Skip to content. | Skip to navigation

Authentication: The token question

Added:
Nov 30, 2005

Identity and access management (I&AM) has never been such a hot topic around the boardroom table.  With widespread reports of identity theft and misuse of online identities, concerns about the security and privacy of doing business online and increased pressure on organisations to meet compliance regulations, all indicate a shift in the role of security.  It is now paramount for businesses to find secure, efficient and flexible ways to manage user identities and access privileges but with a wealth of options to choose from, finding the best security solution can be a challenge.

 

Password Protection

 

The password has long been relied upon to secure corporate information because it is cost effective, easy to use and secure.  In fact 60 per cent of security professionals and IT managers use single passwords as their only form of user authentication according to research conducted for RSA Security.

 

However, as businesses protect more and more applications with individual passwords, employees find themselves with four or five different codes to remember and every forgotten password leads to time-consuming calls to the helpdesk. 

 

One solution is to use directory management to format all existing user identities into a single identity and password, through which a user can access multiple applications.  Using this form of centralised identity management, it is easier to automate and enforce secure password practices consistently across the workforce.  Employees simply need to be encouraged to create strong passwords incorporating non-alpha-numeric characters, change their passwords on a regular basis and by requiring them to only memorise one strong password, there are far less calls to the help desk.

 

Strong Authentication

 

But no matter how much time is invested in educating employees on password protection, a single password alone is no match for the latest hacking tools that use brute force and exhaustive dictionary techniques to test possible password combinations.

 

With this in mind, many organisations have looked to stronger authentication methods to secure their applications, requiring employees to present multiple forms of identification such as passwords and PINs, a token or smart card or even biometrics that are unique to the individual such as retinal or fingerprint scans.

 

HSBC and Lloyds TSB are just two large organisations that have turned to token authentication to protect their online applications.  30,000 TSB customers have been given a key-ring sized device that generates a unique number which the customer must enter in order to log into their account.  This obviously overcomes the problem of remembering a password but this form of strong authentication can often prove expensive, difficult to manage and a source of frustration for end-users.  Which explains why relatively few banks with online facilities are following the same route.

 

Instead, many banks and other organisations considering strong authentication, prefer an approach that balances both security and usability by using passwords and PINs.  The user is familiar with this method and where the traditional password is not strong enough to fend off today’s hackers, clever techniques are now employed to increase security through the way in which the password is entered with sophisticated back-end systems to detect system abuse.

 

The password – not so passé

 

Strong security is a must in today’s business and consumer environments, but this has to be tempered with ease of use.  The password has been around since the dawn of computing, which means every user is familiar with the concept. Perhaps this is why many businesses continue to use it - concentrating efforts on improving the security around the mechanisms used to distribute and protect passwords, rather than reinventing the wheel with new authentication concepts that are often both costly and difficult to use.

 

Encryption and prompts for specific password character sequences prevent both interception and eavesdropping of passwords and more complex authentication systems are constantly being introduced which generate time-limited or one-time-use passwords that minimise the possibility of ‘the bad guys’ stealing and re-using passwords. 

 

The password, it seems, is here to stay.

 

Document Actions
Subscribe to Netimperative Newsletters

Email address:


Daily
Weekly
Search Marketing
Events
Publishing & Media

Send as:
Text
HTML

Alternatively, click here to unsubscribe

Digital Training Academy
Digital Training Academy
Essential skills for today's marketers: boost your team's results with customised advanced digital marketing coaching from world class trainers at the Academy.
Mail our academy managers Ask our tutors for more
Full details here...
Digital marketing audits
Digital Training Academy

Getting the best ROI from your websites, emails and online ads? Sure?

Our digital marketing audits review your current and planned campaigns to find ways of cutting budgets without cutting impacts.

Mail our academy managers Ask for more
Full details here...
 
Digital events
Latest polls
Mobile ad networks
Apple's iAds Vs Google's AdMob- which do you think will be most succesful in the long term?



Votes : 114
Comment
Right to reply: The New Twitter – a sticky, revenue-rich service that blitzes the third-party apps
Twitter is now a 'destination website' and that means it is gunning for Facebook, but cleverly avoiding a direct dogfight. It’s more an information network than a social network and so is offering much, much more. Tanya Goodin, CEO of search and social conversion agency Tamar comments…
Sep 16, 2010
Right to reply: ‘Instant Search’– Google giveth then taketh away
Google has just announced its “streaming search” service, Google Instant, is coming out of limited Beta testing and going live for all users. According to Adam Bunn, Head of Search at leading independent search and social marketing agency Greenlight, when it comes to search engine optimisation campaigns (SEO), some websites may now suffer a drop in traffic.
Sep 10, 2010
Guest comment: No rival to the SMS text exists in the market today
SMS is the obvious “lowest common denominator” mobile marketing solution... yet critics still talk about apps and website and vouchers. Darren Daws, Managing Director at Txtlocal argues why SMS is still the best mobile marketing medium, even on smartphones.
Aug 04, 2010
All subject items…