In a recent research paper, Microsoft principal researcher Cormac Herley asserted that security measures that are being recommended are a waste of time. He argues that security protocols that attempt to protect an individual or organization from the consequences of a security breach often exact a much steeper price—in the form of user effort and [...]
Last December, someone hacked into the Web site RockYou.com, and exposed a list of usernames and passwords on the Web, in plain text. A month later, security analysis firm Imperva analyzed the most common passwords. The results are eye-opening and should serve as a reminder to you and your staff about the importance of creating [...]
Google, PayPal, Equifax, VeriSign, Verizon, CA, and Booz Allen Hamilton have formed a nonprofit company to oversee the development and exchange of online identity credentials on Web sites as a way to help with the user ID and password problems we all face.
The goal of the Open Identity Exchange (OIX) is to create a “trust [...]