Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: ual Factor/Adaptive Authentication

Re: ual Factor/Adaptive Authentication

From: Saqib Ali <docbook.xml_at_gmail.com>
Date: Thu, 4 May 2006 07:56:36 -0700

On 5/3/06, Casey DeBerry <cdeberry_at_cobizinc.com> wrote:
> If you are in any way governed by FFIEC, this is your MO for 2006. I
> had an introduction to RSA's offering today which included recently
> purchased Passmark, and Cyota's converged solution. Initially, I was

BofA uses Passmark (see http://www.bankofamerica.com/privacy/passmark/
). The security concerns of Passmark was dicussed on Full disclosure
see:
http://seclists.org/lists/fulldisclosure/2005/May/0629.html

Passmark technology tries to solve the machine authentication problem
using encrypted cookies. The idea looks good, but I don't know how
safe it is.

I would personally wait till Passmark and similar technologies utilize
TPM (Trusted Platform Module) to perform a mutual authentication
before I can consider replacing physical hardware tokens with
Passmark.

But then again a TPM does NOT replace a USB cryptographic key device /
token. They compliement each other. A USB token/smart card
authenticates the user whereas a TPM authenticates a machine.

I guess use of passmark instead of physical tokens will depend on the
security needs of the system.....

--
Saqib Ali, CISSP, ISSAP
Support http://www.capital-punishment.net
-----------
"I fear, if I rebel against my Lord, the retribution of an Awful Day
(The Day of Resurrection)" Al-Quran 6:15
-----------
-------------------------------------------------------------------------
Sponsored by: Watchfire
The Twelve Most Common Application-level Hack Attacks
Hackers continue to add billions to the cost of doing business online 
despite security executives' efforts to prevent malicious attacks. This 
whitepaper identifies the most common methods of attacks that we have seen, 
and outlines a guideline for developing secure web applications. 
Download this whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=701300000007t9r
--------------------------------------------------------------------------
Received on May 04 2006
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos