Why mobile two-factor authentication makes sense

Andy Kemshall · Network Security · 2011

Although technology never stops evolving, sometimes it takes its time. Often for good reasons: new operating systems need to be assessed for compatibility before being rolled out across an organisation, and numerous technologies have been vigorously touted as the Next Big Thing. Virtualisation has been held back by connectivity limitations. And the cloud has suffered from the same drawbacks – the omnipresent connectivity that was promised and has yet to materialise. Computer security must always tread the fine line between efficacy and usability, but regular two-factor authentication (2FA) using physical tokens crosses this line. Users need to remember their token, while technical services departments are charged with the job of maintaining and administering each token. This is the overwhelming reason why 2FA has failed to catch on. However, new ways of implementing 2FA have been developed – the most popular being passcode delivery directly to each user's own mobile phone via SMS. Although computer security measures need to constantly adapt to each new threat, Andy Kemshall of SecurEnvoy argues that tokenless 2FA represents a new way forward for organisations that are looking for the added layer of security offered by 2FA in 2011.

Read the paper · More papers on PaperTik