With the introduction of additional associations and research organizations (e.g., FIDO: https://fidoalliance.org/) focused on negating the need for passwords, one might ask if they are going away.
The answer is no, not really. Password-based credentials will still be around, especially within enterprises, for years to come. Especially for legacy systems, and administrative access.
With that said, business-to-consumer (B2C) authentication for enterprises will morph considerably, as it already has. And for that matter, so has business-to-business (B2B) authentication with PKI / x.509 certificate-based authentication for point-to-point VPN / RESTful API.
So, compensating controls in the way of conditional access (CA), multi-factor authentication (MFA: biometrics, OTP, voice, security challenge / questions), etc. will take the lead in identity verification, but passwords will be around for a long time.
Showing posts with label MFA. Show all posts
Showing posts with label MFA. Show all posts
Tuesday, December 6, 2016
Are passwords going away?
Labels:
API,
B2B,
B2C,
biometrics,
conditional access,
FIDO,
MFA,
OTP,
password,
PKI,
REST,
security questions,
voice,
VPN,
x.509
Monday, November 21, 2016
Identity & Access Management (IAM / IdAM) Programs
IAM / IdAM / Single Sign-On (SSO) / Privileged Access Management (PAM) / Multi-Factor Authentication (MFA) / Identity Providers (IdP) / Identity Federation are all part of a program that enterprises should focus on these days. And, these programs need to be able to extend to multiple technologies: cloud, mobile, IoT, ERP, etc.
However, these endeavors are treated as one-offs.
As organizations wrestle with business transactions (merges, acquisitions, divestitures), the need to have a formal, organized IAM / IdAM program grows in need.
However, these endeavors are treated as one-offs.
As organizations wrestle with business transactions (merges, acquisitions, divestitures), the need to have a formal, organized IAM / IdAM program grows in need.
Subscribe to:
Posts (Atom)