<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Connected Web: Why It&#8217;s Time For Strong Authentication</title>
	<atom:link href="http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication</link>
	<description>grep understanding</description>
	<lastBuildDate>Sun, 29 Jan 2012 20:44:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Verisign VIP: A &#8220;Weakest Link&#8221; Case in Point &#124; danielmiessler.com</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-244093</link>
		<dc:creator>Verisign VIP: A &#8220;Weakest Link&#8221; Case in Point &#124; danielmiessler.com</dc:creator>
		<pubDate>Wed, 07 Apr 2010 01:45:36 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-244093</guid>
		<description>&lt;p&gt;[...] am an enthusiastic user of the Verisign PIP two-factor authentication service. It&#8217;s a system that allows you to add [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] am an enthusiastic user of the Verisign PIP two-factor authentication service. It&#8217;s a system that allows you to add [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Dual Sim Phones</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-243261</link>
		<dc:creator>Dual Sim Phones</dc:creator>
		<pubDate>Mon, 07 Sep 2009 17:32:10 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-243261</guid>
		<description>&lt;p&gt;great post&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>great post</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Lewis</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241820</link>
		<dc:creator>Rob Lewis</dc:creator>
		<pubDate>Thu, 21 May 2009 17:01:51 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241820</guid>
		<description>&lt;p&gt;At what point does authentication as a proxy for authorization become inadequate, in terms of data level acess or behavior enforcement?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>At what point does authentication as a proxy for authorization become inadequate, in terms of data level acess or behavior enforcement?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Lewis</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241732</link>
		<dc:creator>Rob Lewis</dc:creator>
		<pubDate>Thu, 21 May 2009 13:01:51 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241732</guid>
		<description>&lt;p&gt;At what point does authentication as a proxy for authorization become inadequate, in terms of data level acess or behavior enforcement?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>At what point does authentication as a proxy for authorization become inadequate, in terms of data level acess or behavior enforcement?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241731</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Thu, 21 May 2009 05:16:56 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241731</guid>
		<description>&lt;p&gt;The risk presented by a hole in a castle wall that is easily visible is much&lt;br&gt;higher than the risk presented by an equally sized hole in the wall that&#039;s&lt;br&gt;more obfuscated.&lt;br&gt;Not because the hole is of a different size, or because it&#039;s easier to pass&lt;br&gt;through, but because it&#039;s more likely to be noticed and therefore taken&lt;br&gt;advantage of.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The risk presented by a hole in a castle wall that is easily visible is much<br />higher than the risk presented by an equally sized hole in the wall that&#39;s<br />more obfuscated.<br />Not because the hole is of a different size, or because it&#39;s easier to pass<br />through, but because it&#39;s more likely to be noticed and therefore taken<br />advantage of.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241727</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Thu, 21 May 2009 03:52:08 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241727</guid>
		<description>&lt;p&gt;The risk presented by a hole in a castle wall that is easily visible is much higher than the risk presented by an equally sized hole in the wall that&#039;s more obfuscated.&lt;br&gt;&lt;br&gt;Not because the hole is of a different size, or because it&#039;s easier to pass through, but because it&#039;s more likely to be noticed and therefore taken advantage of.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The risk presented by a hole in a castle wall that is easily visible is much higher than the risk presented by an equally sized hole in the wall that&#39;s more obfuscated.<br /><br />Not because the hole is of a different size, or because it&#39;s easier to pass through, but because it&#39;s more likely to be noticed and therefore taken advantage of.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Nerves of steel, No Coffee Needed, who am i kidding &#124; The CaffiNation Podcast</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241729</link>
		<dc:creator>Nerves of steel, No Coffee Needed, who am i kidding &#124; The CaffiNation Podcast</dc:creator>
		<pubDate>Thu, 21 May 2009 03:46:02 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241729</guid>
