SC Magazine on whether or not authentication is sufficient
Charles Jeter, myself, and a few others have been having an interesting email discussion over the weekend. The discussion was around whether or not the rumored updates to the FFIEC guidelines will be sufficient.
Many people are saying that the guidelines are going to re-emphasize that financial institutions need to have strong authentication mechanisms in place. While that is necessary, my belief is that because of technology like Zeus, strong authentication is not sufficient.
In the email thread there was some discussion on the definition of “authentication”. The point being made was that authentication can mean verifying identity OR verifying legitimacy. My stance is that most people know the first definition and not the second.
Read more on the first part of the article here.
1 Comment »
Leave a Reply
-
Archives
- February 2012 (5)
- January 2012 (4)
- December 2011 (7)
- November 2011 (8)
- October 2011 (9)
- September 2011 (5)
- August 2011 (7)
- July 2011 (7)
- June 2011 (6)
- May 2011 (4)
- April 2011 (6)
- March 2011 (5)
-
Categories
- behavior analysis
- business logic abuse
- Business Logic Flaw
- Business Process Abuse
- Compliance
- Cost of fraud
- Data Loss
- Detection
- education
- Fraud
- Gaming
- General
- information security
- Investigation
- Man-in-the-Browser
- Online Fraud
- Payment
- Phishing
- predictive analytics
- Prevention
- risk management
- Social engineering
- Social Networks
- Trust
- Uncategorized
- web logic abuse
- Zeus
-
RSS
Entries RSS
Comments RSS


[...] This post was mentioned on Twitter by Laura Mather, Michael Stanton. Michael Stanton said: SC Magazine on whether or not authentication is sufficient: Charles Jeter, myself, and a few others have been ha… http://bit.ly/f2HQz8 [...]
Pingback by Tweets that mention SC Magazine on whether or not authentication is sufficient « Silver Tail Blog -- Topsy.com | January 24, 2011 |