Personal tools
You are here: Home wikidblog More on Layered Authentication
« August 2008 »
Mo Tu We Th Fr Sa Su
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Recent comments
Re:Security and Oil admin Apr 25, 2008
Re:Security and Oil Paul feet Apr 24, 2008
Re:100% open source admin Apr 22, 2008
Re:100% open source Adam Apr 22, 2008
Re:Capital Gains Tax Rates and Entrepreneurs Lance Oct 23, 2007
 

More on Layered Authentication

Ok, I slagged the concept of 'layered' authentication as a marketing neologism in my response to Eric Nolan's identity predictions for 2006. I was overcome by prediction hysteria. I've got to calm down...

Here's the problem with most of the pitches I have seen for "layered authentication". Let's start with an actual pitch:

"Moving beyond the two-factor or multifactor authentication solutions available in the market today, the multi-layered approach provides a stronger form of authentication without compromising the online banking experience for end users. In addition to a user name and password, Intelligent Authentication leverages multiple patterns of online banking behavior and attributes of the online banking user to determine when it is necessary to block or challenge suspicious visitors."

I have a few problems with this:

1. "Moving beyond..." Let's judge the strength of the solution based on it's relative security. To break this security, all you need to do is a MITM replay attack, use a session hijacking trojan and/or know the user's challenge information. This really hasn't moved beyond.

2. What value is here? It's easy to log IP address, plant cookies, etc. I hope this is a free service. It's also easy to know which transactions are suspicious - the ones where money leaves an account.

3. A large number of users will absolutely hate this. They delete cookies, use WiFi in weird places and use multiple computers. They also have lots of money.

To me, layered authentication means session, host/mutual and transaction authentication. I think authentication needs to be consistent and involve the user. Using tools like cookies, which rely on DNS and are hidden from the user, aren't optimal solutions.



The URL to Trackback this entry is:
http://www.wikidsystems.com/WiKIDBlog/88/tbping
Add comment

You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

(Required)
(Required)
(Required)
(Required)
This helps us prevent automated spamming.