Risks arising from compromised identity
When an online identity is compromised, it causes actual harm. While internet services spend a lot of money to make their systems safe, compromising the identity procedures has an impact on the entire system. One prominent example is the banking industry, which is an appealing target since a breach might allow an attacker to steal cash. Losing the keys to systems that secure sensitive information, such as medical data, can have serious ramifications for users:
Figure 6.1 – Compromised identity risks
The issue with the web’s trust source and identity procedures is that credentials act as keys to all the values stored in the systems. A social security number, for example, can be a unique identifier for all US citizens, but it is also widely used as a validation secret, something that only the user knows and can thus be used to authenticate their identities. Furthermore, dangers exist across the systems...