Assurance Enhancements for IdPv2
Tom Scavo
trscavo at gmail.com
Tue May 21 17:05:57 EDT 2013
[if this gets off-topic, let me know and take it off line]
On Tue, May 21, 2013 at 3:17 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> I don't claim to understand the RFP very well but a multi-stage
>> approach to authentication seems to be essential.
>
> From a design point of view, I agree. From a deployment point of view, I couldn't disagree more.
Are you saying a solution that is difficult to deploy is probably
gonna get deployed incorrectly? Of course that's true. It's even true
of passwords alone.
> A MFA solution that requires people to glue together unrelated systems to get multiple factors is just an incomplete solution.
Incomplete in what way? Do you mean there's a higher probability the
solution is deployed incorrectly? Maybe. Otoh, a solution that
utilizes two independent channels is usually preferred to one that
doesn't, so it cuts both ways.
> I couldn't believe what I was reading when I started looking into things like OATH and realized that people are just building stand-alone OTP systems that have be glued back to a second password database by the deployer. That's just asking for security holes, especially when you accommodate all the different places you may need to integrate it.
I'm not sure I understand the point you're trying to make. You seem to
be saying that some people deploy OATH incorrectly (which is true) but
I can't be sure. You're not saying that deploying OATH as a second
factor on top of an existing password-based authentication system is
inherently flawed, are you?
Tom
More information about the dev
mailing list