I came up with this idea related to the Introduction to Identity talk I ll be performing at Identiverse on Monday at 1:30pm PDT. The idea is simple: curate a list of talks that, in my opinion, might help a newcomer to identiverse or identity navigate the conference in a way that might make their experience Continue reading "Identity Basics Talks at Identiverse"
Back at Identiverse in 2022, as I completed my final term as a founding member of the Board of Directors at IDPro and my one year as its Chair, my emotions were mixed and fairly intense. This was a close to an amazing chapter of helping build an organization whose mission I was zealously passionate Continue reading "Milestone Achieved!"
If you re a member of IDPro, you already know part of this story, at least the professional version. Today marks the last day of my 3rd term as a member of the Board of Directors with IDPro. 5 years! Per the bylaws of this terrific organization, a board member is limited to no more than Continue reading "Turning the Page with IDPro"
(note: this is a writeup of a talk that I gave at DerbyCon 2019 and at UNCC s CyberSecurity Symposium in 2020. Thought it would be useful to get it in blog form, especially with the Solar Winds event unfolding.) It seems like today’s world offers constant reminders of how insecure our digital lives can be. Continue reading "Evaluating 2FA in the Era of Security Panic Theater"
I ll be the first one to admit that I jumped the gun a little when Twitter announced that their founder, Jack Dorsey, had his account hijacked. Initially, no one (including yours truly) had details as to how his account was taken over. However, all fingers pointed at a SMS jacking, which wasn t terribly far from Continue reading "SMS as a 2FA Method"
This talk was originally given at RSA, but I was able to do an expanded version recently at IT Hot Topics. A few have asked for the slides, so here they are. I actually hope to write out the talk in full at some point as a blog post, but I have two more talks Continue reading "Slides from Recent PAM Talk"
Think of everything you do in terms of a rheostat, rather than a switch. Horseman Mark Rashid In information security, we often measure the controls that are deployed in terms of the friction, or resistance that is presented to the user. In digital identity, we speak of balancing the user experience against the friction that Continue reading "Applying a Rheostat to Local Admin Rights"
I m not writing this to shame a company, though I do plan to share this post with them in hopes that they can make some adjustments that will benefit customers in the future. As such, I ll do my best to mask their identity as much as reasonably possible. Before doing so, I want to back Continue reading "Why UX Matters or How Color (and other) Choices Can Ruin an Identity Experience for Users"
(Note: this topic is background for a panel that I m participating on June 20th at the Cloud Identity Summit, in Chicago, Illinois. I wrote this in hopes of informing some of the context around the panel, though I m sure it will be revisited in some respect during our session.) Knock, Knock: Identity is here. Identity Continue reading "Deploying Identity Solutions Field of Dreams Doesn t Work"
(photo credit: Brian Campbell) I think teaching eviscerated my time for blogging. Going to try and put more energy in it this year. Naturally, I m going big on this revival with a two part post about my experience at the RSA Conference, to the best of my knowledge the largest security conference on the planet Continue reading "RSA Thoughts, Part 1"