TwistedHelixis Posted November 21, 2016 Posted November 21, 2016 Do any other schools use u2f keys for the 2 step authentication in G Suite? We are a small primary school and I wondered how easy they are to manage from an admin perspective, What happens if a key gets damaged etc. Also who would be a good make / company to purchase these from in the UK? Thanks
limawhiskey Posted November 21, 2016 Posted November 21, 2016 (edited) For staff or student accounts? Personally I can't see the need to have them, with options for OTPs by SMS, via the authenticator app, or the new option to have a notification pop up on your android device (Google prompt). As for damaged keys, the individual would use another 2-Step Verification method to log in, remove the damaged/lost key and register the new one. You shouldn't have to do any administration other than create a help guide and keep a stock of keys. Worst case is you'd need to recover a backup key for the individual: Troubleshoot 2-Step Verification - G Suite Administrator Help If your user has lost their phone and doesn't have their backup code' date=' you can obtain a backup code for them via: [b']Admin console > Users > (select user) > Security > Show backup verification codes[/b] Edited November 21, 2016 by limawhiskey
TwistedHelixis Posted November 22, 2016 Author Posted November 22, 2016 Personally I can't see the need to have them, with options for OTPs by SMS, via the authenticator app, or the new option to have a notification pop up on your android device (Google prompt). That would be fine but the school does not allow personal devices and has not purchased any mobile devices for the staff, and even if they used their own phones we have absolutely no signal.
pete Posted November 22, 2016 Posted November 22, 2016 ^ You don't need a network connection for Google authenticator to work. It's the same as an RSA fob in that respect.
TwistedHelixis Posted November 22, 2016 Author Posted November 22, 2016 Also I was just thinking, if we used a mobile device with the authenticator app installed, I would need to make sure that the device was also very secure, just in case it got stolen or lost, which is another layer of my time taken up, something I don't have at this primary school.
TwistedHelixis Posted November 22, 2016 Author Posted November 22, 2016 You don't need a network connection for Google authenticator to work. It's the same as an RSA fob in that respect. Good point, thanks.
limawhiskey Posted November 22, 2016 Posted November 22, 2016 That would be fine but the school does not allow personal devices and has not purchased any mobile devices for the staff, and even if they used their own phones we have absolutely no signal.You didn't let me finish, I was about to say: unless you have a policy that disallows personal devices, no devices provided for staff and no mobile coverage, in which case the U2F key would be perfect for you I would need to make sure that the device was also very secureI don't see why - an insecure device would be about as secure as a U2F key; you're only using it to access/generate the OTP.
TwistedHelixis Posted November 22, 2016 Author Posted November 22, 2016 I don't see why - an insecure device would be about as secure as a U2F key; you're only using it to access/generate the OTP. What I am thinking is, if someone found a phone and managed to log in they would have the accounts and 2 form auth to access those accounts all in one handy place with all the users details, if someone found a U2F key on the floor there is no way to know what account it is linked with and so is useless.
pete Posted November 22, 2016 Posted November 22, 2016 (edited) ^ I think @limawhiskey and I were treating the phone as the second factor to a laptop/desktop/whatever. Instead of being used itself to directly access Google accounts. Based on your "we don't allow personal devices" assertion. Plus, people are more likely to notice (and report, or at least whine about) losing a phone. Edited November 22, 2016 by pete
TwistedHelixis Posted December 6, 2016 Author Posted December 6, 2016 Ordered some test keys and have a problem. In order to access the 2 step setup pages in Google security it asks for a phone number so it can either text or call the number with a security number prior to setting up the u2f key. Problem is my test teacher is not near a landline phone and the school does not let the staff bring in a mobile. I could take the test teacher to the main office and set everything up but I don't want to do this for every member of staff. So I have a u2f key that I can't use with the account. Any ideas?
pete Posted December 6, 2016 Posted December 6, 2016 ^ I think you'll find the same issue for more 2FA setups - you'll be asked for a get-out-of-jail option should said 2FA key/phone/whatever get dropped down the toilet. Either setup near a phone or discuss making the "no personal devices" policy a bit more granular (say, OK in the staff room, not OK anywhere else). 1
TwistedHelixis Posted December 6, 2016 Author Posted December 6, 2016 Thanks for the info / advice. I assume that as the G Suite admin I can go in and disable or change 2 factor auth for any user accounts should the f2a key get dropped down the toilet anyway. Would be handy if it had a tick box, 'Allow admin to reset security if needed' or something similar.
