mmm this poses an interesting question: what if a defendant/suspect cannot remember the password? Does anyone know if there is any comparable precedent regarding forgetting things?
yes, the steps detailed in the post are likely not enough to evade being caught if a large intel agency is looking for a leaker. it very probably will be enough to prevent detection before the materials are published, but not necessarily afterwards when authorities start looking for a leaker.
"A species is often defined as the largest group of organisms in which two individuals can produce fertile offspring, typically by sexual reproduction."[1]
As far as I know there is no evidence that neanderthal females could produce fertile offspring with a male homo sapiens -- but only the other way round.
They can send push requests that you can just approve on your mobile device, no typing in those codes. They also have backup methods that work w/o needing internet access on your phone.
I think institutions also use Duo because Duo takes care of the whole think whereas traditional 2FA isn't trivial to implement for the institution (generating tokens and all of that). At least that's what I was told by my institution when they made us start using Duo.
Duo does work as advertised, and my uni uses it, but the privacy policy allows for a lot of personal data collection.
tldr: "Duo Security does not sell, rent, or trade and, except as described in this Privacy Policy, does not share any Personal Information with third parties for their promotional purposes." But Duo still collects A LOT of data on you.
From the policy:
"Device-Specific Information: We also collect device-specific information (e.g. mobile and desktop) from you in order to provide the Services. Device-specific information includes:
attributes (e.g. hardware model, operating system, web browser version, as well as unique device identifiers and characteristics (such as, whether your device is “jailbroken,” whether you have a screen lock in place and whether your device has full disk encryption enabled));
connection information (e.g. name of your mobile operator or ISP, browser type, language and time zone, and mobile phone number); and
device locations (e.g. internet protocol addresses and Wi-Fi).
We may need to associate your device-specific information with your Personal Information on a periodic basis in order to confirm you as a user and to check the security on your device."
The policy continues to state that Duo may use this data for analytic/advertising purposes (although only in-house) as well as to comply with legal requests, subpoenas, NSLs etc.
Duo isn't collecting your data for nefarious purposes or to sell it to other companies but they still are collecting A LOT of it. Other two factor methods, like the one's used by Google and Facebook, allow clients to install their own code generators that don't collect personal data or even need access to the internet. Of course these methods don't have push requests that you can just approve rather than type in the code.