As the information received from CTO team, RSA Risk Engine builds for every account a number of profiles ? Geolocation, Cookie, Flash Cookie, Class B IP and Device fingerprint.
For example, In order for the Device Fingerprint profile to be built, it requires some fields as a minimum requirement.
The "Display field" is currently one of these mandatory fields required for the device fingerprint profile to be created.
If a client does not send this field ? no Device Fingerprint profiles are built for its users.
The creation of the Device Fingerprint profile has nothing to do with the creation or not of other profiles.
The creation of one profile is not dependent on the creation of another
Sending more data elements, and more reliable ones would not always result in a general decrease of the Risk Scores, but rather in a lower false-positive ratio, more stable users? profiles and therefore, an overall higher quality of fraud detection.
Also the Cookies information are saved in our DB as they are received from the client. Encrypted or not ? the only thing that is important to us is their uniqueness.
If cookies are sent encrypted ? we save them this way.
Related Articles
Creation of an Admin Exceptions Tabular Report fails with 'ORA-01031: insufficient privileges' error in RSA Identity Gover… 119Number of Views SCIM API for User Creation 166Number of Views The "User Cannot change the password" flag for Active Directory Account creation in RSA Identity Governance and Lifecycle … 28Number of Views How to test authentication from RSA Authentication Agent 1.0.2 for Microsoft AD FS 3.0 when it fails with a UDP packet cre… 268Number of Views When removing a user from a large number of Roles, the Change Request creation fails with an 'ORA-01704: string literal to… 82Number of Views