Go to Main Contents

:: Industry developments

Portal certification system for micro-mails and text messages, where's the balance between experience and security?

Portal certification in the public area, most of which is a code for the account. Micromail sweep and text message authentication codes are mainstreamed, experienced well, low thresholds. But they both have natural and security tensions: one we recognize.

Your position:Home > Content Centre > Industry News > > Text

Portal certification in the public domain is most annoying for users, with a loss code. Micromail sweeps and text message authentication codes are mainstreamed, experienced well, and have low thresholds. Both are natural and safe: micro-recognition is personal social identity, and text messages are not as easy to use as account numbers.

We can verify it for the open scene.

Open spaces like malls, playgrounds, waiting halls, where users come and go free, micro-scannap the fastest, just to pick up a cell phone. Wet identity is not a real name, but it can be linked to specific microsigners, so we can follow them. Wet is a top priority in open scenes, and hard access codes only drive people away. Wet also needs to get the authorization: take out necessary information, not get rid of users at once, or overtake data that they are wrongly able to comply with.

Text messages are valid for the scene of contact.

If you need to keep a mobile phone number for notice or secondary marketing, SMS certification is more appropriate. Users have both the numbers in the code and follow-up notices and return visits are useful. But text messages have a risk of being brushed, the authentication code interface has to be protected against bombing, otherwise someone takes a script out of the place and the channel can still be sealed. Text messages also require frequency: how often the same number is sent, how much the ceiling per day is, the rules are written down so that the interface is not controlled as a free sender channel, cost and safety.

Both have to be controlled and not run naked.

Micro-letters and text messages are not death-free. A microsignal is re-exchange equipment, a mobile phone number is registered in bulk, probably with a grey product. Basic wind control: frequency of same device numbers, congestment of the network, unusual concentration of time. Wind control is less complicated than it is to block a visible gathering and keep the wool party out of the door. Wind control rules need to be observed, which are an anomaly that can be seen at first glance, do not become black boxes, operate without knowing what is being guarded, and the rules are not adjusted.

The authentication code is not explicit.

SMS code is stored and transmitted encrypted in the chain, not explicitly in a log. Once an explicit code has been leaked, cell phone numbers plus authentication codes are used for counterfeiting. Logs are disaminative, transmission encryption, storage time-bound. These things look basic. The problem is a massive spill.

The wait for experience is hidden.

Users take the micro-letter authorization or text message, and then go to the real Internet for a few seconds, and experience design is crucial. Loading tips, failing to retry, and changing modes of entry are easy. When you wait unclear, users think they have broken repeat points and double the pressure on interfaces.

Failed to give user access

Micromails fail, text messages fail and the user is not able to receive them. It has to be done in a second way: change the way, contact the front desk, watch help. One road is left and it breaks, the user dies on the login page, and experiences an instant collapse. Multiple ways are used to get one out of the other, and one point is not available. The bottom is smart: one way is going to lose more than one way, another automatically alerting the user to make a mistake, and the operation will also detect access problems from the failure margin ahead of time.

Data belong and privacy to be written.

The information is classified as personal identification data, and the access rights are separated. It is not a risk to keep cell phone numbers and offline records in one library.

The tunnels need backup.

Text messages and micro-mail channels can be leaking. The main channel is available, the user side automatically cuts or suggests a change of direction. One after another, the factory upgrades or the tunnel shakes, it cannot get on the net, experience and safety are compromised. Backup access is usually not visible, life saving at critical times, switching strategy needs to be rehearsed early, so don't wait until you've really hung up before you cut it, which is already blown up by the user.

Security incidents need to be traced.

Any unusual, failed authentication or wind-controlled account that is blocked must be traceable. It is not a slogan to be followed. Retrospectively linked to online behavior: whether a microsignal abnormal actually connects to it and does anything, the ring is closed, and the retrace is justified only by recording an interception.

Someone's got to check the quality of the tunnel when it gets online.

The micro-letter and SMS channels are not finished, but they are often based on service rates, failure rates, and time. Quality declines occur early on, and users have to prepare or repair them before filing a large-scale complaint.

Portal certification systems receive micro-mails and text messages, the balance is not cut easily, leaving it easy for most people, keeping risk in a few anomalies. The way to choose between scenes, access controls, code hides, failure to get out, data writing belongings, experience and security are not zero-sum, but two sides of the same set.

Access Program I'll be right back. Telephone counselling