Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Token authentication with web applications

Token authentication with web applications

From: Ivan Krstic <krstic_at_fas.harvard.edu>
Date: Thu, 01 Jul 2004 23:48:22 +0100

All,

I'm looking for people's experiences with cheap, uncomplicated token
devices or other physical means of authentication that play nicely with
more traditional authentication methods in web applications.

The cheapest solutions that came to mind are printing credit-card sized
s/key cards, or burning mini-CDs with a key and an auth agent for users.
Obviously, both methods are flawed (s/key cards can be copied down if
left exposed, and that's assuming they're not taped to the monitor,
while a stolen CD can be copied and replaced without evidence of
tampering[1]), but would still raise the security bar at essentially no
cost. More extensive authentication solutions are usually rather expensive.

Thoughts?

Cheers,
Ivan.

[1] The s/key printed cards at least address this insofar as the user,
presuming he can be bothered with remembering which of the 100 s/keys he
used last, can notice that an intruder gained access to the system.
Received on Jul 02 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]