|By Tom Smith||
|February 14, 2014 11:00 AM EST||
What have you done online today - checked LinkedIn? Facebook? Twitter? Opened and sent business emails? Used business apps? Every business employee also has a private life - and it's becoming increasingly difficult to keep the two separate. Rather than ignoring the growing role of social media in your customers' and employees' lives, many businesses are starting to take advantage of it. One way to do this is through social login.
Social login is a way to use social network credentials to create accounts on other sites or applications. From a business perspective, you may decide to offer social login to your customers. For this discussion, we'll call this the business-to-customer or B2C use case. There are also good reasons for offering employees the ability to access business applications using a social login. We'll call this the business-to-employee or B2E use case. Your employees are also consumers with social media accounts, and social login lets them use one set of credentials for multiple purposes.
Social login in a nutshell
Social login is a growing trend. While Facebook is the most popular social login identity provider (through Facebook Connect), others like Twitter, Google/Google Plus and Yahoo also offer social logins. See the research from Gigya on the fierce competition for social identity providers. It's popular because it solves a common problem - creating and remembering accounts and passwords for all of the various websites and applications we use.
You have most likely encountered social login when opening a new account on a website, if you are given an option of signing in with an existing social network account:
If you choose to login with your existing social network account, then you've opted in to social login. That decision has ramifications that you might not expect. Social networks are a mother lode of personal information - you may be sharing more than you realize.
Before you implement social login for your business' customers or employees, or choose to use it yourself, you should have an understanding of what's happening behind the scenes.
The social login: What happens behind the scenes
If your business wants to offer social login for customers on your website, you first need to choose which networks to link. Social login middleware or aggregators like Gigya and Janrain make it easy to offer social login through multiple social networks.
When a new user chooses the option of registering on a site with their social media credentials, they also grant permission to link your site with their account. You gain API-level access to personal data and contacts from the social network. The overall process is illustrated below:
Photo credit: Facebook
The process of granting permissions to your profile information is an "all or nothing" decision forced on you by the website you are trying to access. Without permission, the registration is canceled and the user must then create a new account directly with your website. But if the user grants permission, the social media account is linked to the website that you just registered at. Your website can now retrieve existing or new profile information without the user's future consent. The linked website can also post information to your social network. Of course, you must use care if you want to retain the customer.
From a business perspective, offering social login has many benefits:
- Social login makes it easy for new customers or consumers on your website to create accounts - reducing friction and potentially increasing sign-ups. Beyond the initial sign-up, research by Janrain shows that many people are more likely to return to a site that welcomes them with social login, while they will abandon sites for which they have forgotten their passwords.
- Consumer identity can be instantly verified; you have to use a real e-mail address to have ongoing use of your social media account. This verification dramatically reduces the number of bogus account registrations of people trying to remain anonymous and entering false information at account creation time.
- The social networks provide a rich source of demographic and behavioral data about your customers that they may not want to provide if they were filling out forms during registration.
However, there are also risk factors. Because the social media identity provider maintains data about the customer and manages their credentials, any problem with their credentials affects their ability to connect to your site as well. Alexandra Samuel posted about an experience of being shut out of multiple sites over the Thanksgiving weekend online shopping time because of a problem with her Facebook login on the HBR blog.
Social login and your employees
When it comes to your employees, the decision to use social login involves a different thought process.
The B2E use case has security and compliance implications. Identity and profile information shared from social networks creates additional points of attack for hacking into business accounts through social engineering or spear-phishing attacks. Social login gives criminals more avenues into personal information and logins, especially if employees are in the habit of using weak passwords or reusing passwords across multiple sites
For example, a hacker who discovers that one of your employees is an avid stamp collector and that they work at XYZ Company. They could send them an invitation to create an account on a stamp collecting website. If the employee uses the same login for stamp collecting as other apps, the attacker is in and knows what company to target.
Depending on what your employees share on Facebook, a site using Facebook Connect has access to personal identity information, including: birth date, photos, email address, employer, address, and interests.
With social login, your own business accounts are only as secure as the employee's social media account. And your business has no visibility or control into how employees create and manage passwords for their personal accounts, or whether they share passwords between personal and work accounts.
For these reasons, you don't want to establish a direct link between the social media accounts and your business applications. However, social login can be useful for your employees, as it reduces the number of passwords they have to track. There are ways to mitigate the risks of offering employees social login to business applications.
Making social login work for B2E
One essential difference with employee logins is that you already know the information you need about the employee's identity and job role. You don't need profile information from the social network. The social login can simply provide the login credential.
To reduce the risks of social login, create a ‘firewall' between the social network and your business applications, so business applications are never linked to your employee's social network accounts. Use the social login as a login credential for business applications, but require additional authentication for those applications. Used in this way, your business maintains its role as the authority or curator of employee identities and business application access at all times.
An identity and Access Management (IAM) or Single Sign-on (SSO) solution can act as this firewall between the social network and your applications. Because social media credentials are created outside of the business, you cannot trust them alone to grant access to sensitive business applications. The IAM solution can require additional authentication factors before authenticating an employee as a trusted user with the authority to access business applications.
