Chapter 92. Risk, 2FA, MFA, It’s All Just Authentication! Isn’t It?
Unique Glover
I’m sure you’ve heard the old adage, “There’s nothing new under the sun.”
Technology is full of buzzwords, let’s face it: “cloud,” “IoT”, “Agile,” “holistically,” “AI”—sometimes I think technology is 90% marketing and 10% practice. And, it’s easy for decision makers to fall into the allure and excitement the next “it” wave promises to solve, especially when the career lifespan of CISOs average two years—that “it” starts to look very attractive to the eye.
That’s when you as a practitioner earn your money. As you grow in your career and climb up that proverbial ladder, you’ll invariably encounter situations where while working with decision makers, you’ll be placed in a position where you’ll have to discern fact from myth, and those conversations may be uncomfortable but necessary.
“Our MFA will have five pillars, we’ll label it the NextGen MFA. Our MFA will go beyond the typical three pillars—who you are, what you have, and what you know...we’ll use location and keyboard typing patterns as an authentication factor! Making it less painful for our users to access our systems” my VP spoke in a room full of his subordinates as everyone nodded their head in agreement. “Huh?” was my response. See, I knew what was being asked—achieving a security utopia of balancing sensible security with a seamless user ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access