Endpoint // Authentication
5/20/2013
10:13 AM
Tim Wilson
Tim Wilson
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Rethinking Identity Management

Secret identities are a good thing. Multiple identities? Not so much

Having spent some years in security, I've often been at odds with myself over the concept of "single sign-on," in which an individual can use a single method of authentication to log onto multiple systems and applications.

On one hand, single sign-on is a boon because it gives users quick access to lots of resources without having to remember dozens of different passwords. On the other hand, a bad guy who steals individual passwords gains access to one application; a bad guy who steals your single sign-on credentials gains the keys to the kingdom.

With this latter point in mind, I've generally avoided consolidating my online identity, preferring the "multiple personality" approach that allowed me to use different passwords, different security questions, and even different names and birth dates on different systems. Better to be Steve Austin on one site and Clark Kent on another, I felt, than to make myself vulnerable on both sites at the same time.

Recently, however, I've begun to rethink this strategy. For one thing, maintaining multiple personalities is a pain in the neck. Trying to remember your username, password, and security questions is hard enough when you're one person. When you're Sybil and have 13 different personalities, it's nigh unto impossible.

For another thing, the technology is getting better. Password management and consolidation tools such as KeePass and LastPass are becoming more reliable and secure, and many of them offer a form of second-factor authentication that actually improves security.

New initiatives, such as the FIDO Alliance discussed in our main story in today's newly published Dark Reading digital issue on Web authentication, offer the promise of using a single interface for many different systems and applications, and take advantage of the most secure authentication tools available for each system.

More important than either of these points, however, is the fact that so much of the world is becoming Web-connected. Increasingly, who we are is defined by what we do on the Web. Google knows that I'm a security person, so it offers me search results that are slanted in that direction. Facebook offers me security-related ads, and LinkedIn tells me about security people I might want to connect with. There are advantages to having a single online identity, and those advantages will increase as Web technology improves and the promise of "Internet personalization" becomes reality.

Then again, the security person in me resists this idea. Do I really want Google, Facebook, and other sites collecting information about my online background and surfing habits? I find that increasingly -- if it can be done securely -- my answer is often yes. While I don't want websites to have all of my information, and while I believe all users should have the option to opt out, I am increasingly opting in. Having a single identity enables me to meet more people and do more things on the Web, and faster, than I could as Clark Kent and Steve Austin.

It's still a trade-off, but the costs and benefits of that trade are shifting. If the technology continues to improve, then it might soon be safer for all of us to be one person on the Web, instead of many. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0914
Published: 2014-07-30
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management f...

CVE-2014-0915
Published: 2014-07-30
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8...

CVE-2014-0947
Published: 2014-07-30
Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site.

CVE-2014-0948
Published: 2014-07-30
Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive.

CVE-2014-2356
Published: 2014-07-30
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.

Best of the Web
Dark Reading Radio