• Speaking
  • Downloads
  • About Talking Identity
  • About Me

The Epic Hacking of Mat Honan and Our Identity Challenge

  • Posted on:August 7, 2012
  • Posted in:Personal Identity Management, The Cloud Identity Series
  • Posted by:Nishant Kaushik
4

Wired has the kind of article that will make all of us leading highly digitized lives (is that the right term?) wake up in a cold sweat. While the title – How Apple and Amazon Security Flaws Led to My Epic Hacking – may strike many as sensationalist, the article does a good job of…

Read More
Tags: Amazon SecurityApple SecurityGMail SecurityIdentity AssuranceIdentity ProvidersIdentity VerificationMat HonanNSTICPassword ManagementPassword Recovery TechniquesPasswords Must Die

Protecting Yourself While Using Cloud Services

  • Posted on:November 3, 2011
  • Posted in:Personal Identity Management
  • Posted by:Nishant Kaushik
0

I was recently asked to comment on the top 5 ways to protect yourself (as an individual) when using the cloud. Obviously I brought a very identity-centric slant to it, but it was an interesting exercise as I tried to put down on paper (!) the steps I take to protect myself daily. I thought…

Read More
Tags: Cloud SecurityPassword ManagementPasswords Must DiePersonal Identity Management

Cardspace and the KISS Principle

  • Posted on:February 22, 2011
  • Posted in:Insight IdM
  • Posted by:Nishant Kaushik
0

(My original title for this post was “Cardspace, We Hardly Knew Thee”, but Dave Kearns stole that by a nose). RSA is not the best conference for identity related news and topics, but there were more than a few interesting story lines that emerged last week (and no, I am not referring to what went…

Read More
Tags: Authentication ServicesCardspaceFederated Consumer AuthenticationIdentity In The BrowserInformation CardsPassword ManagementUser-Centric Identity

The Challenge of Security Questions

  • Posted on:July 22, 2010
  • Posted in:Insight IdM, Oracle Identity Management
  • Posted by:Nishant Kaushik
6

Jackson Shaw just wrote about a website called goodsecurityquestions.com. As the name indicates, it’s a site that purports to distinguish between good and bad questions to employ when setting up for your identity re-verification challenges (for when you forget your password or need to execute a high-value transaction, for instance). The same site also (correctly)…

Read More
Tags: Identity ProofingKnowledge-Based AuthenticationOAAMOIMOracle Identity ManagementOracle Identity Management 11gPassword ManagementPassword Recovery TechniquesSecurity QuestionsService-Oriented Security

The Twitter Break-In: Anything to learn here?

  • Posted on:July 15, 2009
  • Posted in:Insight IdM
  • Posted by:Nishant Kaushik
0

The answer is: Plenty. In a nutshell, here is what happened as I understand it: A hacker named Hacker Croll (who has been a pain in Twitter’s behind for a while now) was able to gain access to the Gmail accounts of various twitter employees, including founder Evan Williams. He was then able to use…

Read More
Tags: Cloud ComputingOAAMOracle_IDMPassword ManagementPassword Recovery Techniques

Now How Are We Supposed To Solve This?

  • Posted on:June 5, 2009
  • Posted in:Personal Identity Management
  • Posted by:Nishant Kaushik
2

Here is an interesting anecdote I heard yesterday (identity of person withheld for their own protection): My tween daughter was entering some sort of online popularity contest. It involved registering yourself as a contestant online with your email address, and then verifying your entry by clicking on a link in a verification email you would…

Read More
Tags: Password Management

The changing face of Password Management

  • Posted on:October 9, 2008
  • Posted in:Personal Identity Management, User-Centric Identity
  • Posted by:Nishant Kaushik
0

A college student was arraigned on Wednesday for allegedly breaking into Gov. Sarah Palin’s private e-mail account last month. Political leanings aside, I  read the news article with great interest for the inherent security implications. Reading it, this line jumped out at me: The F.B.I. said that the younger Mr. Kernell allegedly hacked into the…

Read More
Tags: Identity AssurancePassword ManagementUser-Centric Identity

New Ideas in Password Management

  • Posted on:August 29, 2007
  • Posted in:Insight IdM, Oracle Identity Management
  • Posted by:Nishant Kaushik
1

In his Network World on Security newsletter this week, Dave Kearns talks about a new kind of password management product that seems to be picking up traction. Lieberman Software’s Random Password Manager offers interesting new capabilities in password management similar to Cyber-Ark’s Enterprise Password Vault (EPV). I had briefly mentioned Cyber-Ark in a blog post…

Read More
Tags: Burton Catalyst ConferenceBurtonGroupCatalyst07Cyber-ArkOracle Identity ManagementPassword ManagementPrivileged Account Management

Talk about the need for Complex Passwords

  • Posted on:July 14, 2007
  • Posted in:Insight IdM
  • Posted by:Nishant Kaushik
0

I read this post on the Wired blogs about an ATM heist in which the culprit re-programmed the ATM to think it was dispensing dollar bills when it was actually dispensing twenties, thereby allowing the guy to clean out the ATM. How did he do the re-programming? Because he knew the Master Passcode for the…

Read More
Tags: Password ComplexityPassword ManagementPrivileged Account Management

How good are our passwords?