Arthur Posted December 6, 2016 Posted December 6, 2016 Problem is my test teacher is not near a landline phone and the school does not let the staff bring in a mobile. I could take the test teacher to the main office and set everything up but I don't want to do this for every member of staff. I have successfully setup Google's 2FA with a free virtual mobile number from RWG Mobile. https://bayton.org/2016/07/using-rwg-mobile-for-simple-cross-device-centralised-voicemail/ (just follow steps 1-4) Once the U2F key has been added to the teacher's Google account you can remove the virtual phone number since it becomes the alternative second step after adding the U2F key. 1
TwistedHelixis Posted December 6, 2016 Author Posted December 6, 2016 Brilliant, Ill have a play. THANKS.
TwistedHelixis Posted January 13, 2017 Author Posted January 13, 2017 So over Christmas I took over another primary school and all the staff use personal phones (Android and iphone) to access their gmail accounts. In this setup would you use the text method, Authenticator app or Google push / prompt method? I was thinking it would be easier to use the text method as it would be easier to get the staff to do it themselves. I was trying out the Authenticator app on an iphone but it would not let me login to the email on the iphone but I could loin on a desktop computer using the code generated on the iphone, I believe its something to do with ios being older than 8.3. Google mention setting up a one time app password for 2 step on older iphone devices, has anyone done this? Cheers
mayoper Posted May 23, 2017 Posted May 23, 2017 The original question posted asked for suggested UK suppliers - while Yubico keys are heavily promoted there a some cheaper alternatives at conform to the same FIDO standard from Hypersecu, Feitian and Key-ID. Key-ID is UK based, and offers discount pricing for quantities of 10 and above. 1
mavhc Posted May 23, 2017 Posted May 23, 2017 So over Christmas I took over another primary school and all the staff use personal phones (Android and iphone) to access their gmail accounts. In this setup would you use the text method, Authenticator app or Google push / prompt method? I was thinking it would be easier to use the text method as it would be easier to get the staff to do it themselves. I was trying out the Authenticator app on an iphone but it would not let me login to the email on the iphone but I could loin on a desktop computer using the code generated on the iphone, I believe its something to do with ios being older than 8.3. Google mention setting up a one time app password for 2 step on older iphone devices, has anyone done this? Cheers Don't use SMS as it's insecure. I'd use Google Authenticator with the push method, code as backup. Programs that don't support 2 factor login can be assigned unique passwords, but I'd just install the gmail app for iphone. If staff are using their own phones you can still enforce a pin code with the device policy app. 2 factor reduces your attack surface from the whole world to the 5 m^2 around you
caffrey Posted July 26, 2017 Posted July 26, 2017 I'm tempted to set this up for staff, been a few phishing attempts lately and it worries me, especially how lax the staff are with passwords Recent update to Google Apps may make this even easier https://gsuiteupdates.googleblog.com/2017/07/making-two-step-verification-deployment-easier.html 1
Arthur Posted July 26, 2017 Posted July 26, 2017 Recent update to Google Apps may make this even easier From your link... Security key enrollment improvements are available to all G Suite Enterprise edition domains
caffrey Posted July 26, 2017 Posted July 26, 2017 That's a shame, maybe it'll be coming to education soon
caffrey Posted March 25, 2018 Posted March 25, 2018 Seems like it is https://gsuiteupdates.googleblog.com/2018/03/manage-security-keys.html
AlanD Posted March 25, 2018 Posted March 25, 2018 So over Christmas I took over another primary school and all the staff use personal phones (Android and iphone) to access their gmail accounts. ...Are these gamil accounts - school gmail accounts.....if they are personal phones....how are you going to wipe them if lost to ensure there is no school data on them?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now