[Dave Birch] A discussion that I was in earlier today reminded about a point made earlier in the year. I was discussing the idea of using software in mobile phones instead of bank-provided “tokens”. It’s superficially very attractive, but it needs the operators to get on board. And then service providers, such as banks, may not want to use it because they don’t want someone else in between them and their customers. While the mobile phone with a SIM is an excellent repository for phishing-resistant credentials, the fact the mobile operators control access to the SIM (and often severely restrict that access) turns many people off. On the other hand, if the mobile phone were to be used as part of a standard open authentication scheme — so if the operator doesn’t play ball, banks (or whoever) had plenty of choice of alternative tokens — then that’s not so much of a barrier. With the continued progress of OATH (who we’ve spoken to before) in making interoperable authentication practical, this scenario isn’t particular far-fetched if there’s a convenient way of implementing OATH in the phone.
Technorati Tags: identity, mobile
These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.