Test User Registration Process (OTG-IDENT-002)

Summary
Some websites offer a user registration process that automates (or semi-automates) the provisioning of people with system access. The identity requirements for access vary from positive identification to none at all, depending on the security requirements of the system. Many public applications completely automate the registration and provisioning process because the size of their userbase makes it impossible to manage manually. However, many corporate applications will provision users manually, so this test case may not apply.

Test objectives
Verify the identity requirements for user registration align with business/security requirements

Validate the registration process

How to test

 * 1) Verify the identity requirements for user registration align with business/security requirements
 * 2) Can anyone register for access?
 * 3) Are registrations vetted by a human prior to provisioning, or are they automatically granted if the criteria are met?
 * 4) Can the same person/identity register multiple times?
 * 5) Can users register for different roles/permissions?
 * 6) What proof of identity is required for a registration to be successful?
 * 7) Are registered identities verified?


 * 1) Validate the registration process
 * 2) Can identity information be easily forged or faked?
 * 3) Can the exchange of identity information be manipulated during registration?

Example
In the Wordpress example below, the only identification requirement is an email address that is accessible to the registrant.

In contrast, the Google example below, the identification requirements include name, DOB, country, mobile phone number, email address and CAPTCHA response. While only two of these can be verified (email address and mobile number), the identification requirements are stricter than Wordpress.

Tools
HTTP Proxy

Remediation
Implement identification and verification requirements that correspond to the security requirements of the information the credentials protect.