Sunday | 21 March, 2010
CSO

Authentication

News
  • +

    VeriSign rolls out new Web site verification service 24/02/2010 04:30:00

    The subscription service is designed for those Web sites not using SSL certificates
    VeriSign is introducing a certification service that confirms whether a business is legitimate and that their Web site is free of malware.
  • +

    CA brings SOA security to open source JBoss 09/02/2010 10:08:00

    More commercial options for widely-used app server
    CA has announced its SiteMinder and SOA Security Manager products are now available for the open source JBoss middleware platform.
  • +

    Twitter forces password reset to protect some accounts 04/02/2010 05:48:00

    The company has discovered that log-in information has been stolen in compromised torrent file-sharing sites
    Twitter required some users to reset their passwords on Tuesday after discovering that their log-in information may have been harvested via security-compromised torrent Web sites, the company said.
  • +

    Gmail of foreign journalists in China hijacked 19/01/2010 06:36:00

    Google says cyberattacks have also recently targeted the Gmail accounts of Chinese human rights activists
    The Gmail accounts of foreign reporters in at least two news bureaus in Beijing have been hijacked, a journalists' group in China said Monday.
  • +

    Microsoft buys health-care software company 11/12/2009 07:44:00

    Microsoft's plan to buy Sentillion could help it take advantage of a potential boom in health-care technology spending
    Microsoft plans to buy health-care software maker Sentillion for an undisclosed sum in order to expand its own health-care offerings and capitalize on an upcoming opportunity for new sales.
  • +

    US State Dept. worker sentenced for passport snooping 10/12/2009 05:38:00

    The agency employee is sentenced to 12 months of probation and community service
    An employee of the U.S. Department of State was sentenced Wednesday to 12 months of probation for illegally accessing more than 125 electronic passport application files, the U.S. Department of Justice said.
  • +

    New cloud-based service steals Wi-Fi passwords 08/12/2009 08:02:00

    The service can break WPA passwords in just 20 minutes
    For US$34, a new cloud-based hacking service can crack a WPA (Wi-Fi Protected Access) network password in just 20 minutes, its creator says.
  • +

    Security pro says new SSL attack can hit many sites 22/11/2009 08:17:00

    The researcher has developed generic attack code, but is keeping it private.
    A Seattle computer security consultant says he's developed a new way to exploit a recently disclosed bug in the SSL protocol, used to secure communications on the Internet. The attack, while difficult to execute, could give attackers a very powerful phishing attack.
  • +

    SSL flaw could have been used to hack Twitter 17/11/2009 07:47:00

    Other Web sites also may be at risk
    A flaw in the protocol used to secure communications over the Internet could have been used to hack Twitter accounts, according to an IBM security researcher.
  • +

    MasterCard to authenticate online transactions by phone 17/11/2009 07:41:00

    MasterCard adds one-time passwords to improve security
    In the face of mounting threats from hackers, MasterCard will use mobile phones to improve security for online transactions, the company said on Monday.
  • +

    First iPhone worm spreads Rick Astley wallpaper 09/11/2009 08:25:00

    Victims must have jailbroken phone, default password
    The first worm written for Apple's iPhone has been unleashed and is infecting phones in Australia.
  • +

    Software shields online banking on infected PCs 04/11/2009 08:49:00

    UK security vendor Prevx says its software locks out malware during transactions
    A U.K. security company is giving to banks, for free, security software that it says can block malicious software from manipulating online banking transactions or stealing data, even if the computer is infected.
  • +

    Massive bot attack spoofs Facebook password messages 29/10/2009 07:13:00

    'Bredolab' Trojan rides fake reset messages, reaches at least 735,000 users
    A massive bot-based attack has been hitting Facebook users, with nearly three-quarters of a million users receiving fake password reset messages, according to security researchers.
  • +

    Gmail, Yahoo Mail join Hotmail; passwords exposed 07/10/2009 04:25:00

    BBC reports Gmail, Yahoo Mail, AOL and others targeted by industry-wide attack
    Google's Gmail and Yahoo's Mail were also targeted by a large-scale phishing attack, perhaps the same one that harvested at least 10,000 passwords from Microsoft's Windows Live Hotmail, according to a report by the BBC.
  • +

    Phishing scam steals Twitter passwords 24/09/2009 08:30:00

    Twitter messages are leading victims to a fake log-in page
    Twitter users beware: this scam will not leave you ROFL.
Features
  • +

    Using Biometric Access Systems: Dos and Don'ts 18/03/2010 06:41:00

    For biometric access systems, the devil is in the details. Here are implementation strategies from users and analysts.
    Considering a biometric access system? Experts offer practical advice in these dos and don'ts.
  • +

    Social Engineering: The Fine Art of BS, Face to Face 08/06/2009 23:06:00

    A confrontation with a facilities manager demonstrates social engineers' complete comfort dealing with (and manipulating) conflict
    Chris Nickerson is willing to push it about as far as a person can go when it comes to security assessments. The founder of Lares, a security consultancy in Colorado, Nickerson conducts what he calls "Red Team Assessments" for clients. He is paid to try and dupe a client, and the client's employees, to give them a clear picture of the weak spots in their security plan. He then advises them on how to shore up defenses more effectively in the event a real criminal comes knocking.
  • +

    Security on a stick guards British diplomatic business 11/06/2009 06:05:00

    When it comes to security, the British government's Consulate-General in New York, part of the United Kingdom's diplomatic mission for business and visa-related activities, is taking no chances on spies or other intruders sneaking onto its network.
  • +

    Study: Secret questions don't safeguard passwords 20/05/2009 02:03:00

    Spouses and friends can often guess the answers to questions used to reset e-mail passwords
    Even if your spouse doesn't know your e-mail password, he or she probably knows enough information to get it.
  • +

