How to Deploy Two-Factor Authentication

Joel Snyder, Mar 08, 2013
Commentary by Stephen Downes
files/images/password-mobile-security-300.png

We're reading more recently about something called 'two factor authentication'. Here's the concept: "This technique combines a password with something else the user has, such as a token, smart card or a biometric identifier." The 'gold standard' of two factor authentication is the token - a card, signet ring, or some other item that can't be easily duplicated. Google has been trying to use the mobile phone number to generate the second factor - but this depends on people having a mobile phone (and an account in good standing), and they have to not mind surrendering this form of identification to Google. I think we may be moving eventually to some sort of encrypted USB key, at least for online authentication, much like the client certificate created in your browser by StartSSL and similar companies. Unlike your mobile phone number, it won't be directly connected to the credit bureau or marketing department. But unlike passwords, it can't be cracked. In any event, we'll have to do something, as the best-before date for password technology has long since passed.

Views: 0 today, 106 total (since January 1, 2017).[Direct Link]
Creative Commons License. gRSShopper

Copyright 2015 Stephen Downes ~ Contact: stephen@downes.ca
This page generated by gRSShopper.
Last Updated: Dec 12, 2017 12:50 p.m.