SlideShare une entreprise Scribd logo
1  sur  15
Télécharger pour lire hors ligne
PayPal
TM
Michael Barrett, CISM, CISSP
Chief Information Security Officer
Voice	
  Biometrics	
  Conference	
  
May	
  8,	
  2013	
  
Opportunity for Better Authentication is Upon Us
Passwords Just Do Not Work…
For Users For Organizations
Painful to Use
	
  
•  25	
  Accounts	
  
•  8	
  Logins	
  /	
  Day	
  
•  6.5	
  Passwords	
  
Difficult to Secure
•  $5.5M / Data Breach
•  $15M / PWD Reset
•  $60+ / Token
For the Ecosystem
Impossible to Scale
•  Fragmented
•  Inflexible
•  Slow to Adopt
Common experiences related to authentication
failure (respondents who say it happened to them
one or more times over the past 2 years)
Users are frustrated -
password complexity
requirements working
against them instead
of supporting them
Experiences with Identity and Authentication
JUST EASY
SECURE & EASY
JUST BAD
HighSecurityLow
UNPLEASANT
Low HighUsability
Security is not a Continuum…
DO YOU REALLY WANT YOUR
REFRIGERATOR TO KNOW YOUR PAYPAL
PASSWORD?
Do You Really Want Your Refrigerator to Know Your
PayPal Password?
Newer Technologies Exist
0
20
40
60
80
100
120
2006 2007 2008 2009 2010 2011 2012
Authentication Vendors
Increasing Options
Authentication Standards Combined with Advances
in Biometrics Provide a New Path Forward
How FIDO Works
FIDO Authenticators
Website
Browser
FIDO Plugin
Device Specific
Module
6
4
1
2
3 5
Validation
Cache
secret secrets
refresh
Vendor Tokens
FIDO
Repository
•  User picks their own token type
•  User decides when/if to bind their
token to their account
•  Existing tokens (like finger) can be
used by downloading the FIDO
plugin
•  User can download the plugin from
various sites
•  User could have a PIN-protected
USB drive to use while travelling
The FIDO “User” Experience
Please say your passphrase to log into your
account
Speak
Voice Experience
Finger Experience
USB Experience
Ø The Internet needs better authentication, now
Ø Stronger authentication is not “better
authentication”
Ø An industry standards based approach is the
only viable way forward
Ø “Whether you believe you can do a thing, or
not, you are right” (Henry Ford)
Michael Barrett, CISM, CISSP
Chief Information Security Officer
mbarrett@paypal.com
PayPal
TM
Thank You for Your Time!

Contenu connexe

Plus de derektop

Plus de derektop (13)

Operationalizing Voice Biometrics
Operationalizing Voice BiometricsOperationalizing Voice Biometrics
Operationalizing Voice Biometrics
 
Introduction to Truly Handsfree 3.0
Introduction to Truly Handsfree 3.0Introduction to Truly Handsfree 3.0
Introduction to Truly Handsfree 3.0
 
e-Government Applications for Voice Authentication
e-Government Applications for Voice Authenticatione-Government Applications for Voice Authentication
e-Government Applications for Voice Authentication
 
Mobile Voice Authentication
Mobile Voice AuthenticationMobile Voice Authentication
Mobile Voice Authentication
 
Future of Mobile Authentication
Future of Mobile AuthenticationFuture of Mobile Authentication
Future of Mobile Authentication
 
The Future of Secure, Mobile Authentication
The Future of Secure, Mobile AuthenticationThe Future of Secure, Mobile Authentication
The Future of Secure, Mobile Authentication
 
The Case for Voice + Face Recognition
The Case for Voice + Face RecognitionThe Case for Voice + Face Recognition
The Case for Voice + Face Recognition
 
The Power of a Black List, the Promise of a White List
The Power of a Black List, the Promise of a White ListThe Power of a Black List, the Promise of a White List
The Power of a Black List, the Promise of a White List
 
Case Study: Passive Authentication at Barclays
Case Study: Passive Authentication at BarclaysCase Study: Passive Authentication at Barclays
Case Study: Passive Authentication at Barclays
 
Powering Security and Easy Authentication in a Multi-Channel World
Powering Security and Easy Authentication in a Multi-Channel WorldPowering Security and Easy Authentication in a Multi-Channel World
Powering Security and Easy Authentication in a Multi-Channel World
 
Natural Interaction in the Connected Home
Natural Interaction in the Connected HomeNatural Interaction in the Connected Home
Natural Interaction in the Connected Home
 
Case Study: Voice Verification by Mobile Operator Avea
Case Study: Voice Verification by Mobile Operator AveaCase Study: Voice Verification by Mobile Operator Avea
Case Study: Voice Verification by Mobile Operator Avea
 
Voice Biometrics: The Big Picture Gets Bigger
Voice Biometrics: The Big Picture Gets BiggerVoice Biometrics: The Big Picture Gets Bigger
Voice Biometrics: The Big Picture Gets Bigger
 

Dernier

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Dernier (20)

Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 

Beyond Passwords: FIDO (Fast IDentity Online) and the Larger Market for Strong Authentication

  • 1. PayPal TM Michael Barrett, CISM, CISSP Chief Information Security Officer Voice  Biometrics  Conference   May  8,  2013  
  • 2. Opportunity for Better Authentication is Upon Us Passwords Just Do Not Work… For Users For Organizations Painful to Use   •  25  Accounts   •  8  Logins  /  Day   •  6.5  Passwords   Difficult to Secure •  $5.5M / Data Breach •  $15M / PWD Reset •  $60+ / Token For the Ecosystem Impossible to Scale •  Fragmented •  Inflexible •  Slow to Adopt
  • 3. Common experiences related to authentication failure (respondents who say it happened to them one or more times over the past 2 years) Users are frustrated - password complexity requirements working against them instead of supporting them Experiences with Identity and Authentication
  • 4. JUST EASY SECURE & EASY JUST BAD HighSecurityLow UNPLEASANT Low HighUsability Security is not a Continuum…
  • 5. DO YOU REALLY WANT YOUR REFRIGERATOR TO KNOW YOUR PAYPAL PASSWORD? Do You Really Want Your Refrigerator to Know Your PayPal Password?
  • 7. 0 20 40 60 80 100 120 2006 2007 2008 2009 2010 2011 2012 Authentication Vendors Increasing Options
  • 8. Authentication Standards Combined with Advances in Biometrics Provide a New Path Forward
  • 9. How FIDO Works FIDO Authenticators Website Browser FIDO Plugin Device Specific Module 6 4 1 2 3 5 Validation Cache secret secrets refresh Vendor Tokens FIDO Repository
  • 10. •  User picks their own token type •  User decides when/if to bind their token to their account •  Existing tokens (like finger) can be used by downloading the FIDO plugin •  User can download the plugin from various sites •  User could have a PIN-protected USB drive to use while travelling The FIDO “User” Experience
  • 11. Please say your passphrase to log into your account Speak Voice Experience
  • 14. Ø The Internet needs better authentication, now Ø Stronger authentication is not “better authentication” Ø An industry standards based approach is the only viable way forward Ø “Whether you believe you can do a thing, or not, you are right” (Henry Ford)
  • 15. Michael Barrett, CISM, CISSP Chief Information Security Officer mbarrett@paypal.com PayPal TM Thank You for Your Time!