Comments on: Cloudy, chance of rain http://tomorrowstransactions.com/2013/09/cloudy-chance-of-rain/ Thought leadership from Consult Hyperion Tue, 09 Sep 2014 00:19:19 +0000 hourly 1 http://wordpress.org/?v=4.0 By: Alexander Peschkoff http://tomorrowstransactions.com/2013/09/cloudy-chance-of-rain/#comment-48 Tue, 01 Oct 2013 06:29:33 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/09/cloudy-chance-of-rain/#comment-48 As you said it yourself, Dave, who is the trusted party? LinkedIn and your profile? What if I obtained your LI login credentials?..

IMHO, it should be out-of-bound 2FA, involving a smartphone (yes, I know that it’s not socially inclusive, and that’s a good point in some cases…) – the only form factor which we are likely to guard closely (and even then not immune to hacking).

More cumbersome option is a cloud-connected OTP token (to prevent RSA-style seed cracking disasters) coupled with, again, out-of-bound login. Easily deployable (sort of), and a major step forward compared to the current status quo.

]]>
By: David Moss http://tomorrowstransactions.com/2013/09/cloudy-chance-of-rain/#comment-49 Tue, 01 Oct 2013 04:42:07 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2013/09/cloudy-chance-of-rain/#comment-49 You could have written this post five years ago, couldn’t you. In fact, you probably did.

Neither the banks nor the telcos would grasp the opportunity then and they still won’t.

That must tell us something.

The benefits aren’t as great as everyone else (apart from the banks and the telcos) imagines? Mistakes could have existential consequences for the company concerned.

The costs are a lot higher than everyone else imagines? Running a national identity management scheme doesn’t come cheap.

]]>