Saturday | 4 July, 2009
CSO

Authentication

News
  • +

    Busted: the NSW Police crime fighting toolkit 02/06/2009 07:50:00

    State-wide background checks, facial recognition, faster forensics
    NSW Police will have access to a new forensic information database within nine months along with a suite of centralised records management and field imaging systems.
  • +

    Defence trials sneaky cameras 28/05/2009 10:39:00

    Lights and sounds key to good photos
    The Defence Science Technology Organisation (DSTO) is running facial recognition trials which will underpin biometric initiatives across the Department of Defence, Immigration and new smartcard driver's licences.
  • +

    Aussie govt considers quantum leap in secure comms 03/03/2009 13:27:00

    Commonwealth departments to trial Quantum Key Distribution.
    Commonwealth departments to trial Quantum Key Distribution.
  • +

    Fugitive hacker indicted for running VoIP scam 19/02/2009 10:05:00

    US seeks extradition of Miami man who was on the run for more than 2 years
    Just days after his apprehension in Mexico following two years on the run from law enforcement authorities, an alleged hacker was indicted this week by a federal grand jury for hacking into the computer networks of VoIP service providers.
  • +

    Biometric passports agreed to in EU 15/01/2009 04:40:00

    The European Parliament has voted to implement biometric passports in the EU, starting June 29.
    The European Parliament signed up to a plan Wednesday to introduce computerized biometric passports including people's fingerprints as well as their photographs, despite criticism from civil liberties groups and security experts who argue that the move is flawed on technical grounds.
  • +

    PCI council sharpens oversight of security auditors 19/11/2008 10:53:00

    Quality assurance plan targets security assessors and scanning vendors
    The PCI Security Standards Council Monday unveiled a plan to sharpen oversight of the hundreds of security-service providers now authorized to evaluate merchant networks under the organization's Payment Card Industry data standards.
  • +

    Microsoft tools to push identity platform to the cloud 29/10/2008 09:23:00

    Company to add SAML 2.0 protocol support
    Microsoft Tuesday will unveil an open identity platform code-named Geneva that extends to the cloud and includes development tools, gateway technologies and provides long-awaited support for the SAML 2.0 protocol.
  • +

    Cambridge lab sets quantum key world record 09/10/2008 08:51:00

    Researchers can now shift encryption keys around at speeds of 1Mbps.
    The hugely promising security technology of Quantum Key Distribution (QKD) has moved an important step closer to commercialization with the announcement by UK-based researchers that they can now shift encryption keys around at speeds of 1Mbps.
  • +

    Japanese military loses data again 02/07/2008 08:17:21

    Japan's Self Defense Force lost sensitive data on joint US-Japan military exercise
    Japan's Self Defense Force lost sensitive data pertaining to a joint US-Japan military exercise last year, the Ministry of Defense said Tuesday.
  • +

    Icy encryption tool protects laptops from "cold boot" attack, vendor says 14/05/2008 08:36:43

    Vulnerable encryption keys erased by HyBlue's IceLock
    The vendor HyBlue says it can prevent the "cold boot" encryption hack discovered by Princeton researchers with a laptop security product announced Tuesday.
  • +

    Linux, Unix, Mac, Windows PCs get authentication integration 06/12/2007 08:29:57

    Centeris releases version 4.0 of Likewise with the intent of making Linux a first-class citizen on Windows networks
    Centeris, which provides cross-platform authentication via Microsoft's Active Directory, Tuesday enhanced its Likewise platform (Clear Choice Test of Likewise)Â and an added open source project that will be distributed with the top Linux operating systems.
  • +

    PayPal, eBay and Yahoo begin rollout of authentication technology 04/10/2007 13:34:15

    Goal is to protect customers and reduce fake e-mails
    Yahoo!7, eBay and PayPal have joined forces to protect customers against fraudulent e-mails and phishing attacks with the implementation of new authentication technology.
  • +

