Thursday, January 31, 2008

My first haiku

My first haiku...

Kerberos is hound
Active Directory makes
Logon gets better


Yah, sorry, kind of lame but it conforms (3 lines, 1st and 3rd lines have 5 syllables, second line has 7) and it is all about conforming to the standard...

Wednesday, January 30, 2008

Federation - it's not getting better

I like this post...
Federation is about trust

A conversation today set me thinking (yet again) about why things are not getting better. Once again, I must ask why is it that the identity management situation does not seem to be improving much? In particular, surprisingly little seems to be happening in federated identity. Not because the standards needed to do it don't exist, or exist but don't work, but because they don't overcome the trust barrier. Why should a company trust another company's credentials? Or, at least, why should a company trust another company's credentials unless the both belong to a "gang"?

Don't get me wrong, I do want federation to be super, wildly successful but in the software business what's worse than taking a dependency on someone else's product? Trusting them to deliver on time.

Federation is very similar but as David Birch intimates, the trust just ain't there.

p.s. If I read a single "2008 is the year of federation" prediction I'll be happy to act as that person's kaishakunin on New Year's Day 2009.

Technorati Tags:
,

Tuesday, January 29, 2008

The SUN does not shine as bright as it use to!

Check this out - freakin' hilarious! From the PingID blog:

On January 24th, Sun threw down the gauntlet by releasing this video. I guess our new Auto-Connect™ feature got their attention. Yea, Auto-Connect IS good marketing, but it's also real, you can download it and see for yourself.

Now, to be honest, we didn't really know we were in an epic battle with Sun (we need to see them in competitive deals for this to be true), but we can't very well be the leader without a challenger, and we won't be challenged without a response.

So, in the spirit of having a bit of fun with Sun and ourselves, we prepared our response.


http://blog.pingidentity.com/resources/default/media/ping-300.html


Technorati Tags:
, , ,


Monday, January 28, 2008

A $7.2B password mistake?

In case you haven’t heard, Société Générale was the target of a fraud perpetrated by an employee. That fraud, so far, has amounted to $7.2B – yes, that’s a “b” for billion. You can read up about it here, here, and the European Central Bank’s call for additional controls here.

The news broke on Thursday afternoon. So what does this $7.2B fraud have to do with passwords? Well, it appears, a lot. Here’s what was reported in the Wall Street Journal:


“…Mr. Kerviel (the fraudster) used the computer log-in and passwords of colleagues both in the trading unit and the technology section” to help cover his tracks.

I translate this to mean the following:

  • SocGen did not have a password or security policies that enforced frequent changes or other related safeguards (password length, reuse, etc.)

  • SocGen did not use two-factor authentication otherwise Kerviel would not have been able to use a colleagues log-in and password

  • SocGen did not audit their logons effectively

  • SocGen did not audit logons against building access (i.e., logged on inside the building but already keyed out of the building)

The next time you talk about ROI to a potential customer also ask them about the cost of doing nothing. Might they be the next Société Générale?




Technorati Tags:
,