Advertisement
Promo

Security management Toolkit

Amazon's cloud gets multi-factor authentication

David Meyer ZDNet.co.uk

Published: 01 Sep 2009 15:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Users of Amazon Web Services are being offered authentication devices, similar to those used by many online banking customers, for secure access to their cloud services accounts.

The AWS Multi-Factor Authentication (AWS MFA) security system was announced on Monday on the Amazon Web Services Blog. The system uses a device roughly the size of a USB memory stick to generate a single-use, six-digit code which can be used as an extra layer of security after the entry of the user's email address and password.

One token generator is currently on offer — the Ezio, from security company Gemalto — but Amazon says a variety of companies will provide the devices.

In the blog post, the AWS team said the device should be "especially attractive" to the service's enterprise customers.

"The devices are small, lightweight, and long-lasting," the team wrote. "Fraudulent usage becomes much more difficult because a successful login combines something you know (your email address and password) with something you have (the authentication device)."

The single-use passwords are generated according to a reference architecture provided by the Initiative for Open Authentication (OATH), an industry body for authentication open standards. Only one device can be used for accessing each AWS account.

Gemalto's Ezio device is currently only available to US customers. Requests to Amazon for a time scale for UK customers being able to use MFA on their AWS accounts received no reply at the time of writing.

 

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters