- Bank Web sites full of security holes
- SCO Group: Its future is all used up
- Maligned feature being added to IPv6
- I returned my iPhone 3G after six days!
- VPNs: Six burning questions
News | Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
Identity theft is fast becoming the new bête noire of the cyberworld, crowding out spyware, spam and viruses for that dubious honor. During the past several months, the media have splashed increasingly frightening cover stories, consumer alerts and other breaking news about people who've had their identities spoofed, credit cards hijacked and assets looted by unseen strangers lurking on the Internet.
Amid the growing hysteria, the identity-management industry sees a big black eye in the making, and it's beginning to formulate strategies for identity theft prevention, detection and remediation. For example, in June the Liberty Alliance formed a group to develop best practices to help businesses and consumers prevent online identity fraud. In a similar vein, Microsoft recently announced a retooled identity-management federation strategy - the Identity Metasystem - that underscores the need for identity-theft and privacy protection.
The unspoken subtext behind these initiatives is that trust - the foundation of identity-management federation-is in jeopardy if the industry doesn't proactively address identity theft on many levels. The stakes couldn't be higher. What's most worrisome is the growing prevalence of phishing, pharming and other social-engineering ploys to steal user information. These frauds strike at the very heart of the federation: users' trust in the authenticity of identity providers. If you can't trust that the party to whom you're presenting credentials is in fact what it claims to be, then nothing's truly secure.
Likewise, well-publicized break-ins to corporate databases have further shaken people's trust in the safeguarding of critical personal identity data. And massive theft of personal data creates another trust loss: Identity providers who've been victimized can no longer trust that the individual presenting credentials is who he or she claims to be.
In the face of never-ending identity thefts, the only way out of this downward spiral is to continue reissuing new credentials to affected users, but only after reputable agents have proofed those users to strong assurance, and only if the new credentials rely on biometrics for strong authentication. Clearly, this theft-unfriendly identity-management environment is a long way from being implemented in the real world and would be quite expensive, complex and cumbersome to universally deploy.
If the IT manager is knowledgeable regarding Cisco technology, he would have 2 options. Option 1 - Consult...- Anonymous
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.
Download the white paper.
Unauthorized applications: Taking back control
Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?
Download the white paper.
Comment