This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

@@ -1,20 +1,20 @@
# Users and Authentication
- Users must be *identified* to enable:
- User specific access controls
- Individuals accountability for activities
- User specific access controls
- Individuals’ accountability for activities
- Claimed identities must be authenticated
- First line of system protection
- Safeguards against abuse by external parties or unauthorised insiders
- First line of system protection
- Safeguards against abuse by external parties or unauthorised insiders
##### Authentication Methods
1. Something the user *knows*
- passwords, PINs
- passwords, PINs
2. Something the user *has*
- a card, a token
- a card, a token
3. Something the user *is*
- a bio-metric so a finger print or the users face
- a biometric, so a fingerprint or the user’s face
#### Passwords
@@ -28,8 +28,8 @@ On one level they are very usable
Ease of use is often because users have not been made to use them properly
- Users make poor selections
- Dictionary words
- things that people could guess or social engineer
- Dictionary words
- things that people could guess or social engineer
- Use the same password on multiple systems
- Share them with other people
- Write them down in discoverable places
@@ -38,14 +38,14 @@ Ease of use is often because users have not been made to use them properly
#### Current Guidance on Password Systems
- The latest NIST recommendation advise:
- Against automatic password expiry
- Passwords should only be changed when there’s a reason
- Against imposing rules for complex passwords
- Length matters more than complexity
- Against password hints or knowledge-based authentication
- Social media means these can be socially engineered
- To enable “show password while typing” and to allow paste-in password fields
- The latest NIST recommendations advise:
- Against automatic password expiry
- Passwords should only be changed when there’s a reason
- Against imposing rules for complex passwords
- Length matters more than complexity
- Against password hints or knowledge-based authentication
- Social media means these can be socially engineered
- To enable “show password while typing” and to allow paste-in password fields
> Passwords are a **broken mechanism**
>
@@ -57,12 +57,12 @@ Browsers can now auto-generate passwords for us
- Avoids users making poor decisions
- But also avoids us
- Knowing what the password is
- Needing to know the good practice
- Knowing what the password is
- Needing to know the good practice
Some devices may not support password entry
- For example dictating a password to an Alexa or google home
- For example dictating a password to an Alexa or Google Home
- Mobile devices with small keyboards can be tricky
#### Token-based Authentication
@@ -75,23 +75,23 @@ Some devices may not support password entry
- Wearable devices
- Smartphones
Often combined with a secret knowledge to form a 2-stage / 2-factor authentication
Often combined with secret knowledge to form 2-stage / 2-factor authentication
- e.g. using an ATM requires card and pin
Smartphone apps can proveide the same functionality as authentication tokens (i.e. computing OTP)
Smartphone apps can provide the same functionality as authentication tokens (i.e. computing OTP)
- The users no longer need a separate, dedicated device
- Think nationwide card reader for transfers
- Think Nationwide card reader for transfers
- Relies on the security of the smartphone
- User authentication on the device and or the app
- Prevention of compromise via attacks
- User authentication on the device and or the app
- Prevention of compromise via attacks
#### Biometrics
- Theoretically far more usable
- Nothing for the user to remember
- Nothing for them to lose or leave behind
- Nothing for the user to remember
- Nothing for them to lose or leave behind
![1645038798.png](img/1645038798.png)
@@ -114,19 +114,19 @@ Biometrics can be copied, but not easily
###### Biometrics Errors
- **F**alse **R**ejection **R**ate (**FRR**)
- Errors where the system falsely identifies the legitimate user as an imposter
- Also known as False Alarm Rate or Type I error
- Errors where the system falsely identifies the legitimate user as an imposter
- Also known as False Alarm Rate or Type I error
- **F**alse **A**cceptance **R**ate (**FAR**)
- Errors where imposters are falsely believed to be legitimate users
- Also known as Impostor Pass Rate or Type II error
- Errors where imposters are falsely believed to be legitimate users
- Also known as Impostor Pass Rate or Type II error
- **E**qual **E**rror **R**ate (**EER**)
- The point at which FAR and FRR coincide
- The measure normally used to assess biometric products
- Failure to Enroll
- Errors in which the system is unable to establish as biometric template for a proposed user
- e.g. some people don’t have finger prints, some reglions require face covering
- The point at which FAR and FRR coincide
- The measure normally used to assess biometric products
- Failure to Enrol
- Errors in which the system is unable to establish a biometric template for a proposed user
- e.g. some people don’t have fingerprints, some religions require face covering
- Failure to Acquire
- Errors in which the system is unable to successfully acquire the information required to make a decision
- Errors in which the system is unable to successfully acquire the information required to make a decision
A legitimate user’s experience of biometrics will be informed by:
@@ -140,13 +140,13 @@ Developers focus can change on implementation. For example if being used as a pa
##### Modes of Use
- **Verification**
- User claims an identity - authentication against that identity
- One-to-one match (1:1)
- Less unique characteristics can be ultised
- User claims an identity - authentication against that identity
- One-to-one match (1:1)
- Less unique characteristics can be utilised
- **Identification**
- Users’ biometric sample is compared against all in database
- One-to-Many match (1:N)
- Only the more unique biometrics can be ultised - fingerprints, iris, retina etc
- Users’ biometric sample is compared against all in database
- One-to-Many match (1:N)
- Only the more unique biometrics can be utilised - fingerprints, iris, retina etc
### 2-Factor Authentication
@@ -156,4 +156,4 @@ Two-factor and multi-factor Authentication
- Typical implementations have been a password & token
- Ideally you want factors from different categories
![1645040432.png](img/1645040432.png)
![1645040432.png](img/1645040432.png)