Over the last decade cloud computing vendors have invested heavily in making Software-as-a-Service secure as possible. Daily security audits, SSL-based encryption, and SAS 70 Type-II-certified data centers are now the norm, rather than the exception, and data stored in the cloud is now privileged to receive some of the best security technology can afford.

However, as with any security framework, cloud computing security is only as good as its weakest link, and in many circumstances the weakest link is the password used to access a web-based application. Passwords are often easier to guess than users think, and are all too often scribbled on notepads or Post-it notes for prying eyes to see.

To help combat any human-introduced weakness to the security equation, many security-focused services are deploying a technology called two factor authentication. Rather than using just a password to login to a website, users couple a password with a second authentication mechanism. This second authentication mechanism is typically a physical token that generates a second single-use PIN that is used in conjunction with the main password. A widely-used physical token in the banking industry is a keyfob similar to that pictured above, where a unique single-use PIN is generated and used and alongside the primary password. With two factor authentication even if someone has stolen your password, they'll need physical access to your secondary authentication mechanism's PIN in order to access your cloud-based data.

While two-factor authentication has been around for years, this week it has taken a major step forward with Google's announcement that it will adopt two-factor authentication for millions of Google Apps users. Google's enhanced authentication system uses SMS- and mobile application-based security tokens as the secondary authentication mechanism, requiring that users couple their password with a secondary PIN received by SMS:

Google's adoption of two-factor authentication in Google Apps is one of the first deployments of two-factor authentication in a widely used cloud-based application, and may set a new security standard against which other cloud-based providers will be measured.

Jack Newton is co-founder and President of Clio, a leading provider of cloud-based practice management software. Jack writes frequently on the security, ethical, and practical aspects of cloud computing, and has spoken at CLE seminars across Canada and the U.S. about how practice management systems can be used to help a lawyer practice efficiently, ethically and competently. Jack can be reached at jack@goclio.com.
[click on the author's name for more information]

up

4 Comments on “Beyond Passwords: Two Factor Authentication Comes to the Cloud”

  1. Looks like full rollout now for Apps Premier, Education, and Government Editions, and Standard Edition users will have a couple more months to wait.

    For lawyers dabbling in G. Apps, this might be the needed push to get them to pay for the Premier edition. That & the uptime guarantee. :)

  2. John G says:

    So those without mobile phones can't use the application? Or is there a way to receive SMS without a phone? It increases the security against people who aren't on your machine(s), anyway, which is important. Of course those people can't read your primary password from the sticky attached to your monitor either (or if you have any sense, stuffed into a drawer in the form of a hint, so a bad guy would have to have access to the premises for a long time to get anywhere.)

  3. Jack Newton says:

    @Steve – I agree. I think at $50/user/year Google Apps is a no-brainer – the value-add in the form of the uptime guarantee, support, and now two-factor authentication are all strong reasons to opt for it.

    @John – I believe a cell phone would be required as the various options – SMS, mobile app, etc. – all run on a mobile. However, the iOS application might work on a iPod Touch.

  4. John Elwell says:

    We've been using cloud computing in my tax practice for 7-8 years. I really like this idea and will take a serious look at implementing it with my IT manager. Thank you!

SlawTips      

SlawTips United Nations Documents
Wednesday, May 23

Today’s Tip: Monitor UN documents with RSS Since I last looked, the United Nations Documents site has a new look and feel. For what the site is trying to deliver, … »»

Research

SlawTips Updated Version of Great Social Media Guide for Lawyers Released
Wednesday, May 23

Last spring, Meritas’ Leadership Institute released a Social Media Guide for Lawyers. This helpful resource provided lawyers with an overview of the three main social media tools — LinkedIn, Faceb. […] »»

Technology

SlawTips Cash Flow Reports – Part 1
Thursday, May 17

Following on our earlier Top 10 Financial Errors posts, this is the first in a series of 10 posts dealing with Cash Flow Reports and in particular, cash flow management.… »»

Practice

noted on Slaw    

MLB Selected Case Summaries    

These summaries of selected recent cases are provided each week to Slaw by Maritime Law Book.
More information.

  • Aliens - Exclusion and expulsion - Power to detain and deport - Minister’s certificate - Review - Evidence

    In 2002, Harkat was detained pursuant to a ministerial security certificate issued under the Immigration and Refugee Protection Act (IRPA) as a person inadmissible to Canada on grounds ...

  • Contracts - Formation of contract - Signing - Electronic signature

    The plaintiff expressed an interest in purchasing the defendant’s (vendor’s) condo. The parties agreed to carry on their discussions through e-mail. Following an exchange of e-mails, the plaintiff claimed that the defendant was contractually bound to ...

  • Barristers and Solicitors - Relationship with client - Confidential communications - General

    The petitioner was a Receiver appointed in March 2009 by a California court over the assets of GJB Enterprises Inc. (a “Ponzi scheme”) and its principals, the Berkes (the GJB parties). The court ordered ...

  • Practice - Costs - Funding before judgment - When interim or advance costs available

    The plaintiffs were “direct to home” satellite based subscription program providers. Rex and other defendants offered “grey market” services to Canadian residents to facilitate the unauthorized reception in Canada of the plaintiffs’ ...

TalkLaw/ParLoi    

This is a listing of a few upcoming events in Canada of interest to lawyers, law students, legal librarians, and others involved in the practice of law.

Clicking on any event in the list below will give you access to more information and to links allowing you to see the full entry and to add the event to your own calendar.

Click this link for a fuller version of the TalkLaw/ParLoi calendar of events and for instructions as to how to add events and calendars to your own calendar.