Personal tools
You are here: Home wikidblog Schneier clarifies his stance on two-factor authentication
« August 2008 »
Mo Tu We Th Fr Sa Su
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Recent comments
Re:Security and Oil admin Apr 25, 2008
Re:Security and Oil Paul feet Apr 24, 2008
Re:100% open source admin Apr 22, 2008
Re:100% open source Adam Apr 22, 2008
Re:Capital Gains Tax Rates and Entrepreneurs Lance Oct 23, 2007
 

Schneier clarifies his stance on two-factor authentication

Bruce Schneier posted a clarification on his stance regarding two-factor authentication today.

Two-factor authentication is a long-overdue solution to the problem of passwords. I welcome its increasing popularity, but identity theft and bank fraud are not results of password problems; they stem from poorly authenticated transactions. The sooner people realize that, the sooner they'll stop advocating stronger authentication measures and the sooner security will actually improve.

Again, he's missing a couple of points.

  • First, it is simple to use strong authentication to authenticate transactions as well as sessions.
  • Second, some strong authentication systems, such as our strong authentication system can combat the "non-authentication" attacks Schneier describes. For example, the WiKID two-factor client will not generate a valid passcode if the DNS system is poisoned. We are working on extending WiKID in other ways as well.
  • The URL to Trackback this entry is:
    http://www.wikidsystems.com/WiKIDBlog/26/tbping

    Re:Schneier clarifies his stance on two-factor authentication

    Posted by admin at Mar 22, 2007 08:17 AM
    testing on opera/linux - 2-factor authentication anonymous as a captcha

    Re:Schneier clarifies his stance on two-factor authentication

    Posted by admin at Mar 22, 2007 08:17 AM
    testing two-factor authentication as a captcha.
    Add comment

    You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

    (Required)
    (Required)
    (Required)
    (Required)
    This helps us prevent automated spamming.