SEARCH RESULTS
 
Showing 1-10 of 181 records
 
Expand article

End user security psychology, part II: Can knowledge-based authentication be effective?

2008-04-02 11:11:25 by Bill Nagel in Security & Risk Management
 
...authentication process drags on -- the more gantlets a user needs to run before being let in a site's front door -- the less secure those users perceive the site is Implementations of knowledge-based authentication (KBA) -- asking "secret", out-of-wallet questions that presumably only the end user knows the answers to -- on the Web have been...
 
 
 
 
 
Expand article

Keyloggers: Why Banks Need Two-Factor Authentication

The Article has images
2008-01-14 11:55:21 by Tim Bass in The Complex Event Processing Blog
...authentication . To illustratemy keypoints, I showedthe captive audiencevarious pictures of hardware keyloggers, for example the small black keylogger circled in the figure below There are PS2 keyloggers (illustrated above)and USB keyloggers. There are even keyboards with the keyloggers built into normal looking keyboards, so you have no...
 
 
 
 
 
Expand article

Increased Interest in Device-Specific Strong Authentication

2007-09-14 00:00:00 by Sean Kline in Speaking of Security, the RSA Blog and Podcast
 
...authentication mechanisms on a variety of client devices. Service providers, also, are interested in ensuring that end users are able to employ their mobile phones for two-factor authentication. Such organizations may also play the role of outsourcer and are concerned with the provisioning of credentials and new support models. Some of the...
 
 
 
 
 
Expand article

Remote Client Authentication

2008-07-31 13:30:21 by Editor in IEEE Security and Privacy
 
The effectiveness of remote client-authentication schemes varies significantly in relation to today's security challenges, which include phishing, man-in-the-middle attacks, and malicious software. A survey of remote authentication methods shows how each measures up and includes recommendations for solution developers and consumers
 
 
 
 
 
Expand article

"Off the Peg" Authentication can lead to an ill-fitting suit

2008-07-31 00:00:00 by Andrew Moloney in Speaking of Security, the RSA Blog and Podcast
 
...authentication -- using secret questions (you know the kind of thing -- mother's maiden name, date of birth, name of your favourite Spice Girl, etc, etc) -- before brokers can get on with doing business with their clients by phone. This comes a few months after a city firm was hit with a 77k (~$150k) fine for failing to do just that Now,...
 
 
 
 
 
Expand article

Top Five Intriguing Ideas for Authentication in 2008

2007-12-10 00:00:00 by Sean Kline in Speaking of Security, the RSA Blog and Podcast
 
...authentication) that they need and take a more holistic approach to implementing their strategy
 
 
 
 
 
Expand article

Yahoos Browser-Based Authentication service

2006-09-29 20:52:58 by Liudvikas Bukys in Liudvikas Bukys
 
Yahoos release of open access to its BBAuth authentication service (see also here and here ) is a big step forward. Its just the thing for many simple applications. Its not as good as a user-controlled cross-provider identity scheme, but the emergence of a few real high-volume competing web services will help drive us there
 
 
 
 
 
Expand article

Extensible Authentication Protocol (EAP) Security Issues

2008-03-09 00:00:00 by Editor in Infosec Writers Latest Security Papers
 
This document, written by Samuel Sotillo, presents an overview on some security issues that affect the Extensible Authentication Protocol as defined by the IETF RFC 3748
 
 
 
 
 
Expand article

PayPal E-mail authentication

The Article has images
2008-02-22 06:33:00 by Mike Rothman in Security Mike's Blog
...authentication - PayPal will issue you a token to more securely authenticate to your account. It costs $5 and you'll have to carry it around. I definitely adds more security to your account, but you have to carry the thing around. Did I mention you have to carry it around? I think using a strong password will provide enough security Signed...
 
 
 
 
 
Expand article

JanRain taps phone to deliver two-factor authentication

2008-05-13 00:00:00 by John Fontana in Network World on Security
 
JanRain Monday introduced two-factor authentication that taps into a standard telephone or cell phone to beef up security on its user-centric identity technology