  • Posted on:December 15, 2006
  • Posted in:Insight IdM
  • Posted by:Nishant Kaushik
2

Wired News (which I read assiduously) had a pretty interesting article in their “Security Matters” section recently that talked about an analysis done of MySpace account passwords (“MySpace Passwords Aren’t So Dumb“). It makes for a pretty interesting read, so check it out. While you are at it, check out whether you have a password…

Read More
Tags: Password ComplexityPassword Management

Recent Posts

The Conundrum of 2FA meets the Enigma that is PAM
"It's a mystery. Broken into a jigsaw puzzle. Wrapped in a conun...
The Dilemma of the OAuth Token Collector
'Tis the season to be hacked, I guess. Twitter joined a bunch of...
Why 2013 will be 'The Year of the SCUID'
I'm just now coming back to earth from the high I've been on sin...
The IDaaS Powered World
Last week I was in Colorado for the Defrag and Blur conferences....
What Happens When Telco's Declare SMS 'Unsafe'?
If you've been following Authentication related discussions, you...

Recent Comments

  • Bob Pinheiro on The Conundrum of 2FA meets the Enigma that is PAM
  • NishantKaushik on The IDaaS Powered World
  • Nikolaj Ivancic on The IDaaS Powered World
  • Anonymous on The Dilemma of the OAuth Token Collector
  • Anonymous on The Dilemma of the OAuth Token Collector

What I’m Blogging About

Application-Centric IdM Burton Catalyst Conference Cloud Computing Cloud Identity Model Facebook Federated Provisioning Identity Governance Identity Governance Framework Identity in Social Networking Identity Management Identity Services IGF OpenID Oracle Identity Management Oracle Identity Manager Oracle OpenWorld Oracle_IDM Password Management Personal Identity Management Privacy Provisioning Risk Management Role Management Service-Oriented Security User-Centric Identity

Connect

Twitter Follow @NishantK

LinkedIn Connect on LinkedIn

Slideshare View Nishant's Presentations

About Me nishantkaushik.com

Categories

  • Ask Dr. K (11)
  • Identity Services (36)
  • Identropy IDaaS (2)
  • Insight IdM (124)
  • Oracle Identity Management (61)
  • Personal Identity Management (32)
  • The Cloud Identity Series (17)
  • Tips & Techniques (4)
  • User-Centric Identity (24)

Archives

  • ► 2013 (3)
    • April (1)
    • February (1)
    • January (1)
  • ► 2012 (13)
    • November (2)
    • August (3)
    • July (2)
    • June (2)
    • May (1)
    • February (3)
  • ► 2011 (29)
    • December (1)
    • November (1)
    • October (1)
    • September (2)
    • August (3)
    • July (4)
    • June (5)
    • May (3)
    • April (4)
    • February (2)
    • January (3)
  • ► 2010 (33)
    • December (1)
    • October (1)
    • September (4)
    • August (5)
    • July (6)
    • June (4)
    • May (3)
    • April (2)
    • March (3)
    • February (2)
    • January (2)
  • ► 2009 (24)
    • December (1)
    • November (1)
    • October (3)
    • September (3)
    • August (4)
    • July (2)
    • June (2)
    • May (3)
    • April (1)
    • February (2)
    • January (2)
  • ► 2008 (44)
    • December (1)
    • October (4)
    • September (4)
    • August (8)
    • July (11)
    • June (4)
    • May (2)
    • April (2)
    • March (3)
    • February (3)
    • January (2)
  • ► 2007 (56)
    • December (3)
    • November (5)
    • October (6)
    • September (5)
    • August (8)
    • July (5)
    • June (9)
    • May (3)
    • April (2)
    • March (5)
    • February (5)
  • ► 2006 (33)
    • December (4)
    • November (2)
    • October (6)
    • September (1)
    • August (2)
    • July (3)
    • June (5)
    • May (3)
    • April (2)
    • March (5)

Disclaimer

Talking Identity is my exploration of the world of Identity Management. The views expressed on this blog are my own and do not necessarily reflect the views of Identropy (doesn't mean I'm not trying hard to mold them in my own image).

Copyright © 2005-2013 Nishant Kaushik. All Rights Reserved.