• Speaking
  • Downloads
  • About Talking Identity
  • About Me

The Conundrum of 2FA meets the Enigma that is PAM

  • Posted on:April 24, 2013
  • Posted in:The Cloud Identity Series
  • Posted by:Nishant Kaushik
1

“It’s a mystery. Broken into a jigsaw puzzle. Wrapped in a conundrum. Hidden in a Chinese box. A riddle.” – The Riddler, The Long Halloween Yesterday’s hack of the AP’s Twitter account was big. Not only did the impact it had on the stock market prove Ranjeet’s thesis that Twitter is now a SOX (Sarbanes-Oxley)…

Read More
Tags: Multi-Factor AuthenticationPasswords Must DiePrivileged Account ManagementShared AccountsTwitter

The Dilemma of the OAuth Token Collector

  • Posted on:February 5, 2013
  • Posted in:Personal Identity Management
  • Posted by:Nishant Kaushik
6

‘Tis the season to be hacked, I guess. Twitter joined a bunch of other companies in revealing that it was the target of a sophisticated attack that may have exposed the information for about 250,000 users. While the data that was allegedly exposed, including encrypted/salted versions of passwords, was not as bad as in some…

Read More
Tags: Hack AttackOAuthPasswords Must DieToken ManagementTwitter

The Epic Hacking of Mat Honan and Our Identity Challenge

  • Posted on:August 7, 2012
  • Posted in:Personal Identity Management, The Cloud Identity Series
  • Posted by:Nishant Kaushik
4

Wired has the kind of article that will make all of us leading highly digitized lives (is that the right term?) wake up in a cold sweat. While the title – How Apple and Amazon Security Flaws Led to My Epic Hacking – may strike many as sensationalist, the article does a good job of…

Read More
Tags: Amazon SecurityApple SecurityGMail SecurityIdentity AssuranceIdentity ProvidersIdentity VerificationMat HonanNSTICPassword ManagementPassword Recovery TechniquesPasswords Must Die

Protecting Yourself While Using Cloud Services

  • Posted on:November 3, 2011
  • Posted in:Personal Identity Management
  • Posted by:Nishant Kaushik
0

I was recently asked to comment on the top 5 ways to protect yourself (as an individual) when using the cloud. Obviously I brought a very identity-centric slant to it, but it was an interesting exercise as I tried to put down on paper (!) the steps I take to protect myself daily. I thought…

Read More
Tags: Cloud SecurityPassword ManagementPasswords Must DiePersonal Identity Management

FFIEC Updates Their Guidance. And The Winner Is…

  • Posted on:June 29, 2011
  • Posted in:Insight IdM
  • Posted by:Nishant Kaushik
1

In my last post, I mentioned that the FFIEC was preparing an update to their 2005 guidance on internet banking authentication. Well, that update is out, and Anil John couldn’t wait to let me know about it (:)). The update, entitled ‘Supplement to Authentication in an Internet Banking Environment‘ recognizes both the growth in online…

Read More
Tags: Federated IdentityFFIECIdentity ContextMulti-Factor AuthenticationOnline BankingOracle Adaptive Access ManagerPasswords Must DieRisk ManagementSecurity Architecture

So What Does Constitute “Reasonable” Security?

  • Posted on:June 23, 2011
  • Posted in:Insight IdM
  • Posted by:Nishant Kaushik
0

A couple of weeks ago, I tweeted about what I called a must-read article by Brian Krebs. Fellow identirati Anil John lamented yesterday that we hadn’t discussed this more in the community, and on second glance I can see why. The article covers a court case where the magistrate was basically asked to decide what…

Read More
Tags: FFIECIdentity ContextMulti-Factor AuthenticationOnline BankingPasswords Must DieRisk ManagementSecurity Architecture

Recent Posts

The Conundrum of 2FA meets the Enigma that is PAM
"It's a mystery. Broken into a jigsaw puzzle. Wrapped in a conun...
The Dilemma of the OAuth Token Collector
'Tis the season to be hacked, I guess. Twitter joined a bunch of...
Why 2013 will be 'The Year of the SCUID'
I'm just now coming back to earth from the high I've been on sin...
The IDaaS Powered World
Last week I was in Colorado for the Defrag and Blur conferences....
What Happens When Telco's Declare SMS 'Unsafe'?
If you've been following Authentication related discussions, you...

Recent Comments

  • Bob Pinheiro on The Conundrum of 2FA meets the Enigma that is PAM
  • NishantKaushik on The IDaaS Powered World
  • Nikolaj Ivancic on The IDaaS Powered World
  • Anonymous on The Dilemma of the OAuth Token Collector
  • Anonymous on The Dilemma of the OAuth Token Collector

What I’m Blogging About

Application-Centric IdM Burton Catalyst Conference Cloud Computing Cloud Identity Model Facebook Federated Provisioning Identity Governance Identity Governance Framework Identity in Social Networking Identity Management Identity Services IGF OpenID Oracle Identity Management Oracle Identity Manager Oracle OpenWorld Oracle_IDM Password Management Personal Identity Management Privacy Provisioning Risk Management Role Management Service-Oriented Security User-Centric Identity

Connect

Twitter Follow @NishantK

LinkedIn Connect on LinkedIn

Slideshare View Nishant's Presentations

About Me nishantkaushik.com

Categories

  • Ask Dr. K (11)
  • Identity Services (36)
  • Identropy IDaaS (2)
  • Insight IdM (124)
  • Oracle Identity Management (61)
  • Personal Identity Management (32)
  • The Cloud Identity Series (17)
  • Tips & Techniques (4)
  • User-Centric Identity (24)

Archives

  • ► 2013 (3)
    • April (1)
    • February (1)
    • January (1)
  • ► 2012 (13)
    • November (2)
    • August (3)
    • July (2)
    • June (2)
    • May (1)
    • February (3)
  • ► 2011 (29)
    • December (1)
    • November (1)
    • October (1)
    • September (2)
    • August (3)
    • July (4)
    • June (5)
    • May (3)
    • April (4)
    • February (2)
    • January (3)
  • ► 2010 (33)
    • December (1)
    • October (1)
    • September (4)
    • August (5)
    • July (6)
    • June (4)
    • May (3)
    • April (2)
    • March (3)
    • February (2)
    • January (2)
  • ► 2009 (24)
    • December (1)
    • November (1)
    • October (3)
    • September (3)
    • August (4)
    • July (2)
    • June (2)
    • May (3)
    • April (1)
    • February (2)
    • January (2)
  • ► 2008 (44)
    • December (1)
    • October (4)
    • September (4)
    • August (8)
    • July (11)
    • June (4)
    • May (2)
    • April (2)
    • March (3)
    • February (3)
    • January (2)
  • ► 2007 (56)
    • December (3)
    • November (5)
    • October (6)
    • September (5)
    • August (8)
    • July (5)
    • June (9)
    • May (3)
    • April (2)
    • March (5)
    • February (5)
  • ► 2006 (33)
    • December (4)
    • November (2)
    • October (6)
    • September (1)
    • August (2)
    • July (3)
    • June (5)
    • May (3)
    • April (2)
    • March (5)

Disclaimer

Talking Identity is my exploration of the world of Identity Management. The views expressed on this blog are my own and do not necessarily reflect the views of Identropy (doesn't mean I'm not trying hard to mold them in my own image).

Copyright © 2005-2013 Nishant Kaushik. All Rights Reserved.