Join the Community

22,288
Expert opinions
44,292
Total members
325
New members (last 30 days)
163
New opinions (last 30 days)
28,772
Total comments

Authentication Factors

Reaction to the article of TowerGroup

https://www.finextra.com/fullstory.asp?id=20137

Regarding the usage of "traditional" account information (name, address, birthdate...) as authentication factor, I guess we can say that, at least in Finextra Community, we know that this type of data has been compromised long before being put on the spot by the successive data breaches.

Even before the series of data breaches, this type of "traditional" information was already easily available on the web via the social networks and deep web search tools. There is always a trace somewhere even if you never enter your info on a website.

Concerning the recommendation of using knowledge-based authentication and one-time passwords delivered via SMS, I could not agree more.

The type of information that needs to be used for the authentication has to be dynamic, and the process itself must include an out-of-band channel to be insensitive to the latest hacking techniques.

External

This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.

Join the Community

22,288
Expert opinions
44,292
Total members
325
New members (last 30 days)
163
New opinions (last 30 days)
28,772
Total comments

Trending

Now Hiring