Duo idpv3.1
Randy Wiemer
wiemerr at hotmail.com
Wed Mar 18 13:30:08 EDT 2015
I have integrated both SecureID and the PhoneFactor technology Microsoft bought with applications and I disagree with your description and characterizations. These things are more alike than they are different. On the dimensions I care most about - security, flexibility, ease of use, cost - I rank the PhoneFactor model above what RSA provides.
Randy
> From: cantor.2 at osu.edu
> To: users at shibboleth.net
> Subject: Re: Duo idpv3.1
> Date: Wed, 18 Mar 2015 17:06:41 +0000
>
> On 3/18/15, 12:50 PM, "Randy Wiemer" <wiemerr at hotmail.com> wrote:
>
> >Help me understand why you distinguish a series of dependent sequential authentications from multi-factor authentication.
>
> Because the only thing connecting those sequential steps is a separate piece of code unrelated to the actual solutions that is imposing an association around the steps. By themselves, they are not sequential anything, they're discrete.
>
> >
> >I think DUO and Microsoft's MFA solutions are better than RSA SecureID and similar products because they use a separate communication channel.
>
> I think neither is itself such a solution. They have one channel. The application is turning them into two or three. Whether that's better or worse given the need to keep supporting passwords, for example, is a subjective question, but my point wasn't whether a deployment of the whole mess would be MFA, it's whether the single technology is by itself. I just think it's apples and oranges, and I think it's done for marketing and FUD reasons, not technical accuracy.
>
> >
> >I think all three approaches qualify as strong, multi-factor authentication technologies but you seem to disagree.
>
> I think only SecurID is itself such a technology in its own right. The others are SFA building blocks. I think it's relevant that SecurID works with zero extra effort with just about any IdP-like thing, and the others don't. That has value to me, particularly when I'm not the only one who's going to end up doing the integration. It's fine for me to cobble together separate solutions, but asking lots of people on my campus to is a different thing.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150318/336c966e/attachment.html
More information about the users
mailing list