Assurance Enhancements for IdPv2

Tom Scavo trscavo at gmail.com
Tue May 21 17:05:57 EDT 2013


[if this gets off-topic, let me know and take it off line]

On Tue, May 21, 2013 at 3:17 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> I don't claim to understand the RFP very well but a multi-stage
>> approach to authentication seems to be essential.
>
> From a design point of view, I agree. From a deployment point of view, I couldn't disagree more.

Are you saying a solution that is difficult to deploy is probably
gonna get deployed incorrectly? Of course that's true. It's even true
of passwords alone.

> A MFA solution that requires people to glue together unrelated systems to get multiple factors is just an incomplete solution.

Incomplete in what way? Do you mean there's a higher probability the
solution is deployed incorrectly? Maybe. Otoh, a solution that
utilizes two independent channels is usually preferred to one that
doesn't, so it cuts both ways.

> I couldn't believe what I was reading when I started looking into things like OATH and realized that people are just building stand-alone OTP systems that have be glued back to a second password database by the deployer. That's just asking for security holes, especially when you accommodate all the different places you may need to integrate it.

I'm not sure I understand the point you're trying to make. You seem to
be saying that some people deploy OATH incorrectly (which is true) but
I can't be sure. You're not saying that deploying OATH as a second
factor on top of an existing password-based authentication system is
inherently flawed, are you?

Tom


More information about the dev mailing list