<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Talking Identity &#124; Nishant Kaushik&#039;s Look at the World of Identity Management &#187; OAAM</title>
	<atom:link href="http://blog.talkingidentity.com/tag/oaam/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.talkingidentity.com</link>
	<description>An Architect&#039;s Quest to make sense of the world of Identity and Access Management</description>
	<lastBuildDate>Thu, 22 Dec 2011 21:56:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>BT wins European Identity Award for Fraud Service powered by Oracle</title>
		<link>http://blog.talkingidentity.com/2011/05/bt-wins-european-identity-award-for-fraud-service-powered-by-oracle.html</link>
		<comments>http://blog.talkingidentity.com/2011/05/bt-wins-european-identity-award-for-fraud-service-powered-by-oracle.html#comments</comments>
		<pubDate>Wed, 18 May 2011 21:38:08 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[BT]]></category>
		<category><![CDATA[EIC11]]></category>
		<category><![CDATA[European Identity Award]]></category>
		<category><![CDATA[European Identity Conference]]></category>
		<category><![CDATA[Fraud Prevention]]></category>
		<category><![CDATA[Identity Proofing]]></category>
		<category><![CDATA[Managed Fraud Reduction]]></category>
		<category><![CDATA[OAAM]]></category>
		<category><![CDATA[Oracle Adaptive Access Manager]]></category>
		<category><![CDATA[Oracle Service Bus]]></category>
		<category><![CDATA[Oracle_IDM]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=1189</guid>
		<description><![CDATA[Another year, another European Identity Award for an Oracle customer. At last weeks European Identity Conference, KuppingerCole gave their coveted award in the Governance, Risk Management and Compliance category to BT for their Managed Fraud Reduction service. The BT MFR service provides a real time risk assessment of online transactions, thus providing customers the ability [...]]]></description>
			<content:encoded><![CDATA[<p>Another year, another <strong>European Identity Award</strong> for an Oracle customer. At last weeks <a href="http://www.id-conf.com/eic2011" target="_blank">European Identity Conference</a>, KuppingerCole gave their coveted award in the <em>Governance, Risk Management and Compliance</em> category to <strong>BT</strong> for their <strong>Managed Fraud Reduction</strong> service. The <a href="http://bit.ly/mqdMHq" target="_blank"><strong>BT MFR</strong> service</a> provides a real time risk assessment of online transactions, thus providing customers the ability to incorporate an extensible fraud detection tool into their environment at minimal cost.</p>
<div id="attachment_1190" class="wp-caption aligncenter" style="width: 550px"><a href="http://www.kuppingercole.com/gallery/eic2011/IMG_5656.JPG.html" target="_blank"><img class="size-full wp-image-1190" title="award_oracle_eic2011" src="http://blog.talkingidentity.com/wp-content/uploads/2011/05/award_oracle_eic2011.jpg" alt="BT and Oracle accepting a European Iidentity Award" width="540" height="360" /></a><p class="wp-caption-text">BT (Robert McCausland &amp; Peter Boyle) and Oracle (the ever dapper Christian Patrascu) accepting the European Identity Award from Martin Kuppinger &amp; Tim Cole</p></div>
<h3>The Solution</h3>
<p>BT MFR brings together a comprehensive suite of fraud reduction  capabilities under a single service. Device recognition, location  recognition, behavior recognition and comprehensive policy enforcement  through a customizable ruleset (powered by Oracle Adaptive Access  Manager) provide granular risk assessments, returned in real-time so  that even digital services requiring instantaneous delivery can be risk  assessed for suspected fraud.</p>
<p>This functionality is all strung together and orchestrated by an  Oracle Service Bus and accessed via web service calls. The routing and  transformation layer that OSB provides allows for the  augmentation of  all the transaction data presented which can subsequently be  used in a  much richer risk assessment. The sources of such checks could be  external  URU or internal to the enterprise based on intelligence  they&#8217;ve built up over  years.</p>
<p>Risk assessments from multiple services can thus be aggregated to  provide a single response to the protected application, containing all  the information required to determine whether any transaction should  continue forward.</p>
<p><img class="aligncenter size-full wp-image-1192" title="BT MFR Arch" src="http://blog.talkingidentity.com/wp-content/uploads/2011/05/BT-MFR-Arch.jpg" alt="BT MFR Arch" width="550" height="252" /></p>
