<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Security questions and cheese-o 3+ &#8220;factor&#8221; authentication</title>
	<atom:link href="http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/</link>
	<description>One foot in the muck, the other in utopia</description>
	<lastBuildDate>Tue, 22 May 2012 08:23:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: cote</title>
		<link>http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/comment-page-1/#comment-9411</link>
		<dc:creator>cote</dc:creator>
		<pubDate>Fri, 23 Feb 2007 15:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/#comment-9411</guid>
		<description>Good any ideas for those browser changes? ;)</description>
		<content:encoded><![CDATA[<p>Good any ideas for those browser changes? ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Cathcart</title>
		<link>http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/comment-page-1/#comment-9199</link>
		<dc:creator>Mark Cathcart</dc:creator>
		<pubDate>Thu, 22 Feb 2007 22:42:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/#comment-9199</guid>
		<description>Bank of America has been asking you to verify your &quot;site key&quot; plus a user chosen text phrase for almost 2-years now. 
 
You are presented with the user chosen image and phrase and then asked for the equivalent of a user chosen password. For me it&#039;s the best of a bad bunch. 
 
Sure, I&#039;d like some form of 3rd party authentication that doesn&#039;t allow the server I&#039;m connecting to to know anything about my authentication, but will allow me to connect when authenticated log me on. 
 
However, usually when I give this any real thought, I can think of 10-reasons why this isn&#039;t such a good idea. It needs a seed change in the way browsers are built in order to make me think we could pull this off. </description>
		<content:encoded><![CDATA[<p>Bank of America has been asking you to verify your &quot;site key&quot; plus a user chosen text phrase for almost 2-years now.</p>
<p>You are presented with the user chosen image and phrase and then asked for the equivalent of a user chosen password. For me it&#039;s the best of a bad bunch.</p>
<p>Sure, I&#039;d like some form of 3rd party authentication that doesn&#039;t allow the server I&#039;m connecting to to know anything about my authentication, but will allow me to connect when authenticated log me on.</p>
<p>However, usually when I give this any real thought, I can think of 10-reasons why this isn&#039;t such a good idea. It needs a seed change in the way browsers are built in order to make me think we could pull this off. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cote</title>
		<link>http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/comment-page-1/#comment-9063</link>
		<dc:creator>cote</dc:creator>
		<pubDate>Thu, 22 Feb 2007 14:54:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/#comment-9063</guid>
		<description>Thanks for looking that up a leaving the pointer, Mark. Awesome! </description>
		<content:encoded><![CDATA[<p>Thanks for looking that up a leaving the pointer, Mark. Awesome! </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Wahl</title>
		<link>http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/comment-page-1/#comment-9053</link>
		<dc:creator>Mark Wahl</dc:creator>
		<pubDate>Thu, 22 Feb 2007 12:39:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/#comment-9053</guid>
		<description>The &#039;law&#039; you&#039;re thinking of is probably the FFIEC guidance on authentication for Internet banking.  &quot;The agencies consider single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties.&quot;  The focus of the guidance is on risk assessment and management, not so much on user experience. There&#039;s probably scope for some usability studies as the different techniques (OTP token, scratchcard, image, secret question etc) have found deployment.   &lt;a href=&quot;http://www.ffiec.gov/pdf/authentication_guidance.pdf&quot; rel=&quot;nofollow&quot;&gt;http://www.ffiec.gov/pdf/authentication_guidance....&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>The &#039;law&#039; you&#039;re thinking of is probably the FFIEC guidance on authentication for Internet banking.  &quot;The agencies consider single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties.&quot;  The focus of the guidance is on risk assessment and management, not so much on user experience. There&#039;s probably scope for some usability studies as the different techniques (OTP token, scratchcard, image, secret question etc) have found deployment.<br />
  <a href="http://www.ffiec.gov/pdf/authentication_guidance.pdf" rel="nofollow"></a><a href="http://www.ffiec.gov/pdf/authentication_guidance" rel="nofollow">http://www.ffiec.gov/pdf/authentication_guidance</a>&#8230;. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cote</title>
		<link>http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/comment-page-1/#comment-9029</link>
		<dc:creator>cote</dc:creator>
		<pubDate>Thu, 22 Feb 2007 09:24:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/#comment-9029</guid>
		<description>Richard: I agree, as the rest of the post hopefully shows. What I was meaning -- and hoping to point out with the &quot;technologically&quot; prefix -- was that it&#039;s a nifty idea from a purely code monkey context. Usable and nice for end-users, now that&#039;s whole &#039;nuter sotry. </description>
		<content:encoded><![CDATA[<p>Richard: I agree, as the rest of the post hopefully shows. What I was meaning &#8212; and hoping to point out with the &quot;technologically&quot; prefix &#8212; was that it&#039;s a nifty idea from a purely code monkey context. Usable and nice for end-users, now that&#039;s whole &#039;nuter sotry. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ric</title>
		<link>http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/comment-page-1/#comment-8992</link>
		<dc:creator>Ric</dc:creator>
		<pubDate>Thu, 22 Feb 2007 07:14:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/#comment-8992</guid>
		<description>Notice you&#039;re using the same bank as me - fun isn&#039;t it? My wife has the same trouble as yours ...

I can&#039;t wait until web identity is sorted a hell of a lot better than it is now.</description>
		<content:encoded><![CDATA[<p>Notice you&#8217;re using the same bank as me &#8211; fun isn&#8217;t it? My wife has the same trouble as yours &#8230;</p>
<p>I can&#8217;t wait until web identity is sorted a hell of a lot better than it is now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard G Brown</title>
		<link>http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/comment-page-1/#comment-9000</link>
		<dc:creator>Richard G Brown</dc:creator>
		<pubDate>Thu, 22 Feb 2007 03:18:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.redmonk.com/cote/2007/02/21/security-questions-and-cheese-o-3-factor-authentication/#comment-9000</guid>
		<description>[on the new scheme that asks people to look for a specific image and, if it&#039;s not there, to become suspicious]: &quot;to his core point, technologically, it&#8217;s nifty and fun.&quot; 
 
I&#039;m not so sure it is. We have to remember that the vast majority (let&#039;s say &quot;all&quot; to the first approximation) of internet users are busy people for whom a log-on screen is an irritation.  It&#039;s stopping them from doing the task they really want to do. 
 
I don&#039;t see how a security mechanism that relies on one spotting the *absence* of a step in a process is going to work: people just won&#039;t notice. Or if they do, will probably just think to themselves: &quot;neat! They got rid of an annoying step. I can do my banking more quickly!&quot; </description>
		<content:encoded><![CDATA[<p>[on the new scheme that asks people to look for a specific image and, if it&#039;s not there, to become suspicious]: &quot;to his core point, technologically, it&rsquo;s nifty and fun.&quot;</p>
<p>I&#039;m not so sure it is. We have to remember that the vast majority (let&#039;s say &quot;all&quot; to the first approximation) of internet users are busy people for whom a log-on screen is an irritation.  It&#039;s stopping them from doing the task they really want to do.</p>
<p>I don&#039;t see how a security mechanism that relies on one spotting the *absence* of a step in a process is going to work: people just won&#039;t notice. Or if they do, will probably just think to themselves: &quot;neat! They got rid of an annoying step. I can do my banking more quickly!&quot; </p>
]]></content:encoded>
	</item>
</channel>
</rss>

