Skip to Content.
Sympa Menu

assurance - RE: [Assurance] silver and two-factor ...

Subject: Assurance

List archive

RE: [Assurance] silver and two-factor ...


Chronological Thread 
  • From: "Farmer, Jacob" <>
  • To: "" <>
  • Subject: RE: [Assurance] silver and two-factor ...
  • Date: Tue, 13 Mar 2012 18:56:22 +0000
  • Accept-language: en-US

IU is in the same spot, where two-factor is fundamentally easier than trying
to create that much additional rigor around username/passphrase
authentication.

There has also been some historical discomfort with doing Silver things using
just username and password. Some of the interest in choosing to use
two-factor are doing so because they believe the Silver standard isn't
rigorous enough.

Jacob

-----Original Message-----
From:


[mailto:]
On Behalf Of Christopher Bongaarts
Sent: Tuesday, March 13, 2012 2:43 PM
To:

Subject: Re: [Assurance] silver and two-factor ...

On 3/13/2012 1:18 PM, Dunker, Mary wrote:
> One of Virginia Tech's drivers for submitting 2-factor for Silver
> certification is that our hardware token-issuing process already
> includes rigorous face-to-face identity proofing and verification
> procedures. In contrast, our IDs and passwords are issued via
> self-service, with identity-proofing that would be more difficult to
> audit.

Our motivation, like VT, is that we have an existing two factor
implementation that could be leveraged without having to overhaul our current
password regime to meet Silver specs.

--
%% Christopher A. Bongaarts %%

%%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%



Archive powered by MHonArc 2.6.16.

Top of Page