    Password Seeks Partner For Long-Term, Secure Relationship 05/05/2009 09:25:00

    Forrester looks beyond the password to key trends in strong authentication
    Passwords have been standing guard over our computer user accounts seemingly forever; for a long while, and for most purposes, they could go it alone.
  • +

    Biometrics: 3 Tips for Success 12/03/2009 11:35:00

    False positives and faulty readers are common criticism of biometric security systems. But with the right plan, can they be practical in your security portfolio?
    False positives and faulty readers are common criticism of biometric security systems. But with the right plan, can they be practical in your security portfolio?
  • +

    Cyber security threats grow in sophistication, subtlety 16/10/2008 09:26:00

    Researchers say malware, botnets, cyber warfare, threats to VoIP and mobile devices, and the "evolving cyber crime economy" are ever-more sophisticated threats
    The annual report from Georgia Tech Information Security Center identifies five evolving cyber security threats, and the news is not good.
  • +

    How secure is secure enough? 29/07/2008 07:44:00

    Are your information security plans too big, too small or just right? Here are five steps to help you decide.
    If there is a Holy Grail in the information security industry, it surely is the answer to the question, "How secure is secure enough?"
  • +

    Five effective ways to burglar-proof your laptop 05/06/2008 07:55:35

    Five easy - yet effective - strategies to protect your laptop and the valuable data stored in it
    Theft of laptops and other mobile devices is spiraling, and the consequences -- financial and other -- are getting increasingly dire.
  • +

    Five free pen-testing tools 28/05/2008 09:04:38

    The best things in life are ...
    Security assessment and deep testing don't require a big budget. Some of most effective security tools are free, and are commonly used by professional consultants, private industry and government security practitioners. Here are a few to start with.
  • +

    Five steps to successful and cost-effective penetration testing 28/05/2008 08:57:20

    Spending your time and money well
    Whether you hire outside consultants or do the testing yourself, here are some tips for making sure your time and money are well spent.
  • +

    The darker side of Webmail 29/04/2008 10:02:55

    Web-based e-mail may be exposing you to privacy and security problems you didn't expect
    Web-based e-mail is booming. Services such as Gmail, Yahoo Mail and Hotmail are convenient, accessible and, best of all, free. Many of us have come to rely on them without giving it a second thought.
  • +

    Casino insider tells (almost) all about security 10/03/2008 07:56:55

    Engineer built systems used by up to half the world’s casinos
    Jeff Jonas knows the Las Vegas gambling industry inside and out. As the founder and chief scientist of Systems Research & Development (SRD), Jonas helped build numerous casino systems before 2005 when his company was purchased by IBM.
  • +

    E-commerce in crisis: When SSL isn't safe 17/05/2006 12:24:59

    A secure connection between browser and back end underlies Internet commerce. But what if it's already compromised?
  • +

    Two-factor authentication: Hot technology for 2008 15/01/2008 12:12:09

    Where there’s a will, there’s a way
    We've known for a long time that requiring just a user name and password to get on the network or to access personal information on a Web site isn't the tightest security posture, but there weren't a lot of good alternatives, and there wasn't that much pressure to change.
Case Studies
  • +

    Uni fortifies Western Front with IDS 22/02/2008 20:11:00

    Nurtured NAC keeps malware out
    The University of Western Sydney (UWS) has today gone live with a managed Intrusion Detection System (IDS) for its 5000 users.
Interviews
  • +

    Head of PCI council sees security standard as solid 17/04/2008 10:40:46

    GM Bob Russo defends payment card rules but acknowledges that 'interpretation issues' remain
    The PCI Security Standards Council was established in the US by the major credit card companies in September 2006 as an independent organization to manage the Payment Card Industry Data Security Standard. In an interview, general manager Bob Russo talks about the council's efforts to administer the PCI standard amid continuing concerns about credit and debit card security. And he defends the standard, despite the recent data breaches at Hannaford Bros. and Okemo Mountain Resort.
  • +

    RSA CEO talks authentication 14/03/2006 08:44:20

    RSA Security late last year acquired privately held Cyota, which offers online security and anti-fraud services to help financial institutions protect consumer accounts. CEO Art Coviello recently sat down with Ellen Messmer to discuss the Cyota acquisition and RSA's views on the future of authentication. With its anti-fraud services for banks, Cyota is a very different type of business than RSA Security traditionally has been in with its SecurID products for two-factor authentication and the BSAFE encryption toolkits.
  • +

    Schneier: secure tokens won't stop phishing 15/03/2005 09:13:06

    Technology isn't going to protect e-commerce customers -- stronger government regulation is what will get the attention of online banks and merchants, forcing them to stop being casual about security, said Bruce Schneier, founder and chief technology officer of Counterpane Internet Security.
Opinions
  • +

    Hack a million systems - earn a job 16/07/2008 16:12:54

    The idea of employing an admitted botnet creator and carding software author might not be palatable for many, but not so for an 18-year old New Zealander.
    It has been a number of years since the fantasy that hackers will be offered a job by those who they hacked was even a potential reality, but there are reports that this might still be the case in New Zealand.
  • +

    Vendor group plans authentication protocol 07/01/2005 07:46:19

    Open source has encompassed all areas of software applications and services, so there was little doubt that authentication would, sooner or later, be part of this fast growing movement. OpenLDAP, the open source directory project, has been with us for quite some time. But there's a new movement to create an authentication protocol, to standardize how authentication data is exchanged.
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
 
Whitepaper

Making the move to Ethernet | A DECISION GUIDE

While enterprises today need higher bandwidth, there is increasing demand for solutions that can provide scalability, performance, simplicity and control at lower costs. Get the best of both worlds - read about Ethernet adoption today.

Sponsored Links