		<description>&lt;p&gt;[...] Strong Authentication rules, Facebook now playing nice with OpenID [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Strong Authentication rules, Facebook now playing nice with OpenID [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: davidkma</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241724</link>
		<dc:creator>davidkma</dc:creator>
		<pubDate>Thu, 21 May 2009 01:22:59 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241724</guid>
		<description>&lt;p&gt;On what basis are you claiming that the attack vector is less likely? Relying on obfuscation or the visibility of an exploit for security is a recipe for disaster, especially in this case where the existing attack vector still exists in single sign-on.&lt;br&gt;&lt;br&gt;Consider how esoteric and technically difficult exploiting various browser bugs is and even how much effort is required to effectively leverage buffer overruns. Engineering exploits using these vulnerabilities requires significant technical knowledge and insight, yet we frequently see real world working attacks based on these vectors. Worse still, once the knowledge and code of how to exploit these vulnerabilities is released into the wild, it becomes almost trivial for someone who is less skilled to leverage the same attack vector.&lt;br&gt;&lt;br&gt;There is no technical difference between weak OpenID passwords versus weak e-mail passwords. They can be leveraged in same fashion and it just requires the simple insight that having access to someone&#039;s e-mail account allows you to recover their passwords.&lt;br&gt;&lt;br&gt;Just because the public in general is less aware of this issue doesn&#039;t make it any less real. Counting on the ignorance of a malice attacker doesn&#039;t seem like a good idea.&lt;br&gt;&lt;br&gt;Two factor authentication is obviously preferred, but I don&#039;t agree with your argument that single sign-on exposes users to higher risks, hence we should reinforce security. The same vulnerability and risk already exist in web authentication, hence the question is more why are we currently not using two factor authentication rather then we now have increased risk hence we should use two factor authentication.&lt;br&gt;&lt;br&gt;Only a single password protects us now, so what has stopped the spread of two factor authentication? It seems like a more important question since the things that had held us from deploying two factor authentication en mass in the past will likely hinder us moving forward.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>On what basis are you claiming that the attack vector is less likely? Relying on obfuscation or the visibility of an exploit for security is a recipe for disaster, especially in this case where the existing attack vector still exists in single sign-on.<br /><br />Consider how esoteric and technically difficult exploiting various browser bugs is and even how much effort is required to effectively leverage buffer overruns. Engineering exploits using these vulnerabilities requires significant technical knowledge and insight, yet we frequently see real world working attacks based on these vectors. Worse still, once the knowledge and code of how to exploit these vulnerabilities is released into the wild, it becomes almost trivial for someone who is less skilled to leverage the same attack vector.<br /><br />There is no technical difference between weak OpenID passwords versus weak e-mail passwords. They can be leveraged in same fashion and it just requires the simple insight that having access to someone&#39;s e-mail account allows you to recover their passwords.<br /><br />Just because the public in general is less aware of this issue doesn&#39;t make it any less real. Counting on the ignorance of a malice attacker doesn&#39;t seem like a good idea.<br /><br />Two factor authentication is obviously preferred, but I don&#39;t agree with your argument that single sign-on exposes users to higher risks, hence we should reinforce security. The same vulnerability and risk already exist in web authentication, hence the question is more why are we currently not using two factor authentication rather then we now have increased risk hence we should use two factor authentication.<br /><br />Only a single password protects us now, so what has stopped the spread of two factor authentication? It seems like a more important question since the things that had held us from deploying two factor authentication en mass in the past will likely hinder us moving forward.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241722</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Wed, 20 May 2009 21:27:03 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241722</guid>
