Educause Security Discussion mailing list archives
Re: Authentication of remote users
From: "Hunt,Keith A" <keith () UAKRON EDU>
Date: Thu, 3 Jan 2008 13:57:45 -0500
-----Original Message----- From: Cal Frye [mailto:cjf () CALFRYE COM] Sent: Thursday, January 03, 2008 12:46 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] Authentication of remote users Gary Flynn wrote:
Lets say you have a user that: 1) forgot their password 2) forgot their answers to their secret question(s) 3) is traveling making visiting the helpdesk impossible Lets also say asking for last four digits of SSN is not allowed. How do you authenticate the identity of the user and allow them to change their password?
Here we require they fax (or sometimes an email will do) a photocopy of their ID card, which does not itself contain SSN data, but our internal ID number instead. -- Regards, -- Cal Frye, Network Administrator, Oberlin College I have never quite understood the thinking behind this approach, though I have seen a number of folks propose it. What if someone steals my ID card, or I lose it and someone else finds it? How does the possession of such a credential prove anything about the identity of the person who holds it? Keith Hunt 330.972.7968 keith () uakron edu Internet & Server Systems The University of Akron
Current thread:
- Authentication of remote users Gary Flynn (Jan 03)
- <Possible follow-ups>
- Re: Authentication of remote users Robert Paterson (Jan 03)
- Re: Authentication of remote users Cal Frye (Jan 03)
- Re: Authentication of remote users Bob Bayn (Jan 03)
- Re: Authentication of remote users Scott Fendley (Jan 03)
- Re: Authentication of remote users Kees Leune (Jan 03)
- Re: Authentication of remote users Christopher Webber (Jan 03)
- Re: Authentication of remote users Dave Mueller (Jan 03)
- Re: Authentication of remote users Hunt,Keith A (Jan 03)
- Re: Authentication of remote users Andrea Beesing (Jan 03)
- Re: Authentication of remote users Robert Paterson (Jan 03)
- Re: Authentication of remote users Scott Koger (Jan 03)
- Re: Authentication of remote users Tom Peterson (Jan 03)
- Re: Authentication of remote users Chris Vakhordjian (Jan 03)
- Re: Authentication of remote users Joel Rosenblatt (Jan 03)
- Re: Authentication of remote users Roger Safian (Jan 03)
- Re: Authentication of remote users charlie derr (Jan 03)
- Re: Authentication of remote users Roger Safian (Jan 03)
- Re: Authentication of remote users Cal Frye (Jan 03)
(Thread continues...)