Get the latest tech news
Summary of the USA federal government's zero-trust memo
An overview of the U.S. Government’s mandate towards zero trust cybersecurity principles and the impact it will have on the private sector.
The memo is a reaction to 2020’s SolarWinds incident and 2021’s Colonial Pipeline rasomware attack, and advises the Federal Government on what steps each agency must take to improve its cybersecurity. “discontinue support for protocols that register phone numbers for SMS or voice calls, supply one-time codes, or receive push notifications''. But the memo also dismisses the popular one-time code approaches like the TOTP protocol (the Google Authenticator on your phone), which is basically the state of the art for SaaS business everywhere.
Or read this on Hacker News