Assurance Enhancements for IdPv2

Cantor, Scott cantor.2 at osu.edu
Tue May 21 15:17:39 EDT 2013


> I don't claim to understand the RFP very well but a multi-stage
> approach to authentication seems to be essential.

>From a design point of view, I agree. From a deployment point of view, I couldn't disagree more. A MFA solution that requires people to glue together unrelated systems to get multiple factors is just an incomplete solution.

I couldn't believe what I was reading when I started looking into things like OATH and realized that people are just building stand-alone OTP systems that have be glued back to a second password database by the deployer. That's just asking for security holes, especially when you accommodate all the different places you may need to integrate it.

There's a lot of bad about SecurID, but they sure got that part right. One system, two factors.

-- Scott




More information about the dev mailing list