Two-factor authentication hysteria continues!
Two-factor authentication completely fails to bring peace to middle-east
As I predicted, the hysteria around the , well, hysteria in the information security blogosphere, which is a pretty small part of the blogosphere.
As I discussed before, this is a failure of mutual authentication not two-factor authentication. Here are some the headlines:
- Fraudsters defeat two-factor authentication
- Phishers rip into two-factor authentication Phishers crack two-factor authentication
On the other hand, and sadly in the minority, zencoder has it right: Pundits Blaming 2-Factor Authentication…Again
you can’t use 2-factor authentication to protect a telnet session and expect it to be valid hosts guaranteed on both ends…telnet doesn’t have that sort of capability built into the protocol; but that’s not a problem with the 2-factor auth.
Security Curve, is also on the right track transaction authentication to make financial services acceptably secure online.
I think we do as much of a disservice to the Internet community when we inaccurately blame technology as when we inaccurately promote it as a silver bullet.
- The URL to Trackback this entry is:
- http://www.wikidsystems.com/WiKIDBlog/two-factor-authentication-hysteria-continues/tbping


Digg this!
Del.ico.us
Google
Yahoo bookmarks
Reddit
Spurl
Simpy

The only people I have seen arguing in favor of 2-factor authentication are the people trying to sell it to someone, and it is mistakenly (whether innocently or not I can't say) being sold as the end-all solution to online fraud and identity theft, which it definitely is not.
Anonymous != authentication. Authentication != anonymous. Next question?
Authenticating that a PERSON, and not a bot/script/process/spider is receiving the text...ok, I can see that argument. But as in InfoSec practitioner, I call bullsh!t on that position. It's NOT AUTHENTICATION. It's categorization of the user, perhaps; Validation of a biological interaction. But it can be ANY HUMAN...or any smarter-than-the-state-of-Captcha bot-script, too. However, we dont know which person/ip/computer, so it's not authenticated. Perhaps I'm splitting hairs.
Mutual Authentication is the bone we need to pick with this hysteria. I'm really dissapointed that Bruce S. uses the terminology and headline in this way. He is supposed to be smarter than that. Maybe it was an intentional blunder, to stir the controversy and discussion.