Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -1,20 +1,20 @@
|
||||
# Users and Authentication
|
||||
|
||||
- Users must be *identified* to enable:
|
||||
- User specific access controls
|
||||
- Individuals accountability for activities
|
||||
- User specific access controls
|
||||
- Individuals’ accountability for activities
|
||||
- Claimed identities must be authenticated
|
||||
- First line of system protection
|
||||
- Safeguards against abuse by external parties or unauthorised insiders
|
||||
- First line of system protection
|
||||
- Safeguards against abuse by external parties or unauthorised insiders
|
||||
|
||||
##### Authentication Methods
|
||||
|
||||
1. Something the user *knows*
|
||||
- passwords, PINs
|
||||
- passwords, PINs
|
||||
2. Something the user *has*
|
||||
- a card, a token
|
||||
- a card, a token
|
||||
3. Something the user *is*
|
||||
- a bio-metric so a finger print or the users face
|
||||
- a biometric, so a fingerprint or the user’s face
|
||||
|
||||
#### Passwords
|
||||
|
||||
@@ -28,8 +28,8 @@ On one level they are very usable
|
||||
Ease of use is often because users have not been made to use them properly
|
||||
|
||||
- Users make poor selections
|
||||
- Dictionary words
|
||||
- things that people could guess or social engineer
|
||||
- Dictionary words
|
||||
- things that people could guess or social engineer
|
||||
- Use the same password on multiple systems
|
||||
- Share them with other people
|
||||
- Write them down in discoverable places
|
||||
@@ -38,14 +38,14 @@ Ease of use is often because users have not been made to use them properly
|
||||
|
||||
#### Current Guidance on Password Systems
|
||||
|
||||
- The latest NIST recommendation advise:
|
||||
- Against automatic password expiry
|
||||
- Passwords should only be changed when there’s a reason
|
||||
- Against imposing rules for complex passwords
|
||||
- Length matters more than complexity
|
||||
- Against password hints or knowledge-based authentication
|
||||
- Social media means these can be socially engineered
|
||||
- To enable “show password while typing” and to allow paste-in password fields
|
||||
- The latest NIST recommendations advise:
|
||||
- Against automatic password expiry
|
||||
- Passwords should only be changed when there’s a reason
|
||||
- Against imposing rules for complex passwords
|
||||
- Length matters more than complexity
|
||||
- Against password hints or knowledge-based authentication
|
||||
- Social media means these can be socially engineered
|
||||
- To enable “show password while typing” and to allow paste-in password fields
|
||||
|
||||
> Passwords are a **broken mechanism**
|
||||
>
|
||||
@@ -57,12 +57,12 @@ Browsers can now auto-generate passwords for us
|
||||
|
||||
- Avoids users making poor decisions
|
||||
- But also avoids us
|
||||
- Knowing what the password is
|
||||
- Needing to know the good practice
|
||||
- Knowing what the password is
|
||||
- Needing to know the good practice
|
||||
|
||||
Some devices may not support password entry
|
||||
|
||||
- For example dictating a password to an Alexa or google home
|
||||
- For example dictating a password to an Alexa or Google Home
|
||||
- Mobile devices with small keyboards can be tricky
|
||||
|
||||
#### Token-based Authentication
|
||||
@@ -75,23 +75,23 @@ Some devices may not support password entry
|
||||
- Wearable devices
|
||||
- Smartphones
|
||||
|
||||
Often combined with a secret knowledge to form a 2-stage / 2-factor authentication
|
||||
Often combined with secret knowledge to form 2-stage / 2-factor authentication
|
||||
|
||||
- e.g. using an ATM requires card and pin
|
||||
|
||||
Smartphone apps can proveide the same functionality as authentication tokens (i.e. computing OTP)
|
||||
Smartphone apps can provide the same functionality as authentication tokens (i.e. computing OTP)
|
||||
|
||||
- The users no longer need a separate, dedicated device
|
||||
- Think nationwide card reader for transfers
|
||||
- Think Nationwide card reader for transfers
|
||||
- Relies on the security of the smartphone
|
||||
- User authentication on the device and or the app
|
||||
- Prevention of compromise via attacks
|
||||
- User authentication on the device and or the app
|
||||
- Prevention of compromise via attacks
|
||||
|
||||
#### Biometrics
|
||||
|
||||
- Theoretically far more usable
|
||||
- Nothing for the user to remember
|
||||
- Nothing for them to lose or leave behind
|
||||
- Nothing for the user to remember
|
||||
- Nothing for them to lose or leave behind
|
||||
|
||||

|
||||
|
||||
@@ -114,19 +114,19 @@ Biometrics can be copied, but not easily
|
||||
###### Biometrics Errors
|
||||
|
||||
- **F**alse **R**ejection **R**ate (**FRR**)
|
||||
- Errors where the system falsely identifies the legitimate user as an imposter
|
||||
- Also known as False Alarm Rate or Type I error
|
||||
- Errors where the system falsely identifies the legitimate user as an imposter
|
||||
- Also known as False Alarm Rate or Type I error
|
||||
- **F**alse **A**cceptance **R**ate (**FAR**)
|
||||
- Errors where imposters are falsely believed to be legitimate users
|
||||
- Also known as Impostor Pass Rate or Type II error
|
||||
- Errors where imposters are falsely believed to be legitimate users
|
||||
- Also known as Impostor Pass Rate or Type II error
|
||||
- **E**qual **E**rror **R**ate (**EER**)
|
||||
- The point at which FAR and FRR coincide
|
||||
- The measure normally used to assess biometric products
|
||||
- Failure to Enroll
|
||||
- Errors in which the system is unable to establish as biometric template for a proposed user
|
||||
- e.g. some people don’t have finger prints, some reglions require face covering
|
||||
- The point at which FAR and FRR coincide
|
||||
- The measure normally used to assess biometric products
|
||||
- Failure to Enrol
|
||||
- Errors in which the system is unable to establish a biometric template for a proposed user
|
||||
- e.g. some people don’t have fingerprints, some religions require face covering
|
||||
- Failure to Acquire
|
||||
- Errors in which the system is unable to successfully acquire the information required to make a decision
|
||||
- Errors in which the system is unable to successfully acquire the information required to make a decision
|
||||
|
||||
A legitimate user’s experience of biometrics will be informed by:
|
||||
|
||||
@@ -140,13 +140,13 @@ Developers focus can change on implementation. For example if being used as a pa
|
||||
##### Modes of Use
|
||||
|
||||
- **Verification**
|
||||
- User claims an identity - authentication against that identity
|
||||
- One-to-one match (1:1)
|
||||
- Less unique characteristics can be ultised
|
||||
- User claims an identity - authentication against that identity
|
||||
- One-to-one match (1:1)
|
||||
- Less unique characteristics can be utilised
|
||||
- **Identification**
|
||||
- Users’ biometric sample is compared against all in database
|
||||
- One-to-Many match (1:N)
|
||||
- Only the more unique biometrics can be ultised - fingerprints, iris, retina etc
|
||||
- Users’ biometric sample is compared against all in database
|
||||
- One-to-Many match (1:N)
|
||||
- Only the more unique biometrics can be utilised - fingerprints, iris, retina etc
|
||||
|
||||
### 2-Factor Authentication
|
||||
|
||||
@@ -156,4 +156,4 @@ Two-factor and multi-factor Authentication
|
||||
- Typical implementations have been a password & token
|
||||
- Ideally you want factors from different categories
|
||||
|
||||

|
||||

|
||||
Reference in new issue
Block a user