Over the last decade cloud computing vendors have invested heavily in making Software-as-a-Service secure as possible. Daily security audits, SSL-based encryption, and SAS 70 Type-II-certified data centers are now the norm, rather than the exception, and data stored in the cloud is now privileged to receive some of the best security technology can afford.

However, as with any security framework, cloud computing security is only as good as its weakest link, and in many circumstances the weakest link is the password used to access a web-based application. Passwords are often easier to guess than users think, and are all too often scribbled on notepads or Post-it notes for prying eyes to see.

To help combat any human-introduced weakness to the security equation, many security-focused services are deploying a technology called two factor authentication. Rather than using just a password to login to a website, users couple a password with a second authentication mechanism. This second authentication mechanism is typically a physical token that generates a second single-use PIN that is used in conjunction with the main password. A widely-used physical token in the banking industry is a keyfob similar to that pictured above, where a unique single-use PIN is generated and used and alongside the primary password. With two factor authentication even if someone has stolen your password, they'll need physical access to your secondary authentication mechanism's PIN in order to access your cloud-based data.

While two-factor authentication has been around for years, this week it has taken a major step forward with Google's announcement that it will adopt two-factor authentication for millions of Google Apps users. Google's enhanced authentication system uses SMS- and mobile application-based security tokens as the secondary authentication mechanism, requiring that users couple their password with a secondary PIN received by SMS:

Google's adoption of two-factor authentication in Google Apps is one of the first deployments of two-factor authentication in a widely used cloud-based application, and may set a new security standard against which other cloud-based providers will be measured.

Jack Newton is co-founder and President of Clio, a leading provider of cloud-based practice management software. Jack writes frequently on the security, ethical, and practical aspects of cloud computing, and has spoken at CLE seminars across Canada and the U.S. about how practice management systems can be used to help a lawyer practice efficiently, ethically and competently. Jack can be reached at jack@goclio.com.
[click on the author's name for more information]

up

4 Comments on “Beyond Passwords: Two Factor Authentication Comes to the Cloud”

  1. Looks like full rollout now for Apps Premier, Education, and Government Editions, and Standard Edition users will have a couple more months to wait.

    For lawyers dabbling in G. Apps, this might be the needed push to get them to pay for the Premier edition. That & the uptime guarantee. :)

  2. John G says:

    So those without mobile phones can't use the application? Or is there a way to receive SMS without a phone? It increases the security against people who aren't on your machine(s), anyway, which is important. Of course those people can't read your primary password from the sticky attached to your monitor either (or if you have any sense, stuffed into a drawer in the form of a hint, so a bad guy would have to have access to the premises for a long time to get anywhere.)

  3. Jack Newton says:

    @Steve – I agree. I think at $50/user/year Google Apps is a no-brainer – the value-add in the form of the uptime guarantee, support, and now two-factor authentication are all strong reasons to opt for it.

    @John – I believe a cell phone would be required as the various options – SMS, mobile app, etc. – all run on a mobile. However, the iOS application might work on a iPod Touch.

  4. John Elwell says:

    We've been using cloud computing in my tax practice for 7-8 years. I really like this idea and will take a serious look at implementing it with my IT manager. Thank you!

SlawTips      

SlawTips Good Communications = Satisfied Clients
Thursday, February 23

As Richard Ferguson, a lawyer friend of ours says on his email message: “People may forget what you said…. People may forget what you did…. but people will never forget … »»

Practice

SlawTips Current Awareness
Wednesday, February 22

There are two possible approaches to personal current awareness: Develop excellent searching skills so that you can find what you need when you need it Pick a fairly narrow specialty … »»

Research

SlawTips Top 10 Financial Errors: #10 Rely on the Lottery for Your Partnership Retirement Plan
Thursday, February 16

“It is better to have a permanent income than to be fascinating” was said once by Oscar Wilde. The final tip in this series is the capstone issue in our … »»

Practice

noted on Slaw    

MLB Selected Case Summaries    

These summaries of selected recent cases are provided each week to Slaw by Maritime Law Book.
More information.

  • Limitation of Actions - Actions in contract - Actions for debt - General

    Moody died on December 3, 2005, leaving four adult children. Pursuant to Moody’s will two of her children, James and Tyrell, were appointed executors of the estate. It was alleged that, during her ...

  • Barristers and Solicitors - Discipline - Suspension - For professional misconduct

    McLean pled guilty five counts of conduct unbecoming a lawyer. The Discipline Committee suspended him from practice for four months and placed him on indefinite supervision. McLean appealed the length of the penalty.

    The Saskatchewan ...

  • Mines and Minerals - Operation of mines, quarries and wells - Licences and permits - Appeals or judicial review - Standing - Costs

    Grizzly Resources Ltd. (Grizzly). made an applications to the Energy Resources Conservation Board to drill two sour gas wells on the same site. ...

  • Narcotic Control - Offences - Trafficking - Elements of

    The accused was charged with trafficking in cocaine. The trial judge granted the accused’s motion to discharge the charge. The Crown appealed.

    The Saskatchewan Court of Appeal allowed the appeal and ordered a new trial.

    Link ...


TalkLaw/ParLoi    

This is a listing of a few upcoming events in Canada of interest to lawyers, law students, legal librarians, and others involved in the practice of law.

Clicking on any event in the list below will give you access to more information and to links allowing you to see the full entry and to add the event to your own calendar.

Click this link for a fuller version of the TalkLaw/ParLoi calendar of events and for instructions as to how to add events and calendars to your own calendar.

Switch to our mobile site