Home > Enterprise Desktop News > Managing single sign-on security burdens in Windows
Enterprise Desktop News:
EMAIL THIS
COLUMN

Managing single sign-on security burdens in Windows

By Kevin Beaver
10 Nov 2008 | SearchEnterpriseDesktop.com


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Remember the promises of single sign-on (SSO)? "One user account and one password are all you need," the vendors proclaimed. Even before Active Directory became mainstream, many vendors were touting SSO solutions. But that was in the mid-1990s.

Fast forward to today. We've got Active Directory, eDirectory, Federated Identity solutions and so on. But we're still having to manage multiple user accounts and passwords in many areas of what we do with computer systems, including:

  • Hard drive encryption
  • Windows operating systems
  • Web/POP3/SMTP email
  • Internal websites
  • External websites
  • Database systems
  • Word, Excel and PDF documents
  • VPN connections
  • Remote desktop connections
  • Mainframe systems
  • Smartphones

Ask any given user -- even Windows admins -- and you'll hear that true
Desktop management tips from SearchEnterpriseDesktop.com
Sign up for our additional editions of SearchEnterpriseDesktop.com's Desktop Management Adviser to learn more about desktop management, security and virtualization.
SSO is needed but has yet to materialize. It's a problem that gets in the way of doing business and a problem that's creating security risks beyond belief.

So what happened to the promises of one user ID and one password? We could chalk up these broken promises to growing information system complexities. We could credit the Internet and rich applications for pushing the need for authentication out past the OS layer. In the end, it doesn't matter why we have to remember dozens of sets of login credentials. The fact is, it's a problem and we need a solution.

Are tools the answer to SSO problems?

Although SSO and Federated Identities as we know them are arguably still in their infancy, there are some solutions on the market today that can help ease the pain of logon credential management. CA, IBM and RSA, for example, have enterprise solutions.

Based on what I've seen in my work, however, all but the largest enterprises can justify going this route. If your network falls into the less-than-gargantuan-sized category, there are also some smaller vendors that offer their own unique approaches to the SSO issue. Products such as Quest Software Inc.'s One Identity Solution and nFront Security Inc.'s Passfilt Pro help integrate multiple passwords and enforce policies across systems in their own unique ways.

Going beyond OS-level authentication, a Web form filler application such as Siber Systems Inc.'s RoboForm may be all you need. Hewlett-Packard Co. even has its own OS and application-level authentication solution built into its business-class mobile systems called ProtectTools Credential Manager. I have it on my system and I can see how it would be a great way to manage login credentials across the board for mobile users.

Will there ever be an end-to-end solution to our SSO dilemma? Yeah, maybe once we all have RFID chips implanted somewhere in our bodies. We'll simply walk up to the computer and login to everything at once. We go away, we get logged out. As scary as that is to me, I do envision something along those lines being a reality one day.

I'm still optimistic about today's current offerings. If you do go down the SSO road, just make sure you're doing it for all the right reasons: security, convenience, productivity and reducing business risks. Otherwise, your SSO solution could end up getting in the way of things and lead to people and processes increasing security risks (i.e. unauthorized access and breaches) rather than minimizing them.

Check out the existing solutions offered by third-party vendors as well as your current configurations. As with HP's ProtectTools you may already have the solution you need, at least for a subset of your users. Don't wait for Microsoft to solve this problem because it's not really Microsoft's to fix. Just know that until every OS speaks the same language as every application across the board, this is a network management, user education and security issue we're going to have to balance on our own terms.

About the author: Kevin Beaver is an information security consultant, keynote speaker, and expert witness with Atlanta-based Principle Logic, LLC where he specializes in performing independent security assessments. Kevin has authored/co-authored seven books on information security including Hacking For Dummies and Hacking Wireless Networks For Dummies (Wiley). He's also the creator of the Security On Wheels information security audio books and blog providing security learning for IT professionals on the go. Kevin can be reached at kbeaver /at/ principlelogic.com.



Tags: User passwords and network permissionsMicrosoft Windows Vista operating systemMicrosoft Windows XP ProPatches, alerts and critical updatesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
User passwords and network permissions
Eight is too many characters for strong passwords
Nine common password oversights to avoid
Secure your Windows systems with proper password practices
Managing multiple passwords in Windows
Windows desktop endpoint security challenges podcast series
How to strike a balance between Windows security and business needs
Build secure computer password policies
Remote user security checklist
Reduce resistance to creating strong computer passwords
Unauthenticated vs. authenticated security testing

Microsoft Windows Vista operating system
Windows 7 launches, offers salvation from Vista
An intro to Windows 7's Deployment Image Servicing and Management tool
Guide to converting from Windows XP to Windows 7
Choosing the best way to install images
Has Microsoft corrected Vista annoyances in Windows 7?
Microsoft's August patches run the gamut
Your questions answered: The Windows 7 upgrade quandary
Windows Vista users get little pricing relief on Windows 7
Combining folder redirection with roaming profiles
IPv6 protocol, Windows Vista features simplify peer ad-hoc networking

Microsoft Windows XP Pro
Guide to converting from Windows XP to Windows 7
Top 5 registry keys for Windows XP
Manage the desktop image lifecycle to limit work, ensure security
Secure Windows XP before a Windows 7 upgrade
Microsoft's August patches run the gamut
Hold on to Windows XP at your peril
XP stragglers blame hardware costs, new features
Your questions answered: The Windows 7 upgrade quandary
Windows Vista users get little pricing relief on Windows 7
Vista shops eye quick path to Windows 7, XP shops likely to resist

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
key-value pair  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Windows Desktop Technology - Virtualization, Virtual Infrastructure, Virtual Desktop
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts