Identity protection fit for the cloud

November 22, 2011 16:10
Both consumers and businesses are beginning to gravitate toward the convenience and efficiency of cloud computing for a wider range of services. However, users must be aware of the unique online security dangers common to the new platform and take appropriate action to protect their identities.

Both consumers and businesses are beginning to gravitate toward the convenience and efficiency of cloud computing for a wider range of services. However, users must be aware of the unique online security dangers common to the new platform and take appropriate action to protect their identities.

According to InformationWeek contributor and Intel architect Bruno Domingues, each new cloud service a user adopts will require a new set of log in credentials. For tech-savvy consumers, and many business professionals, this could mean having a dozen or more unique accounts to manage. Naturally, users may be tempted to memorize a handful of password combinations and rotate them around various sites.

"The consequence of this approach is obvious: If someone has stolen your information for one service, they will probably compromise your identity for several others," Domingues explained in his latest column.

To guard against this danger, experts recommend using a password organizer tool that automatically generates and manages credentials for each new account.

It is also worth mentioning the inherent vulnerabilities that arise from some methods of accessing cloud services. In many cases, businesses are leveraging the technology for greater employee flexibility and allowing their workers to access materials remotely, from a range of devices.

Once outside the company network, online security is often a bigger challenge. Whether they are accessing the internet through the router in their home office or via public Wi-Fi in an airport terminal, chances are the online environment does not have the robust defenses of a corporate network.

This makes stronger passwords all the more important.

"Instead of just having to contend with people inside the company trying to guess other people’s passwords, you now have all the hackers on the internet having a go," explained Cloud Tweaks contributor Richard Morrell. "They have tools that can try 100,000 password combinations in less than a minute and nothing better to do."

With sensitive business data at stake, IT professionals will have to intervene as they will ultimately be held accountable. While educating users on best practices is a worthwhile pursuit, merely relying on the best judgment of employees could be a decision they come to regret.

Instead, Morrell recommends more aggressive action. On top of the insurance provided by password manager software, administrators must go deeper to provide complex data encryption, threat protection for PC and mobile platforms and access governance tied to worker-specific job functions. 

Identity Security Solutions

March 08, 2012 A new study shows that internet users are becoming more cautious in their behaviors, especially when spending ...

March 02, 2012 For the 12th consecutive year, the No. 1 complaint sent to the Federal Trade Commission involved identity ...

February 24, 2012 Although people remain fearful of the impact identify theft, many are failing to take the appropriate steps ...

February 10, 2012 Companies with many employees may run into serious trouble if their staff members are using the same ...

February 07, 2012 A recent Reuters report indicated that VeriSign, which is responsible for ensuring people access more than ...

February 01, 2012 By declaring February 1 "Change Your Password Day," organizers hope to bring light-hearted attention to the ...

January 30, 2012 Passwords are a central component of online security frameworks, but for too many users they have become the ...