60 Identity Problems that OneID can help solve
- “I forgot my username”
- “I forgot my password”
- The need to create new username and password at each new site
- Having to type in or remember usernames
- Having to type in
Passwords
- Typing in information that has already been typed in; repetitive form filling
- CAPTCHAs (you should only have to do that once if at all)
- Repetitive
E-mail and/or SMS verifications of your phone number and/or email
- Having to disclose credit card to a merchant
- Having to fill out forms to create an account
- Not being able to use US credit card at UK site
- Risk of CNP transactions
- Forced password changes
- Password standards
- Temporary passwords
- Picking usernames
- Shared secrets
- Mass breaches of other sites database allowing attacker to login to your site
with the same username and password
- Mass breach of password databases
- “I forgot my loyalty program #”
- I have too many loyalty cards
- Takes too long to fill out the application for a loyalty card
- Denied credit card charges
- Knowledge-based authentication security questions
- Need to share secrets over the phone or web with a server or person
- The risk of using a public terminal or a friend’s computer
- Usernames that are your old email and cannot be changed
- Break-ins of your accounts caused by theft of a password database at
that site or another site on the Internet where you used the same password
- Fear of an attacker stealing your identity and wiping you out
- The pain of changing your credit card everywhere when it is lost, stolen, or
expires
- The pain of changing your email everywhere when you get a new job or new email
- Remembering screen names
- The privacy risk (OneID can’t decrypt your data)
- The risk your IdP can pose as you
- No use of PKI so no DigiNotar
- Single point of compromises
- The incentive to phish
- Account lock outs due to:
- Inactivity
- New devices
- Invalid password guesses
- Use from strange locations
- Or any other reason
- Having to contact all appropriate vendors when any of your contact or billing
information changes
- The inability for RoboForm, etc. to fill out logins or forms on certain devices
and certain websites
- The need to change your password or PIN when one is compromised (phished or
break into the site or another site)
- The need to ever have to talk to a customer service representative about
authentication issues
- The need to remember who you gave your SMS to so in the event your phone is
stolen, you can revoke the SMS verification.
- The pain you have to endure when you try to convince the bank that they really
did steal your phone
- MITM, MITB attacks where you can’t trust what you see, even if you are using
SecurID (which is not out-of-band)
- LoA is set exclusively by the RP (user can’t get a higher LoA)
- The need to re-type authentication (password or PIN) within a short interval
- The ability to set LoA on a per transaction basis (no more having to approve a
free app purchase if YOU think it is silly)
- Malware threats including Citadel and
Eurograbber
- Problem with user forgetting he’s logged in when he leaves the computer so
someone else can make transactions as him
- User ambiguity where system needs to disambiguate from clever attacker and
legitimate owner
- Having to change ALL your passwords if malware on your machine and you are using
a password manager
- When your air carrier forgets your reservation, if they had stored the
confirmation code in your OneID, even when they make a mistake, you are still
covered because you can go to Account in OneID and retrieve the data
- The chance that you might have typed in the wrong passport number when you made
your plane reservations (because OneID can auto fill this info)
- Having to remember the answer to all the KBA ambiguous questions
- The risk that your account can be phished (no username or password to phish)
- Having to know about and manage digital certificates (these are all hidden)
- Having to remember which offer you want to associate with each merchant (e.g.,
you can associate the Virgin America miles offer with you Hertz reservation)
- Having to manage all those usernames and pwds, especially those tied to your old
email that you can no longer access!
- You changed your cell phone number. Now all those out of band verifications
don’t work (like at Microsoft)
- The insecurity of SMS;
Australian Telcos Declare SMS Unsafe For Bank (OneID never used SMS because it
is unsafe)
- Not being able to set a cumulative dollar limit on your identity so
you can secure your purchase
- You can't purchase on Best Buy and other sites with
RoboForm and other form fillers because the autofill doesn't trigger a
manual type-in, so users are completely baffled as to why their purchase
fails
- Being able to purchase from multiple Internet sites
and seeing all your tracking numbers and receipts in one place
See also:
OneID documentation guide |