The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Risk paralysis iBot IT Security RSS 0 05-23-2008 11:20 AM
Risk 1.0.9.6 (Default branch) iBot Software Releases - RSS News 0 04-20-2008 03:00 PM
Risk 1.0.9.5 (Default branch) iBot Software Releases - RSS News 0 03-06-2008 05:50 PM
Risk 1.0.9.4 (Default branch) iBot Software Releases - RSS News 0 02-11-2008 01:20 PM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 05-29-2008
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 22,137
Reducing Risk Versus Eliminating Risk

IT security professionals are sometimes so passionate about the technical details of a vulnerability that they accidentally lose sight of the benefits of the principles of risk management.
Sometimes the passion of discussing the details of a vulnerability overshadow the cost-benefits of risk reduction when passionate people strive for total risk elimination. For example, consider the example of using an SMS-based based implementation for two-factor authentication (2FA) with one-time password (OTP) combined with a transaction verification message (TVM). There are folks who rightfully argue that 2FA/OTP is vulnerable to a knowledgeable threat agent executing a man-in-the-middle (MITM) attack.
One of the more advanced banks I am familiar with uses SMS-based 2FA/OTP combined with SMS TVMs that detail the individual transactions. The mobile phone number cannot be changed on-line and requires a face-to-face meeting with proper identification, so arguments that an attacker simply logs in and changes the mobile number are without merit. There are folks who might argue that SMS-based 2FA is vulnerable to SIM cloning and mobile phone theft. Others passionately argue that a sophisticated MITM attack can compromise 2FA.
Regardless of the passion of the argument, SMS-based 2FA/OTP/TVM has cost effectively reduced risk for many organizations that depend upon on-line transactions in their business model. Is the risk totally eliminated? No! Given enough sophistication, or certain scenarios, most controls can be defeated. The point of this example is to illustrate the importance of cost-effective risk management and risk reduction principles versus focusing on vulnerabilities from a risk elimination perspective.
Is SMS-based 2FA/OTP/TVA a "perfect solution"?
Of course, the answer is "No."
However, properly implemented cost-effective controls, such as the example in this post, can and do cost-effectively reduce risk for many organizations. Therefore, I often advise IT security professionals nog to permit the passion for risk elimination to cloud the cost-benefits of solid risk management principles.


More...
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 05:58 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0