Hitoshi Kokumai

5年前 · 1 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
Intriguing Evolution from One to Two and Back to One

Intriguing Evolution from One to Two and Back to One

he lock authenticates the key.
The key authenticates the lock.

  

Does the key authenticate
the person who holds it? 

A single factor authentication by a password was a norm until some years ago. In view of the rampant password phishing and data breach, two factor authentications by the password and something possessed deployed in ‘multi-layer’ method have recently been recommended where security matters.

Now some people recommend the removal of the password altogether from the 2 factor schemes and go back to a single factor authentication, this time, by only something possessed with the help of PKI or onetime code.

Shall we imagine what sort of situation we could witness where our identity is authenticated by the verification of a physical token?

"A guy knocked the door of a mansion, claimed to be the owner of the mansion and demanded the residents to leave. The mansion's lock was unlocked by the key that the guy took out of his wallet. In other words, the guy’s key was authenticated by the mansion’s lock.

The guy was accompanied by a shop owner who testified that they had sold the said wallet to the guy. This certifies that the guy was the legitimate owner of the wallet out of which the key was taken out in front of the residents.

Confronted with the integrity of the key verified by the mansion’s lock and the guy’s identity verified by the possession of the said key along with the ownership of the wallet verified by the testimony of the bona fide shop owner, the unhappy residents were unable to insist that the guy was not the owner of the mansion and had to leave the mansion."

In a present digital environment, we might witness a more advanced situation as described in this cartoon (published 14 years ago) -

http://www.mneme.co.jp/english/manga/parody/index1-2.html

It appears that corporations are obsessed with 'low friction customer experience'. There would be nothing wrong with it if the consumers are accurately informed that the security is more or less sacrificed in return for the lower friction experience when it is actually achieved by sacrificing security.

It would be a devastating mistake, however, if consumers are misled to believe that the lower friction experience is achieved without damaging security when the security is actually damaged. The consumers could well get trapped in a serious false sense of security (illusion of safety), which is even worse than lack of security.

Suppliers of security solutions should be more mindful of what they are doing.


< Related Article >


Distracters in Digital Identity

https://www.bebee.com/producer/@hitoshi-kokumai/distracters-in-digital-identity


Departure from Text Password

https://www.bebee.com/producer/@hitoshi-kokumai/departure-from-text-passwords


コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

We today take up this report “NSA: We 'don't know when or even if' a quantum computer will ever be a ...

2年前 · 2 分の読書時間

I would like to take up this somewhat puzzling report - “Google advises passwords are good, spear ph ...

2年前 · 2 分の読書時間

Another topic for today is “Passwordless made simple with user empowerment” · https://www.securitym ...

この職種に興味がある方はこちら

  • 公開範囲1.等を含む求人情報を公開する

    自動車整備

    次の場所にあります: Talent JP C2 - 3日前


    公開範囲1.等を含む求人情報を公開する Towada, 日本 フルタイム

    仕事内容 · ○自動車(重機、普通自動車、バイク等)の修理及び車検整備 · ・車の引取り、納車業務、点検に伴う整備・修理等 · ★初心者大歓迎です · ★丁寧に指導いたします。 · ★休みが取りやすく、ほぼ残業はありません · 離職率も低く、長く働けるような環境が整っています · ◆応募希望者はハローワークを通してお申込みください◆ 雇用形態 正社員 派遣・請負等 就業形態 派遣・請負ではない 雇用期間 雇用期間の定めなし 就業場所 就業場所 事業所所在地と同じ 〒 青森県十和田市大字三本木字一本木沢2 ...

  • 株式会社リクルートスタッフィング

    軽作業/医療関連

    次の場所にあります: Whatjobs JP C2 - 1日前


    株式会社リクルートスタッフィング Yokohama, 日本

    **ここがポイント** · 【直接雇用の可能性あり】【未経験OK/残業少なめ】 医薬品の製造販売会社での包装の軽作業のお仕事 キレイな自社ビル 落ち着いた環境 · - **業種** · その他 事務系+ 一般事務 · - **期間** · 2024/1/4 ~ 長期 再契約の可能性 :初回1ヶ月契約 再契約予定有 · - **勤務地** · 神奈川県 横浜市 港北区 東横線日吉(神奈川県)駅徒歩2分バス5分社バス無し東横線綱島駅徒歩3分バス10分社バス無し自動車通勤:不可 · - **勤務時間** · 【勤務時間】09:00 ~ 17:30(休憩:60分 ...

  • 株式会社SUNRISE

    営業企画

    次の場所にあります: Whatjobs JP C2 - 2日前


    株式会社SUNRISE 大阪市 天王寺区, 日本

    【職種名】 · 【web面談可】【寮完備】企画営業、イベントスタッフ、販売その他(天王寺) · **仕事内容**: · 楽しく笑って仕事がしたい。 · そんな方の為に作った会社がサンライズです · 随時見学会をやってるので · 一度覗きに来てください。 · 楽しいとは言っても、 · 目標もなくダラダラ働いても · 仕事は楽しくありません。 · 仕事のように遊び、遊びのように仕事する · そんなメリハリも持った雰囲気を · 大切にしています。 · 弊社のお仕事は一言で言うと · 【とにかく人と関わる仕事】です · スウィーツや雑貨を主に扱っていますが、 · ...