<p>Thanks to this unique design the service is also able to evolve, with new services integrated into the overall risk assessment procedure as they become required or available, without impacting the single web service call that the customer needs to access this battery of anti-fraud protection.</p>
<h3>The Benefits</h3>
<p>BTs Managed Fraud Reduction service has brought together a unique set of capabilities that address online fraud in ways that adapt to the organizations specific needs:</p>
<ul>
<li>Most online retailers cannot afford to issue password generating tokens to a fickle and ever-changing user-base. so a risk assessment based on transaction parameters such as device recognition and location provides a different way to achieve greater security.</li>
<li>Online retailers providing digital goods or services cannot wait until shipping to review transactions (as delivery is immediate) so a system based on real-time assessment is greatly beneficial.</li>
<li>Financial service providers need to assure funds transfers and payments within increasingly short windows (due to regulations such as ‘Faster Payments’) so real-time responses are essential.</li>
<li>Gaming and leisure services are reliant on age-verification, so require identity verification score aggregated with the normal risk assessment. MFR allows the integration of such additional web services and will launch with BT’s URU identity verification available as an option.</li>
<li>With the BT MFR service in place, customers can demonstrate to auditors that fraud prevention strategies are in operation and as a cloud service allows them to demonstrate this at a fraction of the cost compared to a self build strategy.</li>
<li>With a robust fraud solution in place, customers can demonstrate to merchant acquiring banks that liability has been reduced.</li>
<li>The architecture removes the need for the customer to contract separately with multiple vendors providing identity and fraud related services.</li>
</ul>
<p>Addressing all market sectors and territories, fully customizable and simple to use, BT Managed Fraud Reduction service is an evolving one-stop solution to the ever-changing challenge of online fraud. And Oracle is proud to be a part of the solution.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/bt" rel="tag">BT</a>, <a href="http://blog.talkingidentity.com/tag/eic11" rel="tag">EIC11</a>, <a href="http://blog.talkingidentity.com/tag/european-identity-award" rel="tag">European Identity Award</a>, <a href="http://blog.talkingidentity.com/tag/european-identity-conference" rel="tag">European Identity Conference</a>, <a href="http://blog.talkingidentity.com/tag/fraud-prevention" rel="tag">Fraud Prevention</a>, <a href="http://blog.talkingidentity.com/tag/identity-proofing" rel="tag">Identity Proofing</a>, <a href="http://blog.talkingidentity.com/tag/managed-fraud-reduction" rel="tag">Managed Fraud Reduction</a>, <a href="http://blog.talkingidentity.com/tag/oaam" rel="tag">OAAM</a>, <a href="http://blog.talkingidentity.com/tag/oracle-adaptive-access-manager" rel="tag">Oracle Adaptive Access Manager</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-service-bus" rel="tag">Oracle Service Bus</a>, <a href="http://blog.talkingidentity.com/tag/oracle_idm" rel="tag">Oracle_IDM</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2011/05/bt-wins-european-identity-award-for-fraud-service-powered-by-oracle.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Challenge of Security Questions</title>
		<link>http://blog.talkingidentity.com/2010/07/the-challenge-of-security-questions.html</link>
		<comments>http://blog.talkingidentity.com/2010/07/the-challenge-of-security-questions.html#comments</comments>
		<pubDate>Thu, 22 Jul 2010 20:23:27 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Identity Proofing]]></category>
		<category><![CDATA[Knowledge-Based Authentication]]></category>
		<category><![CDATA[OAAM]]></category>
		<category><![CDATA[OIM]]></category>
		<category><![CDATA[Oracle Identity Management 11g]]></category>
		<category><![CDATA[Password Management]]></category>
		<category><![CDATA[Password Recovery Techniques]]></category>
		<category><![CDATA[Security Questions]]></category>
		<category><![CDATA[Service-Oriented Security]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=966</guid>