In this configuration, your applications themselves do not directly interact with the social networks. The process workflow is illustrated below:
Your business retains full control over all business application logins through the IAM or SSO solution. No personal data is exchanged between business applications and social media networks. If someone leaves the company, you can instantly remove access to those applications with their social media account by shutting off access in the IAM or SSO. This does not, however, affect the employee's ability to access their personal social media account. If someone manages to steal the employee's social login credentials, two-factor authentication means that the identity thief is shut out of your business applications.
Since social login is only one method that an employee could use to login to business apps, a problem with the employee's social credentials does not shut them out of their business applications if they can authenticate directly with the IAM.
This approach is feasible even for small companies without existing investments in IAM solutions. A simple web-based single sign-on (SSO) solution with strong authentication capabilities can fill the role of social login secure bridge quickly and securely, offering employees the instant benefit of simpler logins and secure password management, while giving businesses the control and visibility needed for good governance and compliance.
Is it time to get social?
Businesses should look carefully at the potential benefits of social login. Using native social login on consumer-facing applications (your B2C websites) has many benefits: delegating the hard work of verifying identities, providing you with rich profile information, and reducing friction in the customer sign-up process.
In a business-to-employee context, social login can reduce the number of accounts and passwords employees have to remember. But never allow social media accounts to link directly to your business application - always use a secure intermediary IAM or SSO solution to control application access and manage additional authentication factors for sensitive business applications.
As enterprises work to take advantage of Big Data technologies, they frequently become distracted by product-level decisions. In most new Big Data builds this approach is completely counter-productive: it presupposes tools that may not be a fit for development teams, forces IT to take on the burden of evaluating and maintaining unfamiliar technology, and represents a major up-front expense. In his session at @BigDataExpo at @ThingsExpo, Andrew Warfield, CTO and Co-Founder of Coho Data, will dis...
Feb. 6, 2016 07:15 PM EST
SYS-CON Events announced today that Fusion, a leading provider of cloud services, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Fusion, a leading provider of integrated cloud solutions to small, medium and large businesses, is the industry's single source for the cloud. Fusion's advanced, proprietary cloud service platform enables the integration of leading edge solutions in the cloud, including clou...
Feb. 6, 2016 03:30 PM EST Reads: 703
With the Apple Watch making its way onto wrists all over the world, it’s only a matter of time before it becomes a staple in the workplace. In fact, Forrester reported that 68 percent of technology and business decision-makers characterize wearables as a top priority for 2015. Recognizing their business value early on, FinancialForce.com was the first to bring ERP to wearables, helping streamline communication across front and back office functions. In his session at @ThingsExpo, Kevin Roberts...
Feb. 6, 2016 03:15 PM EST Reads: 324
SYS-CON Events announced today that Commvault, a global leader in enterprise data protection and information management, has been named “Bronze Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Commvault is a leading provider of data protection and information management...
Feb. 6, 2016 02:30 PM EST Reads: 350
SYS-CON Events announced today that Alert Logic, Inc., the leading provider of Security-as-a-Service solutions for the cloud, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Alert Logic, Inc., provides Security-as-a-Service for on-premises, cloud, and hybrid infrastructures, delivering deep security insight and continuous protection for customers at a lower cost than traditional security solutions. Ful...
Feb. 6, 2016 01:30 PM EST Reads: 339
SYS-CON Events announced today that VAI, a leading ERP software provider, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. VAI (Vormittag Associates, Inc.) is a leading independent mid-market ERP software developer renowned for its flexible solutions and ability to automate critical business functions for the distribution, manufacturing, specialty retail and service sectors. An IBM Premier Business Part...
Feb. 6, 2016 01:00 PM EST Reads: 536
The cloud promises new levels of agility and cost-savings for Big Data, data warehousing and analytics. But it’s challenging to understand all the options – from IaaS and PaaS to newer services like HaaS (Hadoop as a Service) and BDaaS (Big Data as a Service). In her session at @BigDataExpo at @ThingsExpo, Hannah Smalltree, a director at Cazena, will provide an educational overview of emerging “as-a-service” options for Big Data in the cloud. This is critical background for IT and data profes...
Feb. 6, 2016 11:00 AM EST Reads: 115
With an estimated 50 billion devices connected to the Internet by 2020, several industries will begin to expand their capabilities for retaining end point data at the edge to better utilize the range of data types and sheer volume of M2M data generated by the Internet of Things. In his session at @ThingsExpo, Don DeLoach, CEO and President of Infobright, will discuss the infrastructures businesses will need to implement to handle this explosion of data by providing specific use cases for filte...
Feb. 6, 2016 11:00 AM EST
Fortunately, meaningful and tangible business cases for IoT are plentiful in a broad array of industries and vertical markets. These range from simple warranty cost reduction for capital intensive assets, to minimizing downtime for vital business tools, to creating feedback loops improving product design, to improving and enhancing enterprise customer experiences. All of these business cases, which will be briefly explored in this session, hinge on cost effectively extracting relevant data from ...
