The core vulnerability lies in the separation between the login process and the subsequent active session. Most systems verify a user's identity once, then hand off access, creating a gap that attackers exploit to intercept communications. Nguyen-Huu argues that this model is outdated, as it relies on human-managed credentials rather than machine-to-machine cryptographic certainty.
To bridge this gap, WinMagic proposes a framework called Live Identity in Transaction (LIT). Instead of relying on passwords or one-time codes, this approach requires the endpoint device to generate a cryptographic key tied directly to the specific service being accessed. By automating this process, the device verifies the user and the session continuously without requiring manual input. The company has already submitted proposals to the World Wide Web Consortium and the Internet Engineering Task Force to standardize this interaction.

Comments (0)
No comments yet. Be the first!