		<description><![CDATA[Jackson Shaw just wrote about a website called goodsecurityquestions.com. As the name indicates, it&#8217;s a site that purports to distinguish between good and bad questions to employ when setting up for your identity re-verification challenges (for when you forget your password or need to execute a high-value transaction, for instance). The same site also (correctly) [...]]]></description>
			<content:encoded><![CDATA[<p>Jackson Shaw just <a href="http://jacksonshaw.blogspot.com/2010/07/what-are-good-security-questions-for.html" target="_blank">wrote about</a> a website called <a href="http://bit.ly/9ZrPKT" target="_blank">goodsecurityquestions.com</a>. As the name indicates, it&#8217;s a site that purports to distinguish between good and bad questions to employ when setting up for your identity re-verification challenges (for when you forget your password or need to execute a high-value transaction, for instance). The same site also (correctly) points out that <a href="http://bit.ly/8Y1r7L" target="_blank">there are no good security questions</a> (due to the inherent security issues in it), just better ones, based on the following criteria:</p>
<ol>
<li>The answer cannot be easily guessed or researched [<em>Safe</em>]</li>
<li>The answer doesn&#8217;t change over time [<em>Stable</em>]</li>
<li>The answer is memorable [<em>Recall-ability</em>]</li>
<li>The answer is definitive or simple [<em>Simplicity</em>]</li>
</ol>
<p>Good criteria to remember next time you are deciding between &#8220;What is your pet&#8217;s name?&#8221; and &#8220;What was the name of your first stuffed animal?&#8221;.</p>
<p>Of course, the service you are interacting with needs to allow you to choose from a large enough set or supply your own questions so you can adhere to this principle. And a highly sensitive application should go beyond just plain security questions. While most services are moving towards simpler yet more secure mechanisms &#8211; emailing the user short-lived password reset tokens, for instance &#8211; there are many cases where you still need a challenge-based mechanism (like when the forgotten password is the one used to access your email).</p>
<p><strong>Knowledge-Based Authentication </strong>has gotten increasingly sophisticated over the last few years, and enterprises looking to leverage this can do better than just providing their users a few hard-coded questions to choose from. <a href="http://bit.ly/9njEb1" target="_blank"><strong>Oracle Adaptive Access Manager 11g</strong></a> brings features like <em>Answer Logic</em> (which employs fuzzy logic to increase the usability of security questions) and <em>One-Time Passwords</em> (delivered via SMS, email, IM or voice) into the mix, while also adding real-time risk analytics to make the overall process more secure, reliable, usable and cost-effective.</p>
<p>And all of this is delivered as a service so that enterprises can incorporate KBA into their various applications as needed. In fact, as part of the suite-wide integration design theme of Oracle Identity Management 11g, OAAM now has out-of-the-box integrations with Oracle Identity Manager and Oracle Access Manager. So if you deploy the suite, the real-time risk analytics and risk-based challenge mechanisms of OAAM are automatically leveraged by those other products. It is a sweet thing to behold.</p>
<p>Even as we <a href="http://bit.ly/cK78jV" target="_blank">sound out the call to kill passwords</a> (an NPT for passwords; I like that), KBA will continue to be a critical tool in the identity proofing arena. So keep an eye out for all the innovation that will take place in this field.</p>
<p><a href="http://www.geekculture.com/joyoftech/joyarchives/001_300/163.html"><img class="alignnone size-full wp-image-968" title="Password Retrieval" src="http://blog.talkingidentity.com/wp-content/uploads/2010/07/ForgotPassword.gif" alt="Password Retrieval" width="469" height="358" /></a></p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/identity-proofing" rel="tag">Identity Proofing</a>, <a href="http://blog.talkingidentity.com/tag/knowledge-based-authentication" rel="tag">Knowledge-Based Authentication</a>, <a href="http://blog.talkingidentity.com/tag/oaam" rel="tag">OAAM</a>, <a href="http://blog.talkingidentity.com/tag/oim" rel="tag">OIM</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management-11g" rel="tag">Oracle Identity Management 11g</a>, <a href="http://blog.talkingidentity.com/tag/password-management" rel="tag">Password Management</a>, <a href="http://blog.talkingidentity.com/tag/password-recovery-techniques" rel="tag">Password Recovery Techniques</a>, <a href="http://blog.talkingidentity.com/tag/security-questions" rel="tag">Security Questions</a>, <a href="http://blog.talkingidentity.com/tag/service-oriented-security" rel="tag">Service-Oriented Security</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/07/the-challenge-of-security-questions.html/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Şekerbank secures online banking with award-winning OAAM implementation</title>
