IDPros / bok

This is a public comment environment for the IDPro body of knowledge.
65 stars 26 forks source link

Best Practice - Call Center Authentication #44

Open lancepeterman opened 3 years ago

lancepeterman commented 3 years ago

This needs to be incorporated into the BoK, probably in one of the Intro to Identity articles:

Would be good to include a passage on why using a shared secret, usually established by the customer, is a risky method for authenticating customers in that setting. These are risky for a number of reasons, not the least of which is that the secret is known by the customer (if they can remember it), the authentication system, and then the operator once they key in the secret.

cronical commented 3 years ago

I think this is referring to private questions and answers often for the purpose of resetting passwords. This is opposed to a shared secret which is the password or PIN. Is that right Lance?