There are
not a few security professionals who wrongly mix up the layer of
‘authenticators’ with that of ‘deployment of authenticators’, talking as though
the former and the latter were competing each other, for example, ‘Multi-Factor
Authentication is better than a password’ and ‘ID federation is better than a
password’.
The
password is an ‘authenticator’. So are the token and biometrics. Whereas MFA
and ID federation like FIDO and Open ID are ‘deployment of the authenticators’
Expanded
Password System is to be found on the layer of 'authenticator', while the likes
of Open ID and FIDO are all to be found on the upper layer of 'deployment of
authenticators' and, as such, the likes of Open ID and FIDO could naturally be
our down-stream partners.
There are
also some people who wrongly allege that removing an authenticator should
increase security. They are plainly
misguided as examined here – “Removal of Passwords and Its Security Effect” https://www.linkedin.com/pulse/removal-passwords-its-security-effect-hitoshi-kokumai/
Comments
Post a Comment