FIDO, the password and Live Ensure®



FIDO or Fast Identity Online was launched last week by a couple of Internet big hitters most notably PayPal.   They clearly have a vested interest in ensuring that their transactions are secure.    

FIDO aims to provide specifications or standards to the industry that embody  an approach to authentication which starts to move away from the ‘security by obscurity ‘  or user name/password paradigm prevalent today.   The main reason why the incidence of hacking is sky-rocketing.   [Twitter Hacked]

FIDO aims to leverage hardware devices such as phones and tablets as well as fingerprint readers, webcams, TPM ( Trusted Platform Module)  chips and tokens into an open-standard whereby there will be inter-operability between different systems but which comply to the standard.   A client/server architecture in combination with some hardware fingerprint starts to approach a much more secure approach than the exchange of self reported credentials.    

The creation of a global repository and browser based plug-in  (a la certificate authority) is IMO a potential weakness in the model.   Who will be the custodian of this information and who will ensure it is updated. ?   The graphic below provides an overview of the approach.




Some of the key elements of FIDO are already embodied in the architecture of Live Ensure® (LiveEnsure) the Cloud based authentication solution that leverages the user’s smart-phones to provide contextual validation without the use of passwords.   Live Ensure® has already created the key elements of what FIDO is setting out to achieve. 

Live Ensure® achieves the following :
·      Passwordless authentication =  like FIDO
·      Leveraging existing device (smartphone) FIDO  (requires tokens)
·      Rapid scalability (Cloud Service) FIDO (except for token distribution)
       ·      Triangulated architecture = FIDO

Live Ensure® embraces a new approach to authentication and endorses any efforts in the direction of making the end user experience better.   If this can be done while achieving stronger security so much the better.    Live Ensure® intends to engage with the FIDO Alliance to make a contribution to this important effort in simplifying and strengthening end-user log-in security.  

Comments

Popular posts from this blog

The End of Passwords

WIKILEAKS - the fuss?

SPOOKS - CYBER ATTACK