Security Basics mailing list archives
Re: How to authentificate an user via telephon?
From: "kawaii" <trunks () stackers org>
Date: Wed, 4 Dec 2002 12:00:03 -0500
From: "Robert Sieber" <rsieber () web de> Sent: Tuesday, December 03, 2002 13:50
Hello colleauges, imaging the following situation: User calls the helpdesk to reset/alter some kind of account-password (NT, RAS, PKI-PIN ...) and you has to determin wheter the user is the correct (owner of the account) user. What would you do to authentificate the users identity? What are good methodes to do this? It should be easy for the user but secure for the administration.
The ways that I've seen are: 1) Have an authenticated user email/call in for the person with the lost password/PIN/etc. 2) Have a secure question that is created by the user (ie: when the user registers for the account, he also submits three personal questions for auth.) 3) Have a PIN/password be used for authentication, with which they can then change/review their other accts/passwords.
Robert
Ever lovable and always scrappy, kawaii "Cunnilingus and psychiatry brought us to this." - Tony Soprano
Current thread:
- How to authentificate an user via telephon? Robert Sieber (Dec 04)
- Re: How to authentificate an user via telephon? Matthew McCleary (Dec 04)
- Re: How to authentificate an user via telephon? kawaii (Dec 04)
- RE: How to authentificate an user via telephon? securityfocus (Dec 04)
- Re: How to authentificate an user via telephon? Brad Arlt (Dec 04)
- Re: How to authentificate an user via telephon? Muhammad Naseer Bhatti (Dec 05)
- Re: How to authentificate an user via telephon? Brad Arlt (Dec 05)
- Re: How to authentificate an user via telephon? Muhammad Naseer Bhatti (Dec 05)
- Re: How to authentificate an user via telephon? Gene Barlow (Dec 05)
- Re: How to authentificate an user via telephon? Valter Santos (Dec 05)
- Re: How to authentificate an user via telephon? Gene (Dec 06)
- Re: How to authentificate an user via telephon? Valter Santos (Dec 05)
- RE: How to authentificate an user via telephon? Burton M. Strauss III (Dec 05)
- Re: How to authentificate an user via telephon? James W. Meritt (Dec 05)
- Re: How to authentificate an user via telephon? Marc Cuypers (Dec 05)
(Thread continues...)