<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://consultingblogs.emc.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>John Brookmyre's Blog : Multiple factor authentication</title><link>http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Multiple+factor+authentication/default.aspx</link><description>Tags: Multiple factor authentication</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP3 (Build: 20423.1)</generator><item><title>I know I am me...</title><link>http://consultingblogs.emc.com/johnbrookmyre/archive/2009/01/29/i-know-i-am-me.aspx</link><pubDate>Thu, 29 Jan 2009 21:35:00 GMT</pubDate><guid isPermaLink="false">e847c0e7-38d9-45c0-b593-56747303e088:14067</guid><dc:creator>john.brookmyre</dc:creator><slash:comments>1</slash:comments><comments>http://consultingblogs.emc.com/johnbrookmyre/comments/14067.aspx</comments><wfw:commentRss>http://consultingblogs.emc.com/johnbrookmyre/commentrss.aspx?PostID=14067</wfw:commentRss><description>&lt;p&gt;&lt;i&gt;Moving into the multiple factor authentication World (crypto calculators, tags etc) it looks like we may all have a lot of these different devices to authenticate our selves, here are my ramblings on the subject...&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;Does anyone else have a bank account which uses crypto calculators, tags or mobile phone codes to validate a transaction? Two factor authentication is fast becoming the norm in the fight to reduce fraud, which cannot be argued against, but what about me as a user? How many times have you needed to do an online transaction and realised that you have left your calculator at work for the weekend or you can only find the one for you other account(s)... Or you are at home trying to check your work emails only to find that you have left your tag somewhere else? These scenarios happen to me quite a lot and I have two tags and two crypto calculators... If we look at the natural progression with fraudsters getting better and more and more information been stored on us, it wouldn't be a massive leap of faith to imagine that we are going to get a lot of these calculators and tags - perhaps &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.tesco.co.uk"&gt;Tesco&lt;/a&gt;, &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.amazon.co.uk"&gt;Amazon&lt;/a&gt; and &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.ebay.co.uk"&gt;EBay&lt;/a&gt; will start to require this level of authentication and maybe this will balloon to all web-sites which require any form of authentication... Live Mesh / Cloud too - this may sound a little far fetched, but look at the explosion of store cards for similarities where some people have upwards of 10 cards. This could also be used for the authentication for cloud computing too which will need some stringent security to gain widespread adoption.&lt;/p&gt;  &lt;p&gt;I was impressed recently when I could use my &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.google.co.uk"&gt;Google&lt;/a&gt; Account to access other sites using OpenID and equally impressed when I was able to use &lt;a href="http://www.mapmyrun.com/login"&gt;Map My Run&lt;/a&gt; with my &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.facebook.com"&gt;Facebook&lt;/a&gt; credentials. From &lt;a href="http://en.wikipedia.org/wiki/OpenID"&gt;Wikipedia&lt;/a&gt;:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p align="center"&gt;&lt;i&gt;OpenID is an open, decentralized user identification standard, allowing users to log onto many services with the same &lt;/i&gt;&lt;i&gt;digital identity&lt;/i&gt;&lt;i&gt;. &lt;/i&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Can we have a consolidation?Is it possible for the banks (maybe not a time where they are looking to invest, but they could take a fee to sign web-sites up) or Google, OpenID, MS Passport, et al to use this concept to come together to offer users the single tag or device to provide the two factor sign on mechanism? There would surely be a lot of benefits to this approach in the fight against crime too, having one confederated repository for the use of authentication would enable analytical techniques to clearly spot potential fraud patterns or none normal behaviours which could be visualised in any number of ways or have advanced algorithms to highlight risks. &lt;/p&gt;  &lt;p align="center"&gt;&lt;a href="http://blogs.conchango.com/blogs/johnbrookmyre/WindowsLiveWriter/Movingintothemultiplefactorauthenticatio_CA0C/image_2.png"&gt;&lt;img src="http://blogs.conchango.com/blogs/johnbrookmyre/WindowsLiveWriter/Movingintothemultiplefactorauthenticatio_CA0C/image_thumb.png" style="border-width:0px;" alt="image" border="0" width="240" height="240"&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;  &lt;p&gt;Social network visualisation techniques could be used to show the interactions of users / access points / accounts over time or a tool like &lt;a href="http://www.deticanetreveal.com/"&gt;Net Reveal&lt;/a&gt; from &lt;a href="http://www.detica.com/"&gt;Detica&lt;/a&gt; could be used to power the investigation.