* The announcement brings the concept of two-factor authentication to the masses
Google just did us all a big favor. The company has introduced two-factor authentication for Google apps. So how does this help us? And, by “us,” I mean those of you and me who make our living through various aspects of identity management.
Google just did us all a big favor. The company has introduced two-factor authentication for Google Apps. So how does this help us? And, by “us,” I mean those of you and me who make our living through various aspects of identity management.
We’ve talked about multi-factor authentication for almost 20 years. But when Google announces multi-factor authentication, it’s big news and makes it into the business section of the newspapers that our business managers read. For example:
* “How your mobile device will make Google apps more secure” (The Independent)
* “Google adds extra security step to e-mail, apps” (Associated Press)
* “Google doubles security for Apps” (Forbes)
* “Google announces Apps security changes” (The Inquirer)
* “Google adds authentication option to Google Apps” (International Business Times)
What that means is that we can now more easily discuss multi-factor authentication in business meetings with an example (“it’s like Google did with Gmail”) that most people in the room will understand.
Even the method Google’s chosen works to our advantage — a one-time password token delivered to a cell phone either by an SMS text message or a call to the phone. And as the SMS service will be free (and available in 19 countries including Australia, Denmark, France, Germany, the Netherlands, Sweden, the U.K. and the U.S.) it should be widely implemented by users.
But all that is really icing on the cake. The real news here is that corporate use of Google Apps just got more secure. At least it did for those organizations who issue their own cell phones to employees (and get them back during the de-provisioning process, a topic for another issue). Retrieve the phone (and the phone number — make sure it’s in the company’s name) and the newly departed employee can no longer retrieve the company’s trade secrets, customer lists or privileged data.
Organizations that have been reluctant to even experiment with Google Apps in the past now have an incentive to try them out. And enterprises whom you couldn’t interest in two-factor authentication in the past (“it’s all geek to me!”) might now be willing to listen.
Sure sounds like a win-win. Thank you, Google!




