3 ms·
While he presents a great overview of all the problems with static knowledge based authentication, I get the feeling that the very fact that this hearing was ca
by glitcher 9y ago
While he presents a great overview of all the problems with static knowledge based authentication, I get the feeling that the very fact that this hearing was called for implies there is already a strong consensus that the current status quo is a big problem. To me it falls a bit short because he primarily elaborates on the details of the problem without offering any suggestions on how to move forward towards a solution. I mean, the details may help understanding which could inform improved policy, but these politicians also need guidance on what actions to consider.
- mtgx 9y agoIndeed, and if impartial security experts won't offer them, the politicians will have to rely on corporate lobbyists to write their own rules and penalties affecting those companies.
- kbenson 9y agoI believe the scope of what he was asked to address might not have included suggested solutions, beyond the obvious "don't suggest all the stuff I'm saying is causing a problem." He does specifically go out of his way to say, in bold and isolated text, Do keep in mind that the context here is the impact on identity verification in "a post-breach world".
- bklaasen 9y agoFrom the article: "I've had some great suggestions around tackling the root cause of data breaches and I'd love to have another opportunity in the future to talk about that, but it goes beyond the specific focus of this hearing. That said, who knows what I'll be asked by congressmen and congresswomen on the day and they may well question what can be done to combat the alarming rise in these incidents. I've now got a lot of great references on hand to go to should that happen so once again, thank you!"
- WhoBeI 9y agoNo, they need facts, the willingness to learn and the courage to think for themselves. "Guidance" is just another way of saying "my way".
- glitcher 9y agoMany politicians still believe that secret backdoors are the silver bullet to the encryption "problem", after how many experts keep saying security and backdoors are incompatible? I don't believe it's nearly as black-and-white as you would make it out to be. There is a middle ground where our industry has a responsibility to not only "give the facts", but also provide guidance, especially when explicitly asked for.