{"id":4213,"date":"2013-10-10T07:00:51","date_gmt":"2013-10-10T15:00:51","guid":{"rendered":"http:\/\/formtek.com\/blog\/?p=4213"},"modified":"2013-11-12T02:25:14","modified_gmt":"2013-11-12T10:25:14","slug":"security-multi-factor-authentication-replacing-standard-passwords","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-multi-factor-authentication-replacing-standard-passwords\/","title":{"rendered":"Security: Multi-Factor Authentication Replacing Standard Passwords"},"content":{"rendered":"<p>Security is by far the number one concern that most businesses cite when considering a move of any of their data to the cloud.  To counter these concerns, cloud vendors are doing all they can  to improve security.  For example, vendors certifying cloud data centers for SAS 70 compliant, encrypting all web pages and service interactions with SSL, and performing frequent security audits.<\/p>\n<div>But despite these many attempts to improve cloud security, what&#8217;s often the <a title=\"Achilles heel of cloud services\" href=\"http:\/\/en.wikipedia.org\/wiki\/Achilles'_heel\" target=\"_blank\">achilles heel<\/a> for cloud security are user passwords.  Passwords can often be easily guessed or broken, allowing unauthorized access to cloud services.  Increasingly alternative, more secure methods than simple passwords are being adopted by vendors.<\/div>\n<div><\/div>\n<div><a title=\"Heather Adkins bio\" href=\"www.linkedin.com\/in\/argvee\" target=\"_blank\">Heather Adkins<\/a>, Google&#8217;s manager of information security, went so far as to say <a title=\"Quote that passwords are dead\" href=\"http:\/\/www.abajournal.com\/news\/article\/passwords_are_dead_says_google_security_expert\/\" target=\"_blank\">that <\/a>&#8220;passwords are dead.&#8221;<\/div>\n<div><\/div>\n<div>Cloud vendors are increasingly adopting a more robust kind of identification that requires a second level of validation besides just knowing the password.  The technology is called &#8216;two factor authentication&#8217;, or more generally, <a title=\"Multi-factor Authentication\" href=\"http:\/\/en.wikipedia.org\/wiki\/Multi-factor_authentication\" target=\"_blank\">&#8216;multi-factor authentication&#8217;<\/a>.<\/div>\n<div><\/div>\n<div>There are three categories of authentication elements:<\/div>\n<div>\n<ul>\n<li>Something you know &#8212; like a password, PIN, or recognition of an image<\/li>\n<li>Something you own &#8211; like an ATM card, smartphone, or security-specific dongle<\/li>\n<li>Something unique to you &#8212; like a biometric trait (fingerprint, retinal scan, etc)<\/li>\n<\/ul>\n<\/div>\n<p>Two-factor authentication is <a title=\"Google Docs two-factor authentication\" href=\"http:\/\/googleblog.blogspot.com\/2011\/02\/advanced-sign-in-security-for-your.html\" target=\"_blank\">available by services now like Google Docs<\/a>.  Administrators can optionally enable two-factor authentication for their users&#8217; accounts.  Once enabled, users first need to enter their password, but before gaining access to their account, they also need to enter a PIN number that is either sent to them via SMS or generated by an app for them on their mobile device.  <a title=\"GitHub two-factor authentication\" href=\"http:\/\/venturebeat.com\/2013\/09\/03\/github-two-factor\/\" target=\"_blank\">GitHub<\/a>, <a title=\"WordPress two factor authentication\" href=\"http:\/\/en.blog.wordpress.com\/2013\/04\/05\/two-step-authentication\/\" target=\"_blank\">WordPress<\/a>, and <a title=\"EverNote\" href=\"http:\/\/blog.evernote.com\/blog\/2013\/05\/30\/evernotes-three-new-security-features\/\" target=\"_blank\">EverNote <\/a>also use the Google Authenticator or similar method.  <a title=\"Twitter app on two-factor authentication\" href=\"http:\/\/www.wired.com\/threatlevel\/2013\/08\/twitter-new-two-facto\/\" target=\"_blank\">Twitter <\/a>has introduced a similar sort of two-factor authentication based on an app running on a mobile device.<\/p>\n<div><\/div>\n<div id=\"_mcePaste\"><\/div>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-multi-factor-authentication-replacing-standard-passwords%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Security is by far the number one concern that most businesses cite when considering a move of any of their data to the cloud. To counter these concerns, cloud vendors are doing all they can to improve security. For example,<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-multi-factor-authentication-replacing-standard-passwords\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-4213","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/4213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=4213"}],"version-history":[{"count":0,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/4213\/revisions"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=4213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=4213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=4213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}