Click here to close now.

Welcome!

Web 2.0 Authors: Peter Silva, Forrest Small, Pat Romanski, Elizabeth White, Alena Prokharchyk

Blog Feed Post

Authentication - An Update

Ian Kilpatrick, chairman Wick Hill Group, looks at the current state of authentication and examines the solutions on offer from two companies in Gartner's Magic Quadrant.

123456. Amazingly, surveys show that this is the most popular password for authentication. And simple passwords are still the most used authentication method. However, popularity, in this case, just doesn't equate with success.

Security breaches are becoming a daily occurrence and high profile companies such as Yahoo, Target and Tesco are just some of the famous names amongst the victims of password theft.

Recently, on a Netherlands server, researchers discovered compromised credentials for more than 93,000 websites, including 318,000 Facebook accounts, 70,000 Gmail, Google+ and YouTube accounts, 60,000 Yahoo accounts, 22,000 Twitter accounts and 8,000 LinkedIn accounts.

However, instances like these represent just a fraction of the organisations suffering from password theft. The majority do not publicise the fact, as there is no requirement to notify anyone, nor have they been publicly 'outed.'

So we have a long established way of doing things, that is proven on a daily basis to be inadequate and insecure, yet the majority of companies still use it. How long will this state of affairs last? Will we see another decade of consistent, repetitive authentication failures?

Probably not, because the Darwin principle applies. Those affected by password theft will either come up to the mark, and improve their authentication, or decline and go out of business.

Moreover, strong authentication is on a high growth curve, driven by the multiple waves of change rolling across organisations, both small and large.

Recent developments in computing have led to increasingly fractured and distributed networks, which are harder to protect.

These developments include the growth of mobile computing, remote access, tablets, smartphones and BYOD, together with the increasing popularity of wireless, the cloud, virtualisation and social networking. Alongside this, there has been a rapid growth of data, meaning there is even more to protect than ever before.

Authentication is the most basic step towards protecting networks and while passwords still have a role, that role is increasingly as part of a multi-factor authentication process.

Other forces driving the move towards strong authentication include the increasing pressures on companies to achieve security compliance, with the consequences of failure including hefty ICO fines and possible reputational damage.

Greater press coverage of computer security failures, such as the insecurity of mobiles devices and smartphones, has also had an effect, creating more visibility of the problems.

Authentication types - benefits and disadvantages
Getting the right kind of authentication needs careful thought. A key question is "Is the authentication method something that staff can use relatively easily?" Get something too complicated and you could have problems.

Another key issue is using the right level of authentication. Do you need different levels for different staff, for different applications, for different departments? Is your authentication method flexible enough to cope with that? Broadly speaking, users are looking for authentication methods that provide the best combination of ease-of-use, security, and, of course, cost. Currently, the main options are:

  • weak single-factor authentication (passwords)
  • strong complex passwords, usually with a minimum of characters, including special characters, and recommended to be regularly changed
  • strong two-factor authentication (passwords + something else, such as a token)
  • strong three-factor authentication (passwords + something else, such as a soft token + a mobile phone).

Weak single factor authentication (passwords)
This is the use of single static passwords, still the most common form of authentication and used by most organisations. However, companies are increasingly aware that even if they continue with passwords for part of their workforce, there are employee types such as power workers, knowledge workers, mobile workers and remote workers, where proof of identity is important.

Any password system not collecting and storing passwords in a secure (encrypted) format is fundamentally vulnerable.

Encrypted passwords
While encrypted passwords are more secure than simple passwords, and superficially secure, they are actually at risk of attack by various methods, such as brute force attacks, dictionary attacks and rainbow tables.

Strong complex passwords
That's what many of us use to access our secure online areas and are used in companies to overcome the disadvantages of weak passwords. They need to be not only strong, and typically including special characters or numbers, but also different for different applications, and changed regularly.

Strong complex passwords, when encrypted, are significantly less vulnerable to rainbow tables and similar methods. They are however vulnerable, as many users employ the same passwords for social and online sites as for their business.

Strong authentication
Strong authentication involves one of a range of elements such as hardware tokens, soft tokens, fingerprint recognition, swipe cards and phone as a token, or phone as a recipient of a soft token. Most strong authentication deployments are used together with passwords (two-factor authentication).

Strong two-factor authentication
Strong two factor authentication is a much more secure means of authenticating users onto networks, as it requires two separate security elements.

