Skip Links

Network World

  • Social Web 
  • Email 
  • Close

A network question

By Dave Kearns , Network World , 07/25/2005
Kearns

When it comes to access, authentication and logon - are you still using simple passwords? You know, minimum six characters (or even four), case insensitive, no requirement for mixed alphanumerics or special characters.

As security expert Bruce Schneier said in this magazinein the spring: "Passwords just don't work anymore. As computers have gotten faster, password guessing has gotten easier. Ever-more-complicated passwords are required to evade password-guessing software. At the same time, there's an upper limit to how complex a password users can be expected to remember."

I'm bringing this up because Sun recently announced it would be donating its enterprise single sign-on (ESSO) technology to the open source movement.

The OpenSSO project, if it follows the trend of other major open source projects, should lead to very workable, easily implemented and very inexpensive ESSO. That means if you don't already have an ESSO project implemented or in planning, you'll soon be facing enormous pressure to do so.

ESSO is a tempting technology. We want to make passwords stronger by requiring longer strings of mixed-case letters and numerics with a special character or two thrown in.

But users who can't remember multiple simple passwords have no hope of remembering multiple complex passwords. Either they'll write them on notes that they tape to their monitor - or, here's a sneaky trick: on the underside of the desk blotter. (I wonder where their spare front door key is!)

A good ESSO package allows you to have a single password in order to access the resources and services on a network. Of course, if there's only one password needed to access all of a user's privileges, then it should be particularly strong. But strings such as Asdf2%Wssd43!!AZgf will not be remembered by users. So it's time to think about strong authentication based on one-time passwords, smart cards/proximity cards or even biometrics.

There have been major advances in these areas over the past few years, so recheck if you dismissed them as either too pricey or unworkable some time ago.

If you're into open source, then check first with the Initiative for Open Authentication (OATH). There is lots of information, pointers, protocols and specifications to get you started on the road to the strong authentication that will be necessary for your ESSO environment.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.