		<link>http://blog.talkingidentity.com/2010/05/sekerbank-secures-online-banking-with-award-winning-oaam-implementation.html</link>
		<comments>http://blog.talkingidentity.com/2010/05/sekerbank-secures-online-banking-with-award-winning-oaam-implementation.html#comments</comments>
		<pubDate>Tue, 18 May 2010 15:17:39 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Oracle Identity Management]]></category>
		<category><![CDATA[Adaptive Risk Manager]]></category>
		<category><![CDATA[EIC10]]></category>
		<category><![CDATA[EIC2010]]></category>
		<category><![CDATA[European Identity Conference]]></category>
		<category><![CDATA[Fraud Prevention]]></category>
		<category><![CDATA[OAAM]]></category>
		<category><![CDATA[Oracle Adaptive Access Manager]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=853</guid>
		<description><![CDATA[Şekerbank T.A.Ş. is the leading Turkish bank for small and midsize enterprises, and its internet banking services are among the three highest-rated online banking Web sites in Turkey. They have earned a reputation for having the most user-friendly and secure online banking Web sites in the country. Last week at the European Identity Conference, they [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Şekerbank T.A.Ş.</strong> is the leading Turkish bank for small and midsize enterprises, and its internet banking services are among the three highest-rated online banking Web sites in Turkey. They have earned a reputation for having the most user-friendly and secure online banking Web sites in the country. Last week at the <strong>European Identity Conference</strong>, they were one of the winners of the “Best Internal Project” award for a solution developed together with <a href="http://bit.ly/bZ82Wg" target="_blank">Smartsoft</a> and Oracle for providing risk-based authentication and authorization. I thought it was an interesting case study, so I thought I would share it with you.</p>
<p>Their solution was built around SmartSoft’s SRM (Smart Risk Manager) Fraud Management System and <strong><a href="http://bit.ly/bfM9OT" target="_blank">Oracle Adaptive Access Manager</a></strong>, our solution in the area of strong authentication and proactive, real-time fraud prevention. SmartSofts’ expertise in EMV and payment card systems means that they understand credit card fraud at a deep level. This understanding is the basis for the fraud controls that SRM introduces at the merchant and issuer sides, detecting fraud in real-time and taking just-in-time precautions and actions. The bank has been using SRM for over 2 years to secure their credit and debit card operations.</p>
<h3>The Challenge</h3>
<p>The bank wanted to bring the same level of fraud management that they had achieved with their credit and debit card operations to their internet banking channel. This would require understanding the mechanisms of internet banking fraud, enable comprehensive and automated tracking of online transactions, and use this to identify instances of frauds in real time. The bank also wanted to make sure that they fully complied with international and domestic regulations for internet banking.</p>
<h3>The Solution</h3>
<p>In order to do this, the bank worked with SmartSoft and Oracle to add OAAM Adaptive Risk Manager (ARM) into their fraud controls system. ARM is OAAM&#8217;s back-end, proactive real-time fraud detection product, providing a behind-the-scenes comprehensive anti-fraud software solution. ARM provides a strong second and third factor of security by verifying a host of factors used to confirm identity – from device characteristics (the computer and mobile device used to login) to a user&#8217;s location and online behavioral profiles. Adaptive Risk Manager can also trigger numerous actions based on its analysis, such as challenging or blocking the user.</p>
<p><img class="alignnone size-full wp-image-865" title="OAAM" src="http://blog.talkingidentity.com/wp-content/uploads/2010/05/OAAM1.jpg" alt="OAAM" width="550" height="307" /></p>
