been issues with applications that use an embedded browser which doesn’t support YubiKey. Possible solutions are to use a native browser for authentication instead. Another alternative may be to use other available authentication methods such as Duo Push.

When I try to log in, I see an error reading "Couldn't use security key." What does this mean?

A screenshot of an error message that reads: Couldn't use security key. Your login request using your security key was canceled or timed out. Make sure your are using a security key that requires a PIN or fingerprint. Two buttons are shown at the bottom of the screenshot: Show other options, or Try Again.

You may see this message when the application or resource you are accessing doesn’t support your security key. If your security key has a PIN or supports fingerprints, try again.  If that doesn’t work, try the “Show other options” link and use an alternate verification method such as Duo Push.

What happens if I lose my security key?

Registering multiple two-factor methods to your PennKey account allows you to continue to work if one of your methods fails (e.g., a lost security key). If your security key is lost or damaged, log in to the Duo Device Management Portal using one of your backup devices and remove the lost key from your account. If you are unable to log in, contact your local IT support provider or PennKey Support.