		<description>&lt;p&gt;Very interesting argument.&lt;br&gt;&lt;br&gt;I agree that password recovery is a similar weak link, but I don&#039;t agree that the introduction of SSO doesn&#039;t make compromise more serious.&lt;br&gt;&lt;br&gt;There is a difference between vulnerabilities that exist and vulnerabilities that are likely to be exploited, and while the password recover vector is real, it&#039;s far less likely to be taken advantage of just because it&#039;s not as intuitive and visible.&lt;br&gt;&lt;br&gt;The probability of exploitation of the SSO vulnerability is much higher, therefore the overall risk is higher as well. But I agree, this is mostly due to the fact that the SSO issue is more visible and less because it&#039;s fundamentally different than weak password security on email accounts.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Very interesting argument.<br /><br />I agree that password recovery is a similar weak link, but I don&#39;t agree that the introduction of SSO doesn&#39;t make compromise more serious.<br /><br />There is a difference between vulnerabilities that exist and vulnerabilities that are likely to be exploited, and while the password recover vector is real, it&#39;s far less likely to be taken advantage of just because it&#39;s not as intuitive and visible.<br /><br />The probability of exploitation of the SSO vulnerability is much higher, therefore the overall risk is higher as well. But I agree, this is mostly due to the fact that the SSO issue is more visible and less because it&#39;s fundamentally different than weak password security on email accounts.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: davidkma</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241719</link>
		<dc:creator>davidkma</dc:creator>
		<pubDate>Wed, 20 May 2009 18:47:49 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241719</guid>
		<description>&lt;p&gt;For reference, I&#039;ve worked on cryptographic software in the past.&lt;br&gt;&lt;br&gt;Your argument that single sign-on increases the impact of an account compromise is flawed. Almost all web based authentication mechanisms bind to a user&#039;s e-mail address to give some assurance the user is a unique person, and more importantly, to allow for password recovery.&lt;br&gt;&lt;br&gt;Right now the vast majority of users have a primary e-mail address which they use to register most, if not all, of their accounts through, hence a single point of failure already exists. Compromising a single e-mail password will give an attacker access to just about every account an individual has registered for via password recovery.&lt;br&gt;&lt;br&gt;If your argument is we should use two factor authentication because all that stands between an attacker and all of a user&#039;s various accounts, then we should ALREADY be using two factor authentication. Single sign-on does not introduce any risks that aren&#039;t already an inherent in web authentication, it simply is easier to distinguish that a single point of failure exists.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>For reference, I&#39;ve worked on cryptographic software in the past.<br /><br />Your argument that single sign-on increases the impact of an account compromise is flawed. Almost all web based authentication mechanisms bind to a user&#39;s e-mail address to give some assurance the user is a unique person, and more importantly, to allow for password recovery.<br /><br />Right now the vast majority of users have a primary e-mail address which they use to register most, if not all, of their accounts through, hence a single point of failure already exists. Compromising a single e-mail password will give an attacker access to just about every account an individual has registered for via password recovery.<br /><br />If your argument is we should use two factor authentication because all that stands between an attacker and all of a user&#39;s various accounts, then we should ALREADY be using two factor authentication. Single sign-on does not introduce any risks that aren&#39;t already an inherent in web authentication, it simply is easier to distinguish that a single point of failure exists.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: dmitr</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241718</link>
		<dc:creator>dmitr</dc:creator>
		<pubDate>Wed, 20 May 2009 18:19:04 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241718</guid>
		<description>&lt;p&gt;This is pretty cool stuff. Unfortunately, in their infinite wisdom, Verisign has restricted the soft token to the American AppStore only. Lame.&lt;br&gt;&lt;br&gt;Also, the twitter button above the comment form doesn&#039;t work. Clicking it brings up a new window which then disappears. The page reloads and I&#039;m still a &#039;guest&#039;.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>This is pretty cool stuff. Unfortunately, in their infinite wisdom, Verisign has restricted the soft token to the American AppStore only. Lame.<br /><br />Also, the twitter button above the comment form doesn&#39;t work. Clicking it brings up a new window which then disappears. The page reloads and I&#39;m still a &#39;guest&#39;.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Naks</title>
		<link>http://danielmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication/comment-page-1#comment-241716</link>
		<dc:creator>Naks</dc:creator>
		<pubDate>Wed, 20 May 2009 08:26:13 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/blog/the-connected-web-why-its-time-for-strong-authentication#comment-241716</guid>
		<description>&lt;p&gt;check out &lt;a href=&quot;http://www.fireid.com&quot; rel=&quot;nofollow&quot;&gt;www.fireid.com&lt;/a&gt; for an innovative 2FA solution.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>check out <a href="http://www.fireid.com" rel="nofollow">http://www.fireid.com</a> for an innovative 2FA solution.</p>]]></content:encoded>
	</item>
</channel>
</rss>

