Following the news that Dropbox is resetting passwords that haven’t been changed since 2012, Charles Read, Regional Director – UK, Ireland and Benelux at OneLogin commented below.
The comment looks at how, despite it being a positive move to come from a vendor as large as Dropbox, for a truly secure environment, the implementation of a single sign-on platform with SAML based authentication services is recommended.
Charles Read, Regional Director – UK, Ireland and Benelux at OneLogin:
In the corporate world, utilising a password as the only form of authentication for multiple accounts is already considered as weak security, however we are yet to see consumers apply this approach to the protection of their personal credentials. By adopting two factor authentication on top of regular passwords it’s possible to significantly reduce the risk coming from compromised credentials. However, for a truly secure environment I would always advocate the implementation of a single sign on platform with SAML based authentication services, something that Dropbox has supported in its product for many years. Two factor authentication can then be layered on top of this technology to entirely eliminate the risk associated with stolen credentials.”