Sunday Mar 31, 2013

Authentication and Authorization Problem in Cyprus

If you are following the Cyprus bailout story, you will sympathize with the extraordinary situation faced by Cypriots coping with unprecedented banking regulation. Faced with a risk of capital outflow, the government placed limits on domestic and foreign currency transactions. After the restrictions were lifted, it was discovered that there were loopholes that allowed withdrawals from subsidiary banks in London where the controls were not enforced. For controls to work they have to be consistent. The limits are very specific and very difficult to enforce. As institutions and governments try to apply fiscal or regulatory controls over large groups of people, the controls are only as effective as the identity management capabilities of the institution. The problem is latency. The longer it takes for an endpoint or in this case a bank subsidiary to get updated, the more security risk. In this case Cyprus loses a significant fraction of foreign deposits.

The problem is not unique to Cyprus. During the American financial crisis, the breakdown in trust almost froze the credit system. When a credit card is swiped at the local retailer, the authentication does not always go directly to the bank that issued the credit card. The transaction flows to a merchant bank. The entire system depends on keeping the merchant banks in synch. Every transaction we make without cash has an element of identity involved. The economic cost of identity authentication, while not explicit, is a factor in every credit card transaction and every purchase online. The Cyprus crisis demonstrates what can happen if identity controls break down or fail. In Cyprus the consequence is failure of the banking system.

Authentication failure at an individual level ends in fraud or theft. As the customer experience becomes more digital the consequences are more drastic. Authentication failure can hurt an individual, a business or in this case compromise the future of a nation.

About

Oracle Identity Management is a complete and integrated next-generation identity management platform that provides breakthrough scalability; enables organizations to achieve rapid compliance with regulatory mandates; secures sensitive applications and data regardless of whether they are hosted on-premise or in a cloud; and reduces operational costs. Oracle Identity Management enables secure user access to resources anytime on any device.

Search

Archives
« March 2013 »
SunMonTueWedThuFriSat
     
1
2
3
5
9
10
11
12
16
17
23
24
28
29
30
      
Today