    Study: Users ignore bank security features 06/02/2007 08:52:00

    A new study has found users of online banking sites tend to bypass critical clues that the integrity of those sites may have been compromised
    Users of online banking sites tend to bypass critical clues that the integrity of those sites may have been compromised, according to the working draft of a study released on Sunday by researchers at Harvard University and the Massachusetts Institute of Technology.
  • +

    E-mail authentication: Cost, standards remain problems 11/11/2004 11:07:29

    E-mail authentication can help fight the growing spam e-mail problem, but vendors need to come up with a single, open standard to avoid confusion and crippling costs for small ISPs (Internet service providers), participants in a U.S. government summit said Wednesday.
Features
  • +

    Security on a stick guards British diplomatic business 11/06/2009 06:05:00

    When it comes to security, the British government's Consulate-General in New York, part of the United Kingdom's diplomatic mission for business and visa-related activities, is taking no chances on spies or other intruders sneaking onto its network.
  • +

    Social Engineering: The Fine Art of BS, Face to Face 08/06/2009 23:06:00

    A confrontation with a facilities manager demonstrates social engineers' complete comfort dealing with (and manipulating) conflict
    Chris Nickerson is willing to push it about as far as a person can go when it comes to security assessments. The founder of Lares, a security consultancy in Colorado, Nickerson conducts what he calls "Red Team Assessments" for clients. He is paid to try and dupe a client, and the client's employees, to give them a clear picture of the weak spots in their security plan. He then advises them on how to shore up defenses more effectively in the event a real criminal comes knocking.
  • +

    Study: Secret questions don't safeguard passwords 20/05/2009 02:03:00

    Spouses and friends can often guess the answers to questions used to reset e-mail passwords
    Even if your spouse doesn't know your e-mail password, he or she probably knows enough information to get it.
  • +

    Password Seeks Partner For Long-Term, Secure Relationship 05/05/2009 09:25:00

    Forrester looks beyond the password to key trends in strong authentication
    Passwords have been standing guard over our computer user accounts seemingly forever; for a long while, and for most purposes, they could go it alone.
  • +

    Biometrics: 3 Tips for Success 12/03/2009 11:35:00

    False positives and faulty readers are common criticism of biometric security systems. But with the right plan, can they be practical in your security portfolio?
    False positives and faulty readers are common criticism of biometric security systems. But with the right plan, can they be practical in your security portfolio?
  • +

    Cyber security threats grow in sophistication, subtlety 16/10/2008 09:26:00

    Researchers say malware, botnets, cyber warfare, threats to VoIP and mobile devices, and the "evolving cyber crime economy" are ever-more sophisticated threats
    The annual report from Georgia Tech Information Security Center identifies five evolving cyber security threats, and the news is not good.
  • +

    How secure is secure enough? 29/07/2008 07:44:00

    Are your information security plans too big, too small or just right? Here are five steps to help you decide.
    If there is a Holy Grail in the information security industry, it surely is the answer to the question, "How secure is secure enough?"
  • +

    Five effective ways to burglar-proof your laptop 05/06/2008 07:55:35

    Five easy - yet effective - strategies to protect your laptop and the valuable data stored in it
    Theft of laptops and other mobile devices is spiraling, and the consequences -- financial and other -- are getting increasingly dire.
  • +

    Five steps to successful and cost-effective penetration testing 28/05/2008 08:57:20

    Spending your time and money well
    Whether you hire outside consultants or do the testing yourself, here are some tips for making sure your time and money are well spent.
  • +

    Five free pen-testing tools 28/05/2008 09:04:38

    The best things in life are ...
    Security assessment and deep testing don't require a big budget. Some of most effective security tools are free, and are commonly used by professional consultants, private industry and government security practitioners. Here are a few to start with.
  • +

    The darker side of Webmail 29/04/2008 10:02:55

    Web-based e-mail may be exposing you to privacy and security problems you didn't expect
    Web-based e-mail is booming. Services such as Gmail, Yahoo Mail and Hotmail are convenient, accessible and, best of all, free. Many of us have come to rely on them without giving it a second thought.
  • +

