Perimeter
2/10/2012
01:19 PM
Taher Elgamal
Taher Elgamal
Commentary
Connect Directly
RSS
E-Mail
50%
50%
Repost This

On Determining Online Identities

Forging a stronger tie between the sign-on process and the actual known user who owns that particular account

Recently, there has been a lot of discussion and argument over the use of online activities to detect user identities. One of the common discussion points today is how Facebook detects the user not just by the user name and password he enters, but also by matching that user with his known activities, circle of friends, and so on. Other similar activities are done by Google (Street Identity) and others.

The advantages of these approaches are that they provide a stronger tie between the sign-on process and the actual known user who owns that particular account. This will help reduce the effect of phishing and stolen credentials, which end up in identity theft and other fraud. In the credit card industry, the associations have been promoting technologies labeled “3D secure” to provide additional identity verification when a credit card is entered in an online transaction.

There are some possible disadvantages for these approaches that are centered around the possible loss of private information that the sites collect and use to determine the online identity of a user. Indeed, if these data elements are protected properly, then the loss of privacy could be severe. However, the power of improving the strength of the tie between a user and a session that the user initiated is a much stronger, continuous authentication process around online sessions.

Examples in the credit card transaction industry are also in progress. IdentityMind is spearheading a new direction that ties the actual user who is known to own a credit card to the transaction, rather than depending on machine IDs, which have been used or years with only marginal improvement in the fraud rates.

Recognized in the industry as the "inventor of SSL," Dr. Taher Elgamal led the SSL efforts at Netscape. He also wrote the SSL patent and promoted SSL as the Internet security standard within standard committees and the industry. Dr. Elgamal invented several industry and government standards in data security and digital signatures area, including the DSS government standard for digital signatures. He holds a Ph.D. and M.S. in Computer Science from Stanford University.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MS8699
50%
50%
MS8699,
User Rank: Apprentice
2/14/2012 | 4:39:04 AM
re: On Determining Online Identities
SSL Certificates is Very important for on line Business
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

CVE-2014-2392
Published: 2014-04-24
The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 places a password in a GET request, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer log...

Best of the Web