Contact

Press & Communication

+49 (0) 441 798-5446

More

IT services of the university

Contact us

IT Service Desk

+49 441 798-5555

  • In the background, a laptop on which the website of an online shop can be seen indistinctly, in the foreground a hand holding a mobile phone on which an encrypted password has been entered.

    Many online services already use two-factor authentication. For example, a query via an app on a mobile phone or a security token offer additional security. At the university, different solutions are provided for employees and students. AdobeStock / khunkornStudio

More security for the university network

Two-factor authentication will soon be introduced at the university - a necessary step to protect computer systems from unwanted intruders.

Two-factor authentication will soon be introduced at the university - a necessary step to protect computer systems from unwanted intruders.

25 February 2023 was not a good day for the University of Oldenburg. Attackers were able to hack several of the university's user accounts via phishing emails. The criminals used emails to trick employees into entering their passwords on fake websites. The hackers used the stolen access data to send further fraudulent emails. They circulated a total of more than 80,000 spam emails that day and the following day. As a result, the university ended up on several blacklists. Many servers automatically blocked emails ending with "uni-oldenburg.de". It took several days before it was possible to send emails again without any problems.

Another massive hacker attack that hit the university in the summer of last year showed that such attacks are not isolated incidents, but an expression of an ongoing threat. The IT experts only managed to fend off the attack with great effort and expertise. "Overall, we have got off relatively lightly so far," says Thorsten Kamp, who is responsible for security in the Data Protection and Information Security Unit. In theory, attackers who have hacked an account could cause a lot more damage. This is because the access data enables them to access all systems and servers for which the respective account has authorisation. In recent years, several universities have been paralysed for months in this way. The attackers encrypted data, blocked systems and made extortionate demands for money. "In many cases, it started with phishing emails," says Kamp.

To prevent accounts from being taken over by phishing in future, the Presidential Board has decided to introduce two-factor authentication. The large-scale IT project was launched at the beginning of March. "In future, when you log in to a system such as webmail, your ID and password will no longer be enough; you will need a second factor to prove your identity," explains project leader Ulrich Czernik. He is responsible for managing the user accounts of university members at IT services.

A work tool like an office key

Many people are probably already familiar with the principle behind this from online banking or other digital services: Where accounts are already protected by two-factor authentication, you usually end up at another barrier after entering your usual password. For example, you have to use an app, a stick or a biometric feature to confirm that you are the real owner of the account. "This prevents unauthorised persons from gaining access to data or functions simply because they are in possession of the password," says Czernik.

At the university, the second factor for all employees will be a so-called security token - either a kind of USB stick that you insert into your computer or a contactless transponder that you have to hold up to your tablet or smartphone when you want to start working. "Basically, this security token is just as much a work tool as an office key," says Czernik. A different solution is planned for students and guests of the university: They should be able to identify themselves using special software - an app on their mobile phone. "The combination of the two factors provides significantly greater protection against misuse," emphasises Czernik. The process is now state of the art.

However, the university's IT experts still have a lot to do before the project can get underway. At the kick-off meeting at the beginning of March, all project participants were brought on board - including representatives of the Divisions and Schools. The next step is to define the future authentication system in detail with the help of a consultancy firm.

Pilot tests in a special test environment

Pilot tests in a special test environment will then take place in the summer. The first systems to be converted are the webmail and VPN applications as well as the platforms konto.uol.de and pw.uol.de, which users can use to change their personal settings. "The VPN tunnel is particularly important because it can be used to connect to the campus network from outside," explains the project leader. At the same time, the IT services have to make some major technical changes to the system architecture in the background: Some services and systems that are currently organised as isolated solutions are to be converted to a central system. "In addition, we first have to make some older systems technically capable of accepting the second factor," reports Czernik. If everything goes according to plan, the new access method could be introduced step by step from autumn or winter.

The aim of the project team is to establish a solid standard that is as fail-safe as possible and at the same time make it as easy and convenient as possible for users - so that logging on to the computer remains as simple as unlocking a lock.

This might also be of interest to you:

Autumn, Hermann Lietz School, aerial view
Photo: National Park House Wittbülten Spiekeroog gGmbH
Campus Life University workplace

Researching and living in the middle of the Wadden Sea

The Wittbülten research centre on Spiekeroog offers seminar rooms, laboratories and flats for university members. The offer is aimed at all…

more: Researching and living in the middle of the Wadden Sea
Hands on a keyboard, next to it is a personal file in paper form
University of Oldenburg / Daniel Schmidt
Digitisation Campus Life University workplace

The end of the paper file

The digitalisation of administration at the university has taken an important step forward: the first e-file has been launched with the personnel…

more: The end of the paper file
Close-up of a tablet. Two hands are visible, the left hand is holding the tablet, the right hand is holding a special pen with which something is being entered on the screen.
University of Oldenburg / Daniel Schmidt
Digitisation Top News University workplace

The human factor

Digitalisation is changing many activities in administration. A Lower Saxony-wide Centre of Excellence coordinated in Oldenburg is to support the…

more: The human factor
(Changed: 12 May 2026)  Kurz-URL:Shortlink: https://uol.de/p82n9397en
Zum Seitananfang scrollen Scroll to the top of the page

This page contains automatically translated content.