    Casino insider tells (almost) all about security 10/03/2008 07:56:55

    Engineer built systems used by up to half the world’s casinos
    Jeff Jonas knows the Las Vegas gambling industry inside and out. As the founder and chief scientist of Systems Research & Development (SRD), Jonas helped build numerous casino systems before 2005 when his company was purchased by IBM.
  • +

    Two-factor authentication: Hot technology for 2008 15/01/2008 12:12:09

    Where there’s a will, there’s a way
    We've known for a long time that requiring just a user name and password to get on the network or to access personal information on a Web site isn't the tightest security posture, but there weren't a lot of good alternatives, and there wasn't that much pressure to change.
  • +

    The top 10 reasons Web sites get hacked 05/10/2007 10:27:37

    Web developers ignore security flaws at customers' peril
    Web security is at the top of customers' minds after many well-publicized personal data breaches, but the people who actually build Web applications aren't paying much attention to security, experts say.
  • +

    E-commerce in crisis: When SSL isn't safe 17/05/2006 12:24:59

    A secure connection between browser and back end underlies Internet commerce. But what if it's already compromised?
Case Studies
  • +

    Uni fortifies Western Front with IDS 22/02/2008 20:11:00

    Nurtured NAC keeps malware out
    The University of Western Sydney (UWS) has today gone live with a managed Intrusion Detection System (IDS) for its 5000 users.
Interviews
  • +

    Head of PCI council sees security standard as solid 17/04/2008 10:40:46

    GM Bob Russo defends payment card rules but acknowledges that 'interpretation issues' remain
    The PCI Security Standards Council was established in the US by the major credit card companies in September 2006 as an independent organization to manage the Payment Card Industry Data Security Standard. In an interview, general manager Bob Russo talks about the council's efforts to administer the PCI standard amid continuing concerns about credit and debit card security. And he defends the standard, despite the recent data breaches at Hannaford Bros. and Okemo Mountain Resort.
  • +

    RSA CEO talks authentication 14/03/2006 08:44:20

    RSA Security late last year acquired privately held Cyota, which offers online security and anti-fraud services to help financial institutions protect consumer accounts. CEO Art Coviello recently sat down with Ellen Messmer to discuss the Cyota acquisition and RSA's views on the future of authentication. With its anti-fraud services for banks, Cyota is a very different type of business than RSA Security traditionally has been in with its SecurID products for two-factor authentication and the BSAFE encryption toolkits.
  • +

    Schneier: secure tokens won't stop phishing 15/03/2005 09:13:06

    Technology isn't going to protect e-commerce customers -- stronger government regulation is what will get the attention of online banks and merchants, forcing them to stop being casual about security, said Bruce Schneier, founder and chief technology officer of Counterpane Internet Security.
Opinions
  • +

    Hack a million systems - earn a job 16/07/2008 16:12:54

    The idea of employing an admitted botnet creator and carding software author might not be palatable for many, but not so for an 18-year old New Zealander.
    It has been a number of years since the fantasy that hackers will be offered a job by those who they hacked was even a potential reality, but there are reports that this might still be the case in New Zealand.
  • +

    Vendor group plans authentication protocol 07/01/2005 07:46:19

    Open source has encompassed all areas of software applications and services, so there was little doubt that authentication would, sooner or later, be part of this fast growing movement. OpenLDAP, the open source directory project, has been with us for quite some time. But there's a new movement to create an authentication protocol, to standardize how authentication data is exchanged.
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
 
Whitepaper

The business justification for data security

In the information security world we face two major types of threats: "noisy" threats which directly interfere with our ability to do business and "quiet" threats which cause real damage, but don't necessarily prevent people from doing their jobs. Read on to discover how to combat both types of threats and to justify the use of data security within your business.

Sponsored Links