Security breaches prompt new multi-factor authentication requirement for university-run websites

By Luke Gentile

The University of Maryland’s Division of Information Technology has set Oct. 15 as the date that all university-run websites will require students to use its new multi-factor authentication (MFA).

After the “go-live” date, anyone accessing resources including ELMS, Testudo, MyDRL, MyUHC, Terrapin Express and library services will have to provide a second form of verification.

This will require users to download an app called Duo Mobile, which students will use when logging on. Users will receive an alert saying their account has been activated, and can then enter a password in the app or respond to the push notification directly.

Kevin Shivers, the assistant director of IT security, said the change has come in the wake of serious security breaches that have occurred over the past few years.

“We’ve seen a lot of cases where accounts have been compromised,” he said. “We’ve had cases where someone learned the password of their professors and went in and attempted to change their grade. We’ve also seen where a person, usually former a boyfriend, girlfriend or ex-roommate, knows someone’s password, and they go on into Testudo and drop all their classes.”

In addition to academic security issues, Shivers also said there has been great concern regarding students’ financial aid going to the right place.

“Students have had their direct deposit information changed for either their scholarship information or their student refund, and the money has been redirected into someone else’s account,” he said.

In response to the breaches, the IT division developed the new system to verify the user’s identity. Once users are registered, they will only have to verify once a day, Shivers said.

Although this extra step sounds simple, the new changes have not gone over well with all UMD students, as additional challenges arise for certain students once they introduce MFA to their accounts.

Eli Crognale, a junior sociology major and member of the varsity men’s soccer team, said the new MFA is a necessary but irritating change.

“I don’t like it because it changed up how the athletes get their grades to their advisors,” he said. “Now, we have to go in and print out our grades and bring them to the advisors weekly. They used to be able to check them online.”

Crognale said that although he has never felt threatened by a security breach, he has heard of some serious cases.

“I’ve heard of past incidents where people have gotten onto student emails and their grades when they aren’t the student themselves,” he said. “So, from a hacking perspective, I think it is very important to protect the students.”

John Sittmann, a fifth-year graduate student studying microbiology, said the only concern he has is for students who don’t have a cell phone capable of downloading the app.

“It’s not too bad,” Sittmann said of using MFA. “I have had minor issues when my connectivity isn’t too good, and I don’t get the push. Also, if I’m in a particular hurry, it’s a little frustrating having to do the extra steps.”

Shivers said he personally has not heard of any complaints and thinks a little apprehension is normal for new systems.

“Folks are usually concerned about systems being inconvenient and worrying that they will have a lot of hassles,” he said. “Then the ‘go-live’ date comes and people get pretty used to it. I’ve been doing this for two years, and that is the process.”

Leave a Reply