<p>For the deployment, the project team conducted a broad analysis of requirements in terms of internet banking fraud rules, and configured more than 50 OOTB rules in OAAM&#8217;s rule engine. They also developed an advanced scoring mechanism for real-time analysis of each transaction’s fraud probability, aimed at achieving a detection rate of nearly 99% of all fraud attempts.</p>
<p>An information channel was defined between OAAM and SRM, whereby the two systems can enrich each others decision-making data. For interactions originating in the internet banking channel, OAAM can calculate risk levels and notify SRM about high risk transactions. Conversely, SRM can send fraud data for risky transactions it encounters to OAAM for use in its behavioral analysis. This integration between the two systems makes the fraud analysis richer and more reliable.</p>
<p><img class="alignnone size-full wp-image-872" title="Sekerbank Solution" src="http://blog.talkingidentity.com/wp-content/uploads/2010/05/Sekerbank-Solution1.jpg" alt="Sekerbank Solution" width="550" height="238" /></p>
<p>On top of this, the bank’s fraud analysts are using existing reporting capabilities and Oracle BI Publisher for deep down reporting and trend analysis to identify zero-day fraud patterns. Case management also enabled the organization to take care of risky activities and provide flexible service to end-users in real time.</p>
<h3>The Results</h3>
<p>The bank deployed OAAM in just three months, providing the bank’s fraud analysts with comprehensive visibility and monitoring capabilities for internet banking transactions. With the deployment in production, the bank was able to achieve a previously unmatched level of security for internet banking and fully ensure <strong>Şekerbank</strong>’s compliance with international and domestic regulations. They were also able to realize a decrease in operational costs for surveying internet banking transactions of ~70%, as now only 2% of all transactions require manual control following a system alert.</p>
<p><img class="alignnone size-full wp-image-859" title="EIC2010_Award" src="http://blog.talkingidentity.com/wp-content/uploads/2010/05/EIC2010_Award.jpg" alt="EIC2010_Award" width="550" height="324" /></p>
<p>It&#8217;s always good when you come across a success story like this one, and when especially when the project teams get the recognition they so richly deserve (but seldom get). Kudos to them on the success of the project and the award.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/adaptive-risk-manager" rel="tag">Adaptive Risk Manager</a>, <a href="http://blog.talkingidentity.com/tag/eic10" rel="tag">EIC10</a>, <a href="http://blog.talkingidentity.com/tag/eic2010" rel="tag">EIC2010</a>, <a href="http://blog.talkingidentity.com/tag/european-identity-conference" rel="tag">European Identity Conference</a>, <a href="http://blog.talkingidentity.com/tag/fraud-prevention" rel="tag">Fraud Prevention</a>, <a href="http://blog.talkingidentity.com/tag/oaam" rel="tag">OAAM</a>, <a href="http://blog.talkingidentity.com/tag/oracle-adaptive-access-manager" rel="tag">Oracle Adaptive Access Manager</a>, <a href="http://blog.talkingidentity.com/tag/oracle-identity-management" rel="tag">Oracle Identity Management</a>, <a href="http://blog.talkingidentity.com/tag/risk-management" rel="tag">Risk Management</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2010/05/sekerbank-secures-online-banking-with-award-winning-oaam-implementation.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Twitter Break-In: Anything to learn here?</title>
		<link>http://blog.talkingidentity.com/2009/07/the-twitter-break-in-anything-to-learn-here.html</link>
		<comments>http://blog.talkingidentity.com/2009/07/the-twitter-break-in-anything-to-learn-here.html#comments</comments>
		<pubDate>Wed, 15 Jul 2009 15:49:49 +0000</pubDate>
		<dc:creator>Nishant Kaushik</dc:creator>
				<category><![CDATA[Insight IdM]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[OAAM]]></category>
		<category><![CDATA[Oracle_IDM]]></category>
		<category><![CDATA[Password Management]]></category>
		<category><![CDATA[Password Recovery Techniques]]></category>

		<guid isPermaLink="false">http://blog.talkingidentity.com/?p=557</guid>
		<description><![CDATA[The answer is: Plenty. In a nutshell, here is what happened as I understand it: A hacker named Hacker Croll (who has been a pain in Twitter&#8217;s behind for a while now) was able to gain access to the Gmail accounts of various twitter employees, including founder Evan Williams. He was then able to use [...]]]></description>
			<content:encoded><![CDATA[<p>The answer is: Plenty.</p>
