Latest News
Higher education faces unique security challenges right now and you, as part of the Cornell community, have the opportunity and responsibility to thwart the attacks that relentlessly target Cornell’s IT defenses on a daily basis by doing one simple thing: protect your NetID from hackers.
You might say to yourself I’m at Cornell! Nobody gets hacked here! The reality is that in 2025 over 1,500 people had their NetIDs hacked. You haven’t heard about it because the security office takes privacy as seriously as identity protection. (And be honest - do you think a colleague will confess that they clicked on a phishing link in a staff meeting?)
Let’s review three options for keeping your NetID in your hands, not someone else’s.
🥉 Passwords + Duo 🥉
The minimal protection you must choose, but also the one hackers target most effectively. To make this option secure, you need to focus on two important areas: first create a strong password, and second be smartly vigilant about your logins.
The vulnerability in this option lies in you, which is why hackers successfully stole 1,500 NetIDs in 2025. Clever social engineering schemes can trick you out of handing over your password and Duo code before you realize it. For this security option, you have to work at hard-to-remember passwords, you have to triple-check that “email from the dean,” you have to deal with an avalanche of Duo requests. Work, work, work.
Avoid a NetID disaster: use these tips to harden your password and look out for these social engineering techniques that hackers use to trick your Duo code out of you.
🥈Passphrase + Duo 🥈
The recent requirement for 16-character passwords wasn’t arbitrarily created to annoy everyone: the longer a password is, the harder it is for hackers to break. Using modern technology a hacker can “brute force” an 8-character password almost instantly. By the time a hacker attempts the same approach with a 16-character password, your great, great, great grandchildren will have already retired.
Thus the recommendation for you to create a passphrase — a combination of words unique to you, that you can easily remember, and that still give you a rock-solid password. Possibly the best part about using a passphrase at Cornell: you don’t need to include numbers or &pec!@| characters. Just having 16 characters protects you significantly!
Once again, though, the vulnerability lies with you: those online memes to “share your favorite x, y, and z” sometimes disguise ways for hackers to guess what you may have used for your passphrase. Or they might trick you into typing it in yourself. You still need to keep a weather eye out for phishing attempts, and fake websites asking you to log in.
🥇Secure Connect Passkey - aka passwordless login 🥇
The strongest protection you can use at Cornell is a Secure Connect passkey. Passkey technology lets faculty and staff use TouchID or Windows Hello (your device's PIN or password if you don't have biometrics), instead of your NetID and password, to access anything using CUWebLogin at Cornell.
Without going into too much technical detail Secure Connect passkeys live in your device, not in the cloud, which means only you can unlock your account, and you can’t accidentally give away your passkey. The only way someone could use your passkey is if you allowed them access your device while you’re logged in. (University Policy 4.12 has a few stern words to say about that kind of a misstep.)
If you don’t like the thought of using your face or fingerprint with a passkey, consider this. Biometrics are so safe, that hackers aren’t afraid to use them to try and set up a passkey in your name if you don’t! They know that thanks to the magic of math once you have a biometric (face or fingerprint) stored, no one can re-create it.
Once you switch to using a passkey to log in, your chances of losing access to your NetID plummet by a factor of several hundred. Remember that 1,500 hacked NetIDs from the first paragraph? In that same time period only 1 person with a registered passkey had their NetID compromised. (Until the university moves entirely to passkeys, hackers can still trick you by attacking you through a password/Duo route.)
Cornell provides strong security tools, but they’re only as good as you - the person using them. Which will you choose: the bronze, silver, or gold option of NetID security?
Comments?
To share feedback about this page or request support, log in with your NetID