&lt;/p&gt;  &lt;p&gt;This could be enriched by including other facets to fight the fraud, why can't banks be on &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.facebook.com"&gt;Facebook&lt;/a&gt;, &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.twitter.com"&gt;Twitter&lt;/a&gt; (and other social tools which have widespread adoption) keeping an eye on my status so it knows where I am or where I am planning to go or share the data which the Government has (owning chunks of the banks may offer some positives) on us or the data which my phone provider has on my location? On these issues the question of big brother, risk of data loss and where to stop always comes into play - but I would happily allow my bank to follow my &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.twitter.com"&gt;Twitter&lt;/a&gt;, &lt;a href="https://blogs.conchango.com/controlpanel/blogs/www.facebook.com"&gt;Facebook&lt;/a&gt; status and movements to purely ensure the safety of my hard earned. Would you?&lt;/p&gt;  &lt;p&gt;As always, any comments and thoughts would be really welcome. Thanks to everyone who has linked to me so far and left comments - much appreciated! Especially &lt;a href="http://www.retailmonster.co.uk/blog/blogger.html"&gt;Pete Hanlon&lt;/a&gt; and &lt;a href="http://cwebbbi.spaces.live.com/"&gt;Chris Webb&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;John&lt;/p&gt;  &lt;div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:75103eb5-3202-4b4b-af24-c3ad41bcbab5" style="margin:0px;padding:0px;display:inline;float:none;"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Business%20Intelligence" rel="tag"&gt;Business Intelligence&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Data%20Visualisation" rel="tag"&gt;Data Visualisation&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Data%20Visualization" rel="tag"&gt;Data Visualization&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Cloud" rel="tag"&gt;Cloud&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Analytics" rel="tag"&gt;Analytics&lt;/a&gt;,&lt;a href="http://technorati.com/tags/OpenID" rel="tag"&gt;OpenID&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Confederated%20Data" rel="tag"&gt;Confederated Data&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Statistics" rel="tag"&gt;Statistics&lt;/a&gt;,&lt;a href="http://technorati.com/tags/John%20Brookmyre" rel="tag"&gt;John Brookmyre&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Conchango" rel="tag"&gt;Conchango&lt;/a&gt;,&lt;a href="http://technorati.com/tags/EMC%20Consulting" rel="tag"&gt;EMC Consulting&lt;/a&gt;,&lt;a href="http://technorati.com/tags/security" rel="tag"&gt;security&lt;/a&gt;,&lt;a href="http://technorati.com/tags/multiple%20factor%20authentication" rel="tag"&gt;multiple factor authentication&lt;/a&gt;&lt;/div&gt;&lt;img src="http://consultingblogs.emc.com/aggbug.aspx?PostID=14067" width="1" height="1"&gt;</description><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/User+Adoption/default.aspx">User Adoption</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Conchango/default.aspx">Conchango</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/BI/default.aspx">BI</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/User+Experience/default.aspx">User Experience</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Business+Intelligence/default.aspx">Business Intelligence</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/John+Brookmyre/default.aspx">John Brookmyre</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Data+Visualization/default.aspx">Data Visualization</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Data+Visualisation/default.aspx">Data Visualisation</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Data+Analysis/default.aspx">Data Analysis</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Statistics/default.aspx">Statistics</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Consultants/default.aspx">Consultants</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Analytics/default.aspx">Analytics</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Authentication/default.aspx">Authentication</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Security/default.aspx">Security</category><category domain="http://consultingblogs.emc.com/johnbrookmyre/archive/tags/Multiple+factor+authentication/default.aspx">Multiple factor authentication</category></item></channel></rss>