Perimeter
2/10/2012
01:19 PM
Taher Elgamal
Taher Elgamal
Commentary
50%
50%

On Determining Online Identities

Forging a stronger tie between the sign-on process and the actual known user who owns that particular account

Recently, there has been a lot of discussion and argument over the use of online activities to detect user identities. One of the common discussion points today is how Facebook detects the user not just by the user name and password he enters, but also by matching that user with his known activities, circle of friends, and so on. Other similar activities are done by Google (Street Identity) and others.

The advantages of these approaches are that they provide a stronger tie between the sign-on process and the actual known user who owns that particular account. This will help reduce the effect of phishing and stolen credentials, which end up in identity theft and other fraud. In the credit card industry, the associations have been promoting technologies labeled “3D secure” to provide additional identity verification when a credit card is entered in an online transaction.

There are some possible disadvantages for these approaches that are centered around the possible loss of private information that the sites collect and use to determine the online identity of a user. Indeed, if these data elements are protected properly, then the loss of privacy could be severe. However, the power of improving the strength of the tie between a user and a session that the user initiated is a much stronger, continuous authentication process around online sessions.

Examples in the credit card transaction industry are also in progress. IdentityMind is spearheading a new direction that ties the actual user who is known to own a credit card to the transaction, rather than depending on machine IDs, which have been used or years with only marginal improvement in the fraud rates.

Recognized in the industry as the "inventor of SSL," Dr. Taher Elgamal led the SSL efforts at Netscape. He also wrote the SSL patent and promoted SSL as the Internet security standard within standard committees and the industry. Dr. Elgamal invented several industry and government standards in data security and digital signatures area, including the DSS government standard for digital signatures. He holds a Ph.D. and M.S. in Computer Science from Stanford University.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MS8699
50%
50%
MS8699,
User Rank: Apprentice
2/14/2012 | 4:39:04 AM
re: On Determining Online Identities
SSL Certificates is Very important for on line Business
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4467
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.

CVE-2014-4476
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4477
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4479
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4480
Published: 2015-01-30
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.