<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: imagic]]></title>
    <link>http://securityratty.com/tag/imagic</link>
    <description></description>
    <pubDate>Thu, 20 Dec 2007 06:31:28 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[New Year's Resolutions for choosing online retailers]]></title>
      <link>http://securityratty.com/article/e6187ca5c7aabde03cc281013f8d6509</link>
      <guid>http://securityratty.com/article/e6187ca5c7aabde03cc281013f8d6509</guid>
      <description><![CDATA[With CardSpace and Higgins being in nascant and almost non-existent market adoption mode, you may wonder what authentication features you want to be looking for when shopping online. Usernames and...]]></description>
      <content:encoded><![CDATA[<p>With CardSpace and Higgins being in nascant and almost non-existent market adoption mode, you may wonder what authentication features you want to be looking for when shopping online. Usernames and passwords are a thing of the past: you can safely assume that you will use a computer to log in which has a keylogger or trojan capturing your keystrokes, and with it your username and password.</p>

<p>Savvy customers are increasingly turning towards online retailers and financial institutions which provide at least some form of multi-factor authentication to protect against password theft. The following list gives a compass to consumers and vendors to navigate the misty waters of online transactions.</p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Smart cards / USB tokens</span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> (very costly, high level of security, great user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Hardware based solution that contains applications, PKI certificates used to authenticate to a site. These cards can include a magstripe for physical access management and RFID proximity sensors.</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: ActivIdentity, Aladdin Knowledge Systems, CRYPTOcard, EntrusT, PortWise, RSA Security, VASCO Data Security</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></span></p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">One time password hardware token</span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> (very costly, high level of security, great user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Token generates a one time password that the user must input during login.</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: ActivIdentity, Entrust, CRYPTOcard, Secure Computing Safeword, RSA Security, VASCO Data Security</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></span></p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">One time password software</span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> (costly, medium level of security, medium user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">User has a portable device (cell phone) with software that generates OTP.</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: ActivIdentity, Entrust, CRYPTOcard, PortWise, RSA Security, VASCO Data Security</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></span></p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Wallet card </span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">(scratchpad, gridcard) (inexpensive, low level of security, medium user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">User has a list of OTP passwords printed on a sheet or a grid card of letters and numbers that the user has to enter when logging in.</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: Entrust</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></span></p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Out of band authentication</span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> (costly, medium level of security, medium level of user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">User receives a secondary one time password in a text message or callback to their registered cell phone.</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: Authentify Technology, Digital Envoy, RSA Security/PassMark Software, Swivel Secure</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></span></p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Device fingerprint</span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> (inexpensive, low to medium level of security, low user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Upon login, the user’s desktop software, hardware and browser environment generate a unique fingerprint. If the user’s desktop changes, user is prompted for additional knowledge based authentication (i.e. must answer multiple security question and answer pairs correctly in addition to providing the correct username and password).</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: Oracle Adaptive Authentication Manager (Bharosa acquisition), Digital Envoy, Entrust, iovation, RSA Security</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></span></p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">File-based device authentication</span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> (inexpensive, low to medium level of security, low user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Website puts a cookie on the user’s browser and uses the cookie to display a user-selected image the next time logs in. This method authenticates the website to the user (mutual authentication).</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: Arcot Systems, TriCipher, Oracle Adaptive Authentication Manager (Bharosa acquisition), Entrust, RSA Security/PassMark Software</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></span></p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">IP Geolocation</span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> (inexpensive, low level of security, low user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Inbound access management looks at the user’s IP address to check for plausible velocity of logins (user can’t legitimately login within 30 minutes from a IP address in the US and China).</span>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: Digital Envoy, Quova, Oracle Adaptive Authentication Manager (Bharosa acquisition)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"></span></p>

<p class="MsoNormal"><strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Keystroke dynamics</span></strong><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"> (inexpensive, medium level of security, medium user inconvenience)</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">User’s keystroke dynamics for entering the username and password (for how long the user presses a key and how long it takes them to move between keys) is used as a second factor for authentication.</span></p>

<p class="MsoNormal"><span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial">Vendors: BioPassword, iMagic Software</span></p>

<p class="MsoNormal"></p>

<p class="MsoNormal"></p></p>]]></content:encoded>
      <pubDate>Thu, 20 Dec 2007 06:31:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/user inconvenience">user inconvenience</category>
      <category domain="http://securityratty.com/tag/low user inconvenience">low user inconvenience</category>
      <category domain="http://securityratty.com/tag/users desktop">users desktop</category>
      <category domain="http://securityratty.com/tag/users desktop software">users desktop software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/medium user inconvenience">medium user inconvenience</category>
      <category domain="http://securityratty.com/tag/low">low</category>
      <category domain="http://securityratty.com/tag/imagic software">imagic software</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <source url="http://blogs.forrester.com/srm/2007/12/new-years-resol.html">New Year's Resolutions for choosing online retailers</source>
    </item>
  </channel>
</rss>
