Trusted Identities

No ratings

Presented at AUScert 2008 by

The foundation of computer security is identity. Given a trusted identity, you can reason about whether someone or something should be granted a privilege. Without it, you can't authoritatively identify your data, much less know who or what is trying gain access. Unfortunately, trustworthy identities are extremely hard to come by as is evidenced by the success of spoofing, phishing, pharming, trojans, rootkits, and identity theft. This session examines how identities can be assigned, trusted, and used to make and enforce security decisions. It will also discuss the necessary steps and risks attendant to doing so.