Network access question
- 26 July, 2005 10:33
- Comments
When it comes to access, authentication and logon - are you still using simple passwords? You know, minimum six characters (or even four), case insensitive, no requirement for mixed alphanumerics or special characters.
As security expert Bruce Schneier said recently: "Passwords just don't work anymore. As computers have gotten faster, password guessing has gotten easier. Ever-more-complicated passwords are required to evade password-guessing software. At the same time, there's an upper limit to how complex a password users can be expected to remember."
I'm bringing this up because Sun recently announced it would be donating its enterprise single sign-on (ESSO) technology to the open source movement.
The OpenSSO project, if it follows the trend of other major open source projects, should lead to very workable, easily implemented and very inexpensive ESSO. That means if you don't already have an ESSO project implemented or in planning, you'll soon be facing enormous pressure to do so.
ESSO is a tempting technology. We want to make passwords stronger by requiring longer strings of mixed-case letters and numerics with a special character or two thrown in.
But users who can't remember multiple simple passwords have no hope of remembering multiple complex passwords. Either they'll write them on notes that they tape to their monitor - or, here's a sneaky trick: on the underside of the desk blotter. (I wonder where their spare front door key is!)
A good ESSO package allows you to have a single password in order to access the resources and services on a network. Of course, if there's only one password needed to access all of a user's privileges, then it should be particularly strong. But strings such as Asdf2 percentWssd43!!AZgf will not be remembered by users. So it's time to think about strong authentication based on one-time passwords, smart cards/proximity cards or even biometrics.
There have been major advances in these areas over the past few years, so recheck if you dismissed them as either too pricey or unworkable some time ago.
If you're into open source, then check first with the Initiative for Open Authentication (OATH). There is lots of information, pointers, protocols and specifications to get you started on the road to the strong authentication that will be necessary for your ESSO environment.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Consolidated Storage for Virtualised Server Environments
- Fixing Your Dropbox Problem - How the Right Data Protection Strategy Can Help
- Enterprise Buyers Guide for Printers
- Printer Usage and Cost Management Strategies for the Australian Mid-market, an Unrealised Opportunity
- Reducing Costs Through Better Server Utilisation
-
NBN service plans won't cost consumers more: Conroy
-
Opinion: Windows 8 tablets - A disaster in the making
-
Australian prisoners chipped as part of a new RFID trial
-
NBN service plans won't cost consumers more: Conroy
-
Glitchy state software system leads to botched payments for foster care providers
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Teach Yourself Visually Windows 7
-
Windows 7 for Seniors for Dummies®
-
Windows 7 for Dummies®
-
Microsoft Office
-
MYOB Software for Dummies 6E Australian Edition








Comments
Post new comment