It comprises something you know (a password) and something you have, e.g. a token, which generates a one-time password (OTP) or a fingerprint. Software and hardware tokens are currently the most popular two-factor solutions, due to their low cost, ease- of-deployment, ease-of-management and the standard of security they provide.

According to Gartner*, hardware tokens still have the largest installed base of any method (70%). In the last few years, however, there has been a move towards the deployment of other types of tokens, including mobile phones, and hardware USBs, such as SafeStick or Ironkey.

The rapid fall in the price of tokens means they are now available from only a few pounds per user per year. That is less than the cost of ONE password-related helpdesk call, so tokens can represent a major cost-saving, as well as an improvement in security.

Strong three factor authentication
This is far superior and involves something you know (e.g. password), something you have (e.g. authentication token) and something you are (e.g. fingerprint, retinal scan, facial recognition). While biometric authentication is obviously more costly and complicated to use, it is appropriate for high security applications/departments such as pharmaceutical R&D, finance, etc.

Trends
Contextual authentication
Contextual authentication is growing, but not yet mainstream. It uses contextual information (such as users' behaviour patterns) to decide whether a user is genuine. It can improve on the use of a password, without the need for traditional two factor strong authentication.

Mobile devices can play a significant role in contextual authentication. They can capture relevant contextual information such as tapping rhythm, voice recognition, facial contours, and iris details.

A strategic view
A growing trend amongst enterprises is to take a more strategic view of authentication. Companies are acknowledging they may need different levels of authentication for different scenarios, different users and different applications. They are looking for one flexible authentication method which can facilitate these different levels. Currently, however, most enterprises and SMEs still tend to use a single authentication method.

The Cloud
The popularity of the cloud should be noted, with researchers predicting that by year-end 2016, about 30% of enterprises will choose cloud-based services as their delivery option for new or refreshed user authentication implementations - up from about 10% today.

Mobile devices
Smartphones and mobile devices are playing a growing part in the authentication scenario. They are already widely used as authentication tokens; they function as fairly powerful computers and are an endpoint in themselves, so need protecting; and they can be used for biometric and contextual authentication.

Two authentication market leaders
Two of the leaders in Gartner's Magic Quadrant for User Authentication* are VASCO and SafeNet.

VASCO
VASCO is a well-known name in authentication and has one of the widest ranges of authentication methods currently available. The company is very strong in the financial sector, government, enterprises and e-commerce, with solutions for companies from SMEs up to the largest enterprises.

Gartner* says VASCO has a "very strong position in this market" and calls the company "a very strong innovator."

Authentication platforms include IDENTIKEY (server software), IDENTIKEY Virtual Appliance, IDENTIKEY Appliance (a hardware appliance), IDENTIKEY Federation Server (a higher end server appliance), DIGIPASS as a Service (private cloud service), and MYDIGIPASS.COM (public cloud service).

IDENTIKEY Server
This is an authentication software suite for organisations of all sizes, with centralised user management, web-based administration, multi-platform support and enhanced reporting features. It verifies authentication requests and centrally administers user authentication policies.

IDENTIKEY Appliance
This is a standalone authentication appliance that secures remote access to corporate networks and web-based applications. It can be used in an unlimited number of applications across a variety of fields, such as online applications, banking applications, enterprise security and remote access.

SMEs
One solution for small businesses from VASCO is DIGIPASS Pack for Remote Authentication. This is an out-of-the-box solution which combines all necessary hardware and software to provide a high level of security to organisations with limited resources and budgets.

Authentication tokens
VASCO offers a very wide range of authentication tokens, with the brand name DIGIPASS, including DIGIPASS Software, DIGIPASS Hardware and DIGIPASS Readers

Go to http://www.wickhill.com/products/vendors/detail/27/Vasco for further information and case studies.

SAFENET
Gartner* says that SafeNet "demonstrated a very sound market understanding, as well as very strong product strategy and innovation." Gartner also says "SafeNet has a strong position in this market…"

SafeNet itself says it has a vision to make two-factor authentication universally available and that it provides inexpensive, easy-to-use, innovative solutions to a large range of clients, worldwide. Clients are in business, government and non-profit organisations.

SafeNet solutions include:
SafeNet Authentication Service
An SaaS (software-as-a service) based authentication platform. This solution comes in four types: a cloud-based service for enterprises, a cloud service for service providers, an onsite solution for enterprises, and an onsite solution for service providers.

It has been designed, says SafeNet, to make two-factor authentication easy to implement and manage. Features include a comprehensive degree of automation to drastically reduce the cost of management, administration, tokens that do not expire and a comprehensive self-service portal that allows users to carry out many functions that would traditionally only have been resolved by the help desk.