<p>In a nutshell, <a href="http://www.techcrunch.com/2009/07/14/twitters-ev-confirms-hacker-targeted-personal-accounts-attack-was-highly-distressing/" target="_blank">here is what happened</a> as I understand it: A hacker named <strong>Hacker Croll</strong> (who has been a pain in Twitter&#8217;s behind for a while now) was able to gain access to the Gmail accounts of various twitter employees, including founder <strong>Evan Williams</strong>. He was then able to use the regular password-recovery techniques that rely on email-based mechanisms to gain access to other services being used like <em>Paypal</em>, <em>GoDaddy</em>, <em>Amazon</em> and <em>Apple</em>. But most notably, he had access to the <em>Google Docs</em> service that the Twitter folks were using extensively to store sensitive corporate documents. This landed Hacker Croll a goldmine (that <a href="http://www.techcrunch.com/2009/07/14/in-our-inbox-hundreds-of-confidential-twitter-documents/" target="_blank">has been shared with TechCrunch</a>) of documents, including &#8220;financial projections, product plans and notes from executive strategy meetings&#8221;. Twitter has a lot to deal with here. But this is an important IdM and Cloud Computing related cautionary tale for all of us. And the takeaways, while obvious, bear repeating.</p>
<p>This episode underscores the fact that password recovery techniques that rely on email delivery of passwords or password-reset links are highly insecure. Secret question based mechanisms (aka <strong><em><a href="http://identityblog.burtongroup.com/bgidps/kba/" target="_blank">Static Knowledge-Based Authentication</a></em></strong>) are not that much more reliable either (anyone and everyone can find out the name of any celebrity&#8217;s first car, dog, mother&#8217;s maiden name, etc). Services that deal with sensitive information NEED to rely on <em><strong>Dynamic Knowledge-Based Authentication</strong></em> (where the data source for the authentication questions could be the content stored in the service itself, which only the users should have knowledge of) or <em><strong>Out-Of-Band Identity Proofing</strong></em> (something <a href="http://www.oracle.com/technology/products/id_mgmt/oaam/index.html" target="_blank">Oracle Adaptive Access Manager</a> can help with).</p>
<p>As more and more companies rely on the cloud, the security of cloud services (or lack thereof) needs to be evaluated very carefully, as will corporate security policies on access to those services. <em><strong>Strong passwords</strong></em> need to exist not only on the service access, but also on the accounts that have access to the service. Ideally, the service provider should support <em><strong>Multi-Factor Authentication</strong></em> and <em><strong>federated identity and authentication</strong></em> for higher identity assurance by corporate clients. And encryption of sensitive documents and data is a must. Cloud service providers need to understand the implications of entering the enterprise market, and that includes deploying enterprise-grade identity management and security technology.</p>
<p>Unfortunately this event will sow doubts in the minds of those that are considering using cloud-based services. Which is why we have to work hard to define the standards cloud services need to live up to. As Michael Arrington <a href="http://www.techcrunch.com/2009/07/15/our-reaction-to-your-reactions-on-the-twitter-confidential-documents-post/" target="_blank">so bluntly put it</a>:</p>
<blockquote><p>It’s not our fault that Google has a ridiculously easy way to get access to accounts via their password recovery question. It’s not our fault that Twitter stored all of these documents and sensitive information in the cloud and had easy-to-guess passwords and recovery questions.</p></blockquote>
<p>That is quite plainly an unacceptable state of affairs.</p>
<p class="tags">Tags: <a href="http://blog.talkingidentity.com/tag/cloud-computing" rel="tag">Cloud Computing</a>, <a href="http://blog.talkingidentity.com/tag/oaam" rel="tag">OAAM</a>, <a href="http://blog.talkingidentity.com/tag/oracle_idm" rel="tag">Oracle_IDM</a>, <a href="http://blog.talkingidentity.com/tag/password-management" rel="tag">Password Management</a>, <a href="http://blog.talkingidentity.com/tag/password-recovery-techniques" rel="tag">Password Recovery Techniques</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.talkingidentity.com/2009/07/the-twitter-break-in-anything-to-learn-here.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

