The death knell sounds for traditional tokens writes Andrew Kemshall, co-founder of IT company SecurEnvoy.
There is an often used phrase that the stars have aligned but, in 2011, it is the technology that has come together to hammer the final nail into the physical tokensโ coffin. The cynical among you would argue that this statement has been made before and yes, I concede that tokens have survived and are still prevalent, so, why is this year different? Letโs examine the evidence.
Just before we do, letโs take a quick trip down memory lane:
โขDuring the 70s tape cassettes were the medium of the day
โขIn the 80s VHS cassettes reigned supreme
โขThe 90s saw the introduction of DVDs
โขAnd the millennium brought with it the BluRay Disc.
What does this demonstrate? Nothing lasts forever and two factor authentication isnโt any different. It too has experienced advancements, from the original complex and time consuming challenge tokens of the 70s to the time synchronised tokens of the 80s. 30 years later, and itโs as if time has stood still, as the majority of physical tokens still rely on this out-dated technology but the tide is turning.
If itโs not broken, why fix it?
True, there are few technologies that have stood the test of time as well as physical tokens have, but thatโs not to say theyโre perfect.
The fact is that there are a number of issues with their utilisation, some of which have been around since their introduction 30 years ago.
Itโs time to present the evidence:
โขRight from the start, token deployment has proven time consuming. For 1000 tokens to be distributed, with many sent using a postal system to remote workers, will take six months to complete.
โข10% will be broken, misplaced or stolen and need replacing each year
โขEach token typically has a life span of between three and five years after which it will need replacing
โขEnd users will forget their token โ even with the type designed to be added to a key ring, wasting their time and the help desks
โขA physical token system requires ongoing administration, such as pin management, re-synchronisation and replacing lost or broken tokens
โขThird party contractors will often find themselves carrying around a number of tokens for their various clients and having to work out which one is the right one for each system.
โขThe stark reality is that many organisations will take the decision that the security offered by two factor authentication isnโt justified against this level of investment.
SMS isnโt new so whatโs changed?
In 2000 the number of mobile phones started to sharply increase. In fact, according to gsmworld.com, there are over 4,947,400,000 GSM and 3GSM connections globally with the figure steadily increasing every second. By the time youโre reading this it wouldnโt surprise me if that figure had topped 5,000,000,000.
Utilising SMS technology any mobile phone can be used as an authentication token. A passcode is sent to a userโs device, eliminating the need for a physical Token. Other enhancements including the option of reusing a userโs existing password instead of remembering a separate PIN.
However, SMS technology alone isnโt the answer as there have been instances when it has proved to be unreliable. In a small number of cases, estimated at 4pc, SMS messages can take longer than one minute to get through. Other issues could be the network is temporarily suspended or the user may be in a signal dead spot, such as the basement of a building or computer room. It is this argument that has saved physical tokens in the past – but it can no longer stave off the Grim Reaperโs scythe.
With the advent of pre-loaded codes, mobile phones are able to hurdle this final barrier. As soon as a user enters their authentication code, the system automatically forwards a new SMS message, overwriting the code in an existing message ready for the next session.
Iโve invested far too much in tokens to change now?
Itโs always going to be hard to justify writing off an investment. Yet thatโs the sensible thing to do if you donโt want to continue haemorrhaging money supporting an old technology:
โขFor starters, it is estimated that moving to SMS authentication will reduce ongoing running costs by 40 to 60 per cent! This is substantiated by Gartner with its belief that โSMS OTP approaches the security of a dedicated hardware token, but at a lower cost and with higher convenience.โ
โขDue to their lifespan, youโll have to replace all your tokens within the next three to five years. With an SMS system, the majority of your users will already have a mobile phone. If for any reason a user does not have a mobile phone, a voice text can be sent instead to a number stored on the system.
โขThere is the argument that people do misplace their mobile phones but this is also true for physical tokens. It is peopleโs attachment to their mobile that is the differentiator as research by YouGov recently revealed that a third of the population would notice theyโd lost their mobile phone within 15 minutes and 60pc would within the hour. The emotional attachment to a physical token can mean its loss isnโt discovered until the user actually needs to use it which could be hours, or even days, later!
โขUsing automation, an SMS system can be set up in a day (an average of 300 users per minute) instead of six months. The existing employee database is used with mobile numbers automatically identified. For records where a number is not listed, an email is automatically sent requesting the user to self enrol.
โขIt can offer substantial benefits for organisations looking to reduce their carbon footprint. It would require 1673 trees to offset the emissions created in deploying 3000 tokens.
Goode Intelligence recognises that pre loaded codes are changing the playing field predicting that โ40 per cent of organisations plan to deploy services that will enable employees to use their mobile phone as an authentication device by the end of 2011.โ
This is substantiated by our own recent poll, conducted between November last year and January, with 146 people asked: โShould SecurEnvoy add support for hardware tokens?โ With an overwhelming 98 per cent responding no, so itโs not just me that believes the physical token is dead.




