I will eat my hat if this happens in that timeframe.
I will eat my hat if this happens in that timeframe.
Login.gov (a product of USDS and 18F @ GSA) is positioned to meet these identity provider needs.
https://www.login.gov/help/get-started/authentication-option... (2FA support for all users + PIV/CAC support for Fed Gov workers)
https://developers.login.gov/ (developer resources)
Skepticism is warranted as 6 USC 1523: Federal cybersecurity requirements [1] has required a lot of what the EO is calling for for almost half a decade, but the tooling exists and 82 agency applications/systems (as of October 2020) are already leveraging this identity provider. Appropriations ($$$) for this identity integration work seems the challenge, as implementation is straightforward.
Sidenote: You can now login to your Social Security Administration account with Login.gov [2] (under "Other Sign In Options"). If you've applied for TSA Precheck or Global Entry, you've been using Login.gov for some time.
[1] https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim...
[2] https://secure.ssa.gov/RIL/SiView.action
(disclosure: no affiliation with any federal government agency or office, not a fed gov employee or contractor currently)
Interestingly enough, the TSA Jobs portal does use Login.gov. [3]
[1] https://login.gov/help/specific-agencies/trusted-traveler-pr...
The process for establishing identity for login.gov was frighteningly easy. It required something like my Global Entry ID and my full name only, and then it automatically connected with other details about me.
The takeaway for me is to go claim my login.gov ID (if possible) before someone else does.
> The Cybersecurity and Infrastructure Security Agency will get $650 million for cybersecurity risk mitigation. The agency has been leading the federal government’s investigation into the SolarWinds hack that breached several federal agencies.
> Also included in the relief funding is $200 million for the U.S. Digital Service, a technology team based within the Executive Office of the President. The General Services Administration will receive two appropriations through the COVID Relief Act: $1 billion for the Technology Modernization Fund and $150 million for its Federal Citizen Services Fund. The citizen services fund enables public access and engagement with government programs through a variety of operational programs and public-facing products, and supports the implementation of emerging technologies in agency-facing programs.
[1] https://www.nextgov.com/cio-briefing/2021/03/covid-relief-bi...
1) The Domain Name "login.gov" is inherently associated with these credentials, your Security Key hasn't the faintest idea how to use them on another site even if you yourself are completely fooled and believe you're on Login.gov
2) Even if the US government, your key manufacturer and Facebook conspire together to try to figure it out, there's no way to take their authentication data and correlate that Facebook user mikey-the-shoe is US Login.gov user Michael Shoemaker of New York based on the Security Key used on both sites. It seems like a good guess of course, but WebAuthn deliberately doesn't confirm this.
We adopted multi factor and now we’re in the process of rolling it out. At the moment Ted is our only user. But we aren’t not compliant.
The down side is that accessing a server requires a patched Putty from Centrify and about 27 configuration steps that are documented nowhere.
Unless you mean they're stuck on a version from 5+ years ago, which is believable, but hardly OpenShift's fault.
Edit: Not to say everywhere in the non-civilian side of the government is secure. It isn't. Just that there are pockets of it that are better hardened that we could just wholesale copy.
But besides that, the federal government already has an SSO provider that supports smart cards, U2F, and TOTP. I suspect many agencies will choose to adopt that rather than trying to roll their own SMS auth.
The important part of the EO is the section 3.d.i, which says that every 60 days, until MFA is fully adopted, the agencies will report to DHS their plan and progress for implementing MFA. So basically, they can take longer then 180 days, but they need to be transparent about their plan and the roadblocks they are hitting in doing so.