[Dave Birch] I know it’s rather trite to point this out, but moving to stronger authentication of digital identities does not by itself automatically mean more "security" unless the human factors are taken care of. Here’s a post I came across while looking for something else to do with a project I’m working on. It comes from inside a large banking organisation that has adopted two-factor authentication for remote access to corporate resources — surely a sensible policy to protect shareholders’ investments. The person in charge of this shift writes to the staff:
I know there have been a lot of complaints about the new RSA tokens that we’ve issued, in that it’s a bit of an inconvenience to carry your laptop AND an RSA token on your key ring. Here’s a solution that will help you keep them together. Get a bigger key ring (we’ve got a handful, first come first serve) and put the token on the key ring using the small diameter ring on the token. Insert the laptop’s power cord through ring, make a half hitch loop on the cord, fastening the bigger ring to the cord.
In other words, tether the token to the access device that’s at risk.
Technorati Tags: internet, mobile, security
These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.