Hitoshi Kokumai

5年前 · 2 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
Blockchain solutions offered without a reliable user authentication don’t make much sense, do they?

Blockchain solutions offered without a reliable user authentication don’t make much sense, do they?


When we say ‘This door is weak’, it could mean ‘The door panel is weak’ and ‘The lock/key system is weak’.  The blockchain technology could indeed help make a strong door panel, but it alone could never make a substitute to a reliable lock/key system.


d40409d0.png

Well, for the most reliable lock/key system for cyberspace, i.e., digital identity authentication, there must be three prerequisite

First of all, identity assurance with NO confirmation of the users volition would lead to a world where criminals and tyrants dominate citizens. Democracy would be dead where our volition was not involved in our identity assurance. We must be against any attempts to do without what we remember, recognize and feed to login volitionally.

Secondly, mathematical strength of a security makes sense so long as the means is practicable for us Homo sapiens. A big cake could be appreciated only if it’s edible.

Thirdly, being ‘unique’ is different from being ‘secret’. ‘Passwords’ must not be displaced by the likes of ‘User ID’. I mean, we should be very careful when using biometrics for the purpose of identity authentication, although we don’t see so big a problem when using biometrics for the purpose of personal identification.

Identification is to give an answer to the question of “Who are they?”, whereas authentication is to give the answer to the question of “Are they the persons who claim to be?” Authentication and identification belong to totally different domains.

We know that the password is an indispensable factor for multi-factor schemes and that the security of password managers and single-sign-on schemes needs to hinge on the reliability of the master-password. Biometrics, which relies on a backup password, can by no means be an alternative to the password,

The password as memorized secret is absolutely necessary. We must not accept any form of password-less login.

We might also need to look at the situation where we cannot rely on anything but the memorized secrets; emergencies.

What is practicable in a calm indoor environment is not necessarily practicable in the turbulent outdoor environment, although the reverse can be said. The difference would be most striking in the cases of battlefield and disaster recovery.

Can we take it for granted that the people in such panicky situations are holding the cards and tokens for their identity authentication?  

Can we be certain that the biometrics measures, whether static or behavioral, are practicable for the people who are injured or caught in panic?

It is the obligation of the democratic societies to provide the citizens with identity authentication measures that are practicable in emergencies.

Slide “Identity Assurance in Emergencies”.

Blockchain solutions for valuable information assets must come with the most reliable means of identity assurance.


"
コメント

Hitoshi Kokumai

4年前 #2

#1
Your heartening comment is very much appreciated.

Debesh Choudhury

4年前 #1

I agree - "We must not accept any form of password-less login" which is vulnerable and against our volition. The identity authentication system should also be practicable in case of emergencies .. Hitoshi Kokumai you raised important points.

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

We’ve come up with a slide presentation for “Bring a healthy second life to your legacy password sys ...

2年前 · 2 分の読書時間

Taken up today is this TechRepublic report on voice print as a new password - https://www.techrepubl ...

2年前 · 2 分の読書時間

I would like to take up this somewhat puzzling report - “Google advises passwords are good, spear ph ...

関連プロフェッショナル

この職種に興味がある方はこちら

  • Aeon Retail

    食品レジスタッフ【アルバイト・パート】

    次の場所にあります: Talent JP C2 - 22時間前


    Aeon Retail Joetsu, 日本

    待遇 · ▽パート · 交通費規定内支給 / 買物割引制度 / 売場により制服貸与 / · 昇給/賞与制度※年2回 / 有給休暇(6カ月以上勤務から) / 社員登用制度 / 社会保険完備(勤務条件による)/ 社内共済会(勤務条件による)/ その他福利厚生 · ▽アルバイト · 交通費規定内支給 / 売場により制服貸与 / 有給休暇(6カ月以上勤務から) · ※店舗及び雇用形態により内容が異なります。詳しくは面接時にお問い合わせ下さい。 · ★店舗事業所敷地内禁煙・就業時間内禁煙応 ...


  • ゴーウェル株式会社 福島県いわき市, 日本 正社員

    【タガログ語・英語/正社員】技能実習生の管理・。【具体的な仕事内容】・フィリピン人技能実習生の生活指導、サポート、ケア・実習生と日本人スタッフ間の通訳業務、各種書類の翻訳業務・総務業務全般フィリピンと日本の橋渡しとなって頂ける方を募集します。 ...

  • ソフトバンク株式会社

    クラウドサービス開発エンジニア(SaaS領域) 【法人事業】

    次の場所にあります: Talent JP C2 - 22時間前


    ソフトバンク株式会社 Kanto Region, 日本

    採用部門 概要 · クラウド企業から仕入れてプロダクト開発を行うのではなく、ソフトバンク内の社内ベンチャーのようにサービスの構想から要件定義、設計、サーバー展開、運用業務までをワンストップで対応し、サービスを作っています。 · 主要顧客はソフトバンクと取引のあるエンタープライズ企業が中心でゼロトラストセキュリティの軸となっていくデバイスセキュリティサービスを提供しています。 · 最新のサービスを積極的に取り込むとともにオンプレ、クラウドの両方のテクノロジーを駆使し、ビジネスコンシェルデバイスマネジメントのサービスを支えています。 · さらにビジネスコン ...