Security Basics mailing list archives

Re: How to authentificate an user via telephon?


From: Gene Barlow <btraquer () att net>
Date: Wed, 04 Dec 2002 10:27:16 -0700

Robert,

Currently, I'm in the process of getting approval on a new procedure for doing just that. If approved, we'll write a script that will query the last 4 digits of the users ssn & birthdate against our ERP software. So, for instance, if John Doe calls and requests a password change, we'll ask for the last 4 digits of the ssn and their birthdate, type it in the script, and see if that user's name is returned in the response. If so, we know (hopefully) that the user is who he says he is...

Hope this helps...
Gene...

Robert Sieber wrote:

Hello colleauges,

imaging the following situation:

User calls the helpdesk to reset/alter some kind
of account-password (NT, RAS, PKI-PIN ...) and you has to determin wheter the user is the correct (owner of the account) user. What would you do
to authentificate the users identity?

What are good methodes to do this? It should be
easy for the user but secure for the administration.


Robert




Current thread: