Investors Hangout Stock Message Boards Logo
  • Mailbox
  • Favorites
  • Boards
    • The Hangout
    • NASDAQ
    • NYSE
    • OTC Markets
    • All Boards
  • Whats Hot!
    • Recent Activity
    • Most Viewed Boards
    • Most Viewed Posts
    • Most Posted
    • Most Followed
    • Top Boards
    • Newest Boards
    • Newest Members
  • Blog
    • Recent Blog Posts
    • Recently Updated
    • News
    • Stocks
    • Crypto
    • Investing
    • Business
    • Markets
    • Economy
    • Real Estate
    • Personal Finance
  • Market Movers
  • Interactive Charts
  • Login - Join Now FREE!
  1. Home ›
  2. Stock Message Boards ›
  3. Stock Boards ›
  4. Zerify Inc (ZRFY) Message Board

NIST says push authentication over OOB is in, out-

Message Board Public Reply | Private Reply | Keep | Replies (2)                   Post New Msg
Edit Msg () | Previous | Next


Post# of 82686
(Total Views: 310)
Posted On: 11/29/2017 8:54:19 AM
Posted By: zpaul
Re: CyberJ #9651
NIST says push authentication over OOB is in , out-of-band SMS is out
((((((((INDUSTRY STANDARD))))))))))

https://pages.nist.gov/800-63-3/ & https://pages.nist.gov/800-63-3/sp800-63-3.html
Quote:
Enter OOB push authentication using push notifications, which is getting a thumbs up from NIST. To quote, “If out of band verification is to be made using a secure application (e.g., on a smart phone), the verifier MAY send a push notification to that device.” Since this method involves an app that is installed on a user’s device, the above fraud scenario wouldn’t apply. How does it work? When accessing a protected resource, a push notification is sent to the user’s mobile device. The user opens the OOB app, taps to approve the login request, and is then logged in to the resource. Interestingly, Gartner predicts that, “By 2019, 60% of phone-as-a-token deployments will use out-of-band push modes for the majority of users, up from less than 10% today. ”

NIST’s new guidelines have made the headlines as a result of the wide adoption of SMS-based OOB by leading social media and retail sites. The method’s pervasiveness largely stems from its ease of use, and the fact that websites don’t have to distribute any hardware or software, and can support any ‘dumb phone.’ With the evolving nature of digital fraud, it only stands to reason that NIST should evolve their guidelines to keep up with today’s mal-doers.

At the end of the day, being able to use Push authentication and other strong authentication methods is all about choice, flexibility – and making sure that the assurance level used is appropriate to the sensitivity of the assets being accessed. So although NIST has given a “thumbs down” to SMS authentication, organizations still have at their disposal a wide range of authentication methods that provide excellent levels of security combined with an easy and unobtrusive user experience.



(10)
(0)




Zerify Inc (ZRFY) Stock Research Links


  1.  
  2.  


  3.  
  4.  
  5.  






Investors Hangout

Home

Mailbox

Message Boards

Favorites

Whats Hot

Blog

Settings

Privacy Policy

Terms and Conditions

Disclaimer

Contact Us

Whats Hot

Recent Activity

Most Viewed Boards

Most Viewed Posts

Most Posted Boards

Most Followed

Top Boards

Newest Boards

Newest Members

Investors Hangout Message Boards

Welcome To Investors Hangout

Stock Message Boards

American Stock Exchange (AMEX)

NASDAQ Stock Exchange (NASDAQ)

New York Stock Exchange (NYSE)

Penny Stocks - (OTC)

User Boards

The Hangout

Private

Global Markets

Australian Securities Exchange (ASX)

Euronext Amsterdam (AMS)

Euronext Brussels (BRU)

Euronext Lisbon (LIS)

Euronext Paris (PAR)

Foreign Exchange (FOREX)

Hong Kong Stock Exchange (HKEX)

London Stock Exchange (LSE)

Milan Stock Exchange (MLSE)

New Zealand Exchange (NZX)

Singapore Stock Exchange (SGX)

Toronto Stock Exchange (TSX)

Contact Investors Hangout

Email Us

Follow Investors Hangout

Twitter

YouTube

Facebook

Market Data powered by QuoteMedia. Copyright © 2025. Data delayed 15 minutes unless otherwise indicated (view delay times for all exchanges).
Analyst Ratings & Earnings by Zacks. RT=Real-Time, EOD=End of Day, PD=Previous Day. Terms of Use.

© 2025 Copyright Investors Hangout, LLC All Rights Reserved.

Privacy Policy |Do Not Sell My Information | Terms & Conditions | Disclaimer | Help | Contact Us