SafeNet authentication tokens
SafeNet supports a very broad range of authentication methods and form factors including: OTP hardware and software tokens, OOB, hybrid tokens and phone tokens for all mobile platforms. SafeNet's authentication platform supports a wide variety of 3rd party tokens, such as those from RSA.

Go to http://www.wickhill.com/products/vendors/detail/16/SafeNet for further info and case studies.

ENDS

* Gartner Magic Quadrant for User Authentication, December 2013. Analyst Ant Allan.

Source: RealWire

Read the original blog entry...

More Stories By RealWire News Distribution

RealWire is a global news release distribution service specialising in the online media. The RealWire approach focuses on delivering relevant content to the receivers of our client's news releases. As we know that it is only through delivering relevance, that influence can ever be achieved.

@ThingsExpo Stories
SYS-CON Events announced today that B2Cloud, a provider of enterprise resource planning software, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. B2cloud develops the software you need. They have the ideal tools to help you work with your clients. B2Cloud’s main solutions include AGIS – ERP, CLOHC, AGIS – Invoice, and IZUM
The Internet of Things Maturity Model (IoTMM) is a qualitative method to gauge the growth and increasing impact of IoT capabilities in an IT environment from both a business and technology perspective. In his session at @ThingsExpo, Tony Shan will first scan the IoT landscape and investigate the major challenges and barriers. The key areas of consideration are identified to get started with IoT journey. He will then pinpoint the need of a tool for effective IoT adoption and implementation, which leads to IoTMM in which five maturity levels are defined: Advanced, Dynamic, Optimized, Primitive,...
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo in Silicon Valley. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 17th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The Internet of Things (IoT) is the most profound change in personal an...
There is no doubt that Big Data is here and getting bigger every day. Building a Big Data infrastructure today is no easy task. There are an enormous number of choices for database engines and technologies. To make things even more challenging, requirements are getting more sophisticated, and the standard paradigm of supporting historical analytics queries is often just one facet of what is needed. As Big Data growth continues, organizations are demanding real-time access to data, allowing immediate and actionable interpretation of events as they happen. Another aspect concerns how to deliver ...
Enterprise IoT is an exciting and chaotic space with a lot of potential to transform how the enterprise resources are managed. In his session at @ThingsExpo, Hari Srinivasan, Sr Product Manager at Cisco, will describe the challenges in enabling mass adoption of IoT, and share perspectives and insights on architectures/standards/protocols that are necessary to build a healthy ecosystem and lay the foundation to for a wide variety of exciting IoT use cases in the years to come.
The world's leading Cloud event, Cloud Expo has launched Microservices Journal on the SYS-CON.com portal, featuring over 19,000 original articles, news stories, features, and blog entries. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. Microservices Journal offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. Follow new article posts on Twitter at @MicroservicesE
Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities. Accordingly, attendees at the upcoming 16th Cloud Expo at the Javits Center in New York June 9-11 will find fresh new content in a new track called PaaS | Containers & Microservices Containers are not being considered for the first time by the cloud community, but a current era of re-consideration has pushed them to the top of the cloud agenda. With the launch of Docker's initial release in March of 2013, interest was revved up several notches. Then late last...
So I guess we’ve officially entered a new era of lean and mean. I say this with the announcement of Ubuntu Snappy Core, “designed for lightweight cloud container hosts running Docker and for smart devices,” according to Canonical. “Snappy Ubuntu Core is the smallest Ubuntu available, designed for security and efficiency in devices or on the cloud.” This first version of Snappy Ubuntu Core features secure app containment and Docker 1.6 (1.5 in main release), is available on public clouds, and for ARM and x86 devices on several IoT boards. It’s a Trend! This announcement comes just as...
WebRTC defines no default signaling protocol, causing fragmentation between WebRTC silos. SIP and XMPP provide possibilities, but come with considerable complexity and are not designed for use in a web environment. In his session at @ThingsExpo, Matthew Hodgson, technical co-founder of the Matrix.org, discussed how Matrix is a new non-profit Open Source Project that defines both a new HTTP-based standard for VoIP & IM signaling and provides reference implementations.
The security devil is always in the details of the attack: the ones you've endured, the ones you prepare yourself to fend off, and the ones that, you fear, will catch you completely unaware and defenseless. The Internet of Things (IoT) is nothing if not an endless proliferation of details. It's the vision of a world in which continuous Internet connectivity and addressability is embedded into a growing range of human artifacts, into the natural world, and even into our smartphones, appliances, and physical persons. In the IoT vision, every new "thing" - sensor, actuator, data source, data con...
