{"id":978,"date":"2020-10-23T15:24:13","date_gmt":"2020-10-23T19:24:13","guid":{"rendered":"https:\/\/increasec.com\/?p=978"},"modified":"2023-09-13T09:16:59","modified_gmt":"2023-09-13T13:16:59","slug":"cheap-2fa-hardware-tokens-for-duo","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=978","title":{"rendered":"Cheap 2FA Hardware Tokens for DUO"},"content":{"rendered":"\n<p>I have tested some cheap Multi-Factor Authentication hardware tokens with DUO security.   Duo is easy to setup with Microsoft RdWeb remote desktop gateway.<\/p>\n\n\n\n<p>These are the tokens i tested  $15 ca  each,  made out of metal so their nice and sturdy to attach to your keychain.<br>https:\/\/www.amazon.ca\/gp\/product\/B07T7SPMJB\/ref=ox_sc_act_title_1?smid=A2IPV56ZW8WL51&amp;psc=1<br><\/p>\n\n\n\n<p>The software to initialize the tokens is here  <br>https:\/\/www.hypersecu.com\/downloads<br><a rel=\"noreferrer noopener\" href=\"http:\/\/hypersecu.company\/downloads\/files\/software\/HyperFIDOPro_HOTP_Seed_Generator.zip\" target=\"_blank\">HyperFIDO Pro HOTP Seed Generator (Ver. 1.0)&nbsp;<\/a><br>(the 2nd download is for Titanium tokens)<br>I ran the software through <a href=\"https:\/\/www.virustotal.com\/gui\/\">VirusTotal <\/a>and it didn&#8217;t set off alarms.<\/p>\n\n\n\n<p>decompress and run the software as administrator<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"858\" height=\"505\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-2.png\" alt=\"\" class=\"wp-image-980\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-2.png 858w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-2-300x177.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-2-768x452.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-2-710x418.png 710w\" sizes=\"auto, (max-width: 858px) 100vw, 858px\" \/><\/figure>\n\n\n\n<p><strong>Before <\/strong>you plug the hardware token in, type the serial #, written on the side of the token, into the &#8220;Key Serial Number&#8221; box<br>Plug the hardware token in to a USB port (Duh), it should get detected in the top window pane<br>if you click &#8220;Check Key&#8221; the program will verify the token is writeable<br>Now click &#8220;Generate Seed&#8221;<br>With the Token plugged in, click the &#8220;Program&#8221; button<br>You will need to <strong>Push the Button <\/strong>on the token or programming will fail.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"413\" height=\"215\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-6.png\" alt=\"\" class=\"wp-image-987\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-6.png 413w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-6-300x156.png 300w\" sizes=\"auto, (max-width: 413px) 100vw, 413px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"226\" height=\"154\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-7.png\" alt=\"\" class=\"wp-image-989\"\/><\/figure>\n\n\n\n<p>Copy the Key Serial # and the Seed and paste them somewhere safe&#8230; like a LastPass encrypted note.  You did setup LastPass, right?<\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"335\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-3-1024x335.png\" alt=\"\" class=\"wp-image-981\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-3-1024x335.png 1024w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-3-300x98.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-3-768x251.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-3-710x232.png 710w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-3.png 1391w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Sign into your DUO cloud admin panel and goto 2FA Devices, Hardware Tokens.<br>click Import Hardware Tokens<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1009\" height=\"823\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-4.png\" alt=\"\" class=\"wp-image-982\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-4.png 1009w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-4-300x245.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-4-768x626.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-4-710x579.png 710w\" sizes=\"auto, (max-width: 1009px) 100vw, 1009px\" \/><\/figure>\n\n\n\n<p>In the &#8220;CSV token data&#8221; box enter your token serial#, a comma, and the generated key.  You can do this for a dozen tokens at once.   Hit the &#8220;Import Hardware Tokens&#8221; button<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"359\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-9-1024x359.png\" alt=\"\" class=\"wp-image-992\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-9-1024x359.png 1024w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-9-300x105.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-9-768x269.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-9-710x249.png 710w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-9.png 1243w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>We can now click on the Token serial number and link the token to a user<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"437\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-10-1024x437.png\" alt=\"\" class=\"wp-image-993\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-10-1024x437.png 1024w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-10-300x128.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-10-768x327.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-10-710x303.png 710w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-10.png 1262w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Verify that your Global Policy (or sub policy if you have one) has Hardware tokens enabled<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"868\" height=\"763\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-11.png\" alt=\"\" class=\"wp-image-994\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-11.png 868w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-11-300x264.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-11-768x675.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-11-710x624.png 710w\" sizes=\"auto, (max-width: 868px) 100vw, 868px\" \/><\/figure>\n\n\n\n<p>Now to test<\/p>\n\n\n\n<p>When we logon to the RdWeb server we are asked first to pick a device if the user has multiple auth methods.   We will pick Token from the drop-down.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"780\" height=\"293\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-12.png\" alt=\"\" class=\"wp-image-996\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-12.png 780w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-12-300x113.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-12-768x288.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-12-710x267.png 710w\" sizes=\"auto, (max-width: 780px) 100vw, 780px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"786\" height=\"296\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-14.png\" alt=\"\" class=\"wp-image-998\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-14.png 786w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-14-300x113.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-14-768x289.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-14-710x267.png 710w\" sizes=\"auto, (max-width: 786px) 100vw, 786px\" \/><figcaption class=\"wp-element-caption\">We need to click &#8220;Enter a Passcode&#8221;<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"789\" height=\"255\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-15.png\" alt=\"\" class=\"wp-image-999\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-15.png 789w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-15-300x97.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-15-768x248.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-15-710x229.png 710w\" sizes=\"auto, (max-width: 789px) 100vw, 789px\" \/><figcaption class=\"wp-element-caption\">Click in the text box so the cursor is in the right place (ex. 867539)<\/figcaption><\/figure>\n\n\n\n<p>The token is like a keyboard with 1 key, so the cursor needs to be in the text box, ready to receive the text.<\/p>\n\n\n\n<p>Push the button on the token and it should fill the text box with 6 digits<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"791\" height=\"222\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-16.png\" alt=\"\" class=\"wp-image-1000\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-16.png 791w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-16-300x84.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-16-768x216.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2020\/10\/image-16-710x199.png 710w\" sizes=\"auto, (max-width: 791px) 100vw, 791px\" \/><\/figure>\n\n\n\n<p>and finally click &#8220;Log In&#8221; to proceed to RdWeb.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Info on how to set these up with M$ Exchange Online  but I haven&#8217;t tested this yet.     https:\/\/www.hypersecu.com\/fido2-microsoft<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>A list of services that work with Fido u2f   https:\/\/www.dongleauth.info\/#software<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Update: been using this for a few months now.  Works well with Microsoft Azure\/WhateverTheyCallItThisMonth.  If you are plugging+unplugging the device every day it does ask for a PIN # 1\/day.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"462\" height=\"327\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/09\/image-3.png\" alt=\"\" class=\"wp-image-2661\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/09\/image-3.png 462w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/09\/image-3-300x212.png 300w\" sizes=\"auto, (max-width: 462px) 100vw, 462px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>I have tested some cheap Multi-Factor Authentication hardware tokens with DUO security. Duo is easy to setup with Microsoft RdWeb remote desktop gateway. These are the tokens i tested $15&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[16,143,144,19],"class_list":["post-978","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-2fa","tag-duo","tag-mfa","tag-rdweb"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/978","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=978"}],"version-history":[{"count":13,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/978\/revisions"}],"predecessor-version":[{"id":2662,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/978\/revisions\/2662"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=978"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=978"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=978"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}