Feb. 6, 2016 09:00 AM EST
SYS-CON Events announced today that Interoute, owner-operator of one of Europe's largest networks and a global cloud services platform, has been named “Bronze Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2015 at the Javits Center in New York, New York. Interoute is the owner-operator of one of Europe's largest networks and a global cloud services platform which encompasses 12 data centers, 14 virtual data centers and 31 colocation centers, with connections to 195 ad...
Feb. 6, 2016 05:00 AM EST Reads: 328
Most people haven’t heard the word, “gamification,” even though they probably, and perhaps unwittingly, participate in it every day. Gamification is “the process of adding games or game-like elements to something (as a task) so as to encourage participation.” Further, gamification is about bringing game mechanics – rules, constructs, processes, and methods – into the real world in an effort to engage people. In his session at @ThingsExpo, Robert Endo, owner and engagement manager of Intrepid D...
Feb. 5, 2016 09:00 PM EST Reads: 770
Eighty percent of a data scientist’s time is spent gathering and cleaning up data, and 80% of all data is unstructured and almost never analyzed. Cognitive computing, in combination with Big Data, is changing the equation by creating data reservoirs and using natural language processing to enable analysis of unstructured data sources. This is impacting every aspect of the analytics profession from how data is mined (and by whom) to how it is delivered. This is not some futuristic vision: it's ha...
Feb. 2, 2016 02:00 PM EST Reads: 401
WebRTC has had a real tough three or four years, and so have those working with it. Only a few short years ago, the development world were excited about WebRTC and proclaiming how awesome it was. You might have played with the technology a couple of years ago, only to find the extra infrastructure requirements were painful to implement and poorly documented. This probably left a bitter taste in your mouth, especially when things went wrong.
Feb. 2, 2016 04:30 AM EST Reads: 838
Learn how IoT, cloud, social networks and last but not least, humans, can be integrated into a seamless integration of cooperative organisms both cybernetic and biological. This has been enabled by recent advances in IoT device capabilities, messaging frameworks, presence and collaboration services, where devices can share information and make independent and human assisted decisions based upon social status from other entities. In his session at @ThingsExpo, Michael Heydt, founder of Seamless...
Feb. 1, 2016 05:00 AM EST Reads: 921
The IoT's basic concept of collecting data from as many sources possible to drive better decision making, create process innovation and realize additional revenue has been in use at large enterprises with deep pockets for decades. So what has changed? In his session at @ThingsExpo, Prasanna Sivaramakrishnan, Solutions Architect at Red Hat, discussed the impact commodity hardware, ubiquitous connectivity, and innovations in open source software are having on the connected universe of people, thi...
Jan. 31, 2016 09:00 PM EST Reads: 715
WebRTC: together these advances have created a perfect storm of technologies that are disrupting and transforming classic communications models and ecosystems. In his session at WebRTC Summit, Cary Bran, VP of Innovation and New Ventures at Plantronics and PLT Labs, provided an overview of this technological shift, including associated business and consumer communications impacts, and opportunities it may enable, complement or entirely transform.
Jan. 31, 2016 07:15 PM EST Reads: 1,135
There are so many tools and techniques for data analytics that even for a data scientist the choices, possible systems, and even the types of data can be daunting. In his session at @ThingsExpo, Chris Harrold, Global CTO for Big Data Solutions for EMC Corporation, showed how to perform a simple, but meaningful analysis of social sentiment data using freely available tools that take only minutes to download and install. Participants received the download information, scripts, and complete end-t...
Jan. 31, 2016 10:00 AM EST Reads: 1,195
For manufacturers, the Internet of Things (IoT) represents a jumping-off point for innovation, jobs, and revenue creation. But to adequately seize the opportunity, manufacturers must design devices that are interconnected, can continually sense their environment and process huge amounts of data. As a first step, manufacturers must embrace a new product development ecosystem in order to support these products.
Jan. 31, 2016 10:00 AM EST Reads: 797
Manufacturing connected IoT versions of traditional products requires more than multiple deep technology skills. It also requires a shift in mindset, to realize that connected, sensor-enabled “things” act more like services than what we usually think of as products. In his session at @ThingsExpo, David Friedman, CEO and co-founder of Ayla Networks, discussed how when sensors start generating detailed real-world data about products and how they’re being used, smart manufacturers can use the dat...
Jan. 30, 2016 07:45 PM EST Reads: 771
When it comes to IoT in the enterprise, namely the commercial building and hospitality markets, a benefit not getting the attention it deserves is energy efficiency, and IoT’s direct impact on a cleaner, greener environment when installed in smart buildings. Until now clean technology was offered piecemeal and led with point solutions that require significant systems integration to orchestrate and deploy. There didn't exist a 'top down' approach that can manage and monitor the way a Smart Buildi...
Jan. 30, 2016 03:45 PM EST Reads: 1,258