It's time to put the "Thing" back in IoT. Whether it’s drones, robots, self-driving cars, ... There are multiple incredible examples of the power of IoT nowadays that are shadowed by announcements of yet another twist on statistics, databases, .... Sorry, I meant, Big Data(TM), tiered storage(TM), complex systems(TM), smart nations(TM), .... In his session at WebRTC Summit, Dr Alex Gouaillard, CTO and Co-Founder of Temasys, will discuss the concrete, cool, examples of IoT already happening today, and how mixing all those different sources of visual and audio input can make your life happier ...
The Internet of Things is not new. Historically, smart businesses have used its basic concept of leveraging data to drive better decision making and have capitalized on those insights to realize additional revenue opportunities. So, what has changed to make the Internet of Things one of the hottest topics in tech? In his session at @ThingsExpo, Chris Gray, Director, Embedded and Internet of Things, discussed the underlying factors that are driving the economics of intelligent systems. Discover how hardware commoditization, the ubiquitous nature of connectivity, and the emergence of Big Data a...
SYS-CON Events announced today the IoT Bootcamp – Jumpstart Your IoT Strategy, being held June 9–10, 2015, in conjunction with 16th Cloud Expo and Internet of @ThingsExpo at the Javits Center in New York City. This is your chance to jumpstart your IoT strategy. Combined with real-world scenarios and use cases, the IoT Bootcamp is not just based on presentations but includes hands-on demos and walkthroughs. We will introduce you to a variety of Do-It-Yourself IoT platforms including Arduino, Raspberry Pi, BeagleBone, Spark and Intel Edison. You will also get an overview of cloud technologies s...
SYS-CON Media announced today that @WebRTCSummit Blog, the largest WebRTC resource in the world, has been launched. @WebRTCSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. @WebRTCSummit Blog can be bookmarked ▸ Here @WebRTCSummit conference site can be bookmarked ▸ Here
Scott Jenson leads a project called The Physical Web within the Chrome team at Google. Project members are working to take the scalability and openness of the web and use it to talk to the exponentially exploding range of smart devices. Nearly every company today working on the IoT comes up with the same basic solution: use my server and you'll be fine. But if we really believe there will be trillions of these devices, that just can't scale. We need a system that is open a scalable and by using the URL as a basic building block, we open this up and get the same resilience that the web enjoys.
Avnet, Inc. has announced that it ranked No. 4 on the InformationWeek Elite 100 – a list of the top business technology innovators in the U.S. Avnet was recognized for the development of an innovative cloud-based training system that serves as the foundation for Avnet Academy – the company’s education and training organization focused on technical training around top IT vendor technologies. The development of this system allowed Avnet to quickly expand its IT-related training capabilities around the world, while creating a new service that Avnet and its IT solution providers can offer to their...
The WebRTC Summit 2015 New York, to be held June 9-11, 2015, at the Javits Center in New York, NY, announces that its Call for Papers is open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 16th International Cloud Expo, @ThingsExpo, Big Data Expo, and DevOps Summit.
Chuck Piluso will present a study of cloud adoption trends and the power and flexibility of IBM Power and Pureflex cloud solutions. Speaker Bio: Prior to Data Storage Corporation (DSC), Mr. Piluso founded North American Telecommunication Corporation, a facilities-based Competitive Local Exchange Carrier licensed by the Public Service Commission in 10 states, serving as the company's chairman and president from 1997 to 2000. Between 1990 and 1997, Mr. Piluso served as chairman & founder of International Telecommunications Corporation, a facilities-based international carrier licensed by t...
There are lots of challenges in IoT around secure, scalable and business friendly infrastructure for enterprises. For large corporations, IoT implementations are one of the top priorities of the decade. All industries are seeing a competitive need to sustain by investing in IoT initiatives. The value addition comes from improved customer service, innovative product and additional revenue streams. The data from these IP-connected devices can be leveraged for a variety of business applications as well as responsive action controls. The various architectural building blocks of an IoT ...
Recent technology advances in miniaturization has positioned the wearables as the pinnacle of technology convergence with the human body. We inquire if wearables are mere standard miniaturized devices extended with the connectivity and present our views on considerations like design, applications, performance, efficiency, interoperability, usage scenarios, human device interaction and consequent trade-offs enabling wearables to impart optimal value.