Andras Cser serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
New Year's Resolutions for choosing online retailers
Posted by Andras Cser on December 20, 2007
- 214 Recommendations
- 0 comments
With CardSpace and Higgins being in nascant and almost non-existent market adoption mode, you may wonder what authentication features you want to be looking for when shopping online. Usernames and passwords are a thing of the past: you can safely assume that you will use a computer to log in which has a keylogger or trojan capturing your keystrokes, and with it your username and password.
Savvy customers are increasingly turning towards online retailers and financial institutions which provide at least some form of multi-factor authentication to protect against password theft. The following list gives a compass to consumers and vendors to navigate the misty waters of online transactions.
Smart cards / USB tokens (very costly, high level of security, great user inconvenience)
Hardware based solution that contains applications, PKI certificates used to authenticate to a site. These cards can include a magstripe for physical access management and RFID proximity sensors.
Vendors: ActivIdentity, Aladdin Knowledge Systems, CRYPTOcard, EntrusT, PortWise, RSA Security, VASCO Data Security
One time password hardware token (very costly, high level of security, great user inconvenience)
Token generates a one time password that the user must input during login.
Vendors: ActivIdentity, Entrust, CRYPTOcard, Secure Computing Safeword, RSA Security, VASCO Data Security
One time password software (costly, medium level of security, medium user inconvenience)
User has a portable device (cell phone) with software that generates OTP.
Vendors: ActivIdentity, Entrust, CRYPTOcard, PortWise, RSA Security, VASCO Data Security
Wallet card (scratchpad, gridcard) (inexpensive, low level of security, medium user inconvenience)
User has a list of OTP passwords printed on a sheet or a grid card of letters and numbers that the user has to enter when logging in.
Vendors: Entrust
Out of band authentication (costly, medium level of security, medium level of user inconvenience)
User receives a secondary one time password in a text message or callback to their registered cell phone.
Vendors: Authentify Technology, Digital Resolve, RSA Security/PassMark Software, Swivel Secure
Device fingerprint (inexpensive, low to medium level of security, low user inconvenience)
Upon login, the user’s desktop software, hardware and browser environment generate a unique fingerprint. If the user’s desktop changes, user is prompted for additional knowledge based authentication (i.e. must answer multiple security question and answer pairs correctly in addition to providing the correct username and password).
Vendors: Oracle Adaptive Authentication Manager (Bharosa acquisition), Digital Envoy, Entrust, iovation, RSA Security
File-based device authentication (inexpensive, low to medium level of security, low user inconvenience)
Website puts a cookie on the user’s browser and uses the cookie to display a user-selected image the next time logs in. This method authenticates the website to the user (mutual authentication).
Vendors: Arcot Systems, TriCipher, Oracle Adaptive Authentication Manager (Bharosa acquisition), Entrust, RSA Security/PassMark Software
IP Geolocation (inexpensive, low level of security, low user inconvenience)
Inbound access management looks at the user’s IP address to check for plausible velocity of logins (user can’t legitimately login within 30 minutes from a IP address in the US and China).
Vendors: Digital Element, Quova, Oracle Adaptive Authentication Manager (Bharosa acquisition)
Keystroke dynamics (inexpensive, medium level of security, medium user inconvenience)
User’s keystroke dynamics for entering the username and password (for how long the user presses a key and how long it takes them to move between keys) is used as a second factor for authentication.
Vendors: BioPassword, iMagic Software
Categories:
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (31)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (20)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- Identity and access management (7)
- Security & Risk (2)
- Acquisition (1)
- application security (1)
- cloud (1)
- Enterprise Role Management (1)
- IT Risk Management (1)
- IT security (1)
- provisioning (1)
- RSA (1)
- See all
Archives
- May 2013 (3)
- April 2013 (3)
- February 2013 (2)
- May 2012 (2)
- April 2012 (1)
- March 2012 (1)
- December 2011 (1)
- June 2011 (1)
- March 2011 (1)
- February 2011 (3)
- October 2010 (1)
- September 2010 (1)
- June 2010 (1)
- See all