Many orgs leverage crypto to verify software / firmware / patches / updates; however, many do not leverage integrity safeguards on the versioning of those platforms.
Checksums and other compensating controls should be utilized to ensure the stability of the platform in question. Such methods would negate the rogue installation of software / firmware.
Showing posts with label PKI. Show all posts
Showing posts with label PKI. Show all posts
Sunday, March 19, 2017
Thursday, January 5, 2017
Integrated Crypto (e.g., TDE, DDM) vs Enterprise Crypto / PKI
While it may be convenient to deploy integrated crypto / PKI solutions for sensitive data stores (e.g., PII, ePHI, PKI) via TDE / DDM, more and more data leaves local databases and / data stores & goes to the cloud.
This is where an enterprise PKI solution will help organizations. With holistic solutions, a tokenized, sensitive data element can proliferate / travel through the cloud or w/in an enterprise while still protected.
While expensive, highly visible, and risky, these endeavors will truly protect an organization from data breach / loss, etc.
This is where an enterprise PKI solution will help organizations. With holistic solutions, a tokenized, sensitive data element can proliferate / travel through the cloud or w/in an enterprise while still protected.
While expensive, highly visible, and risky, these endeavors will truly protect an organization from data breach / loss, etc.
Tuesday, December 6, 2016
Are passwords going away?
With the introduction of additional associations and research organizations (e.g., FIDO: https://fidoalliance.org/) focused on negating the need for passwords, one might ask if they are going away.
The answer is no, not really. Password-based credentials will still be around, especially within enterprises, for years to come. Especially for legacy systems, and administrative access.
With that said, business-to-consumer (B2C) authentication for enterprises will morph considerably, as it already has. And for that matter, so has business-to-business (B2B) authentication with PKI / x.509 certificate-based authentication for point-to-point VPN / RESTful API.
So, compensating controls in the way of conditional access (CA), multi-factor authentication (MFA: biometrics, OTP, voice, security challenge / questions), etc. will take the lead in identity verification, but passwords will be around for a long time.
The answer is no, not really. Password-based credentials will still be around, especially within enterprises, for years to come. Especially for legacy systems, and administrative access.
With that said, business-to-consumer (B2C) authentication for enterprises will morph considerably, as it already has. And for that matter, so has business-to-business (B2B) authentication with PKI / x.509 certificate-based authentication for point-to-point VPN / RESTful API.
So, compensating controls in the way of conditional access (CA), multi-factor authentication (MFA: biometrics, OTP, voice, security challenge / questions), etc. will take the lead in identity verification, but passwords will be around for a long time.
Labels:
API,
B2B,
B2C,
biometrics,
conditional access,
FIDO,
MFA,
OTP,
password,
PKI,
REST,
security questions,
voice,
VPN,
x.509
Subscribe to:
Posts (Atom)