|
2008/11/14
Document ActionsThe Express Scripts BountyNow this could be interesting. Express Scripts is offering $1,000,000 reward for information leading to the arrest and conviction of the attacker trying to blackmail them. That is a lot of Ameros. If this works, then we can expect to see a lot more of it. If it doesn't then perhaps we will see a lot more blackmail?
2008/11/12
Citrix on the need for two-factor authenticationSpecifically, two-factor authentication for Citrix Web Interface. The article doesn't say if Web Interface supports radius, but a quick google search seems to indicate it does. This configuration seems exactly the same as setting up WiKID and Citrix Access Gateway.
2008/11/11
PCI expanding to EuropeAccording to Security Fix Visa is going to enforce PCI DSS in Europe: Visa Inc. on Monday dramatically expanded its credit and debit card security requirements to retailers in Europe, an unexpected move that could be a financial boon to security auditing companies, but a huge cost for European merchants already feeling the pinch from the global financial crisis.I'm fascinated that this is a surprise. My reaction was, "hmm I would have thought the PCI already applied in Europe".
2008/11/06
Embedding WiKID two-factor authentication in your Web applicationOne of our customers, Online Banking Solutions offers banks and financial institution software for commercial account management. They have embedded WiKID for two-factor and mutual https authentication in both the server side and on their optional client. The combined client facilitates the initial validation process, performs session authentication using the one-time passcode and performs mutual https authentication to prevent MITM attacks. The product is a single-sign on solution that aggregates access to the numerous applications a single corporate banker might use:
And here's a screen shot of the combined client showing the OTP:
OBS uses the Java network client that comes with the server. We also have network clients for C#, PHP, Ruby and Python 2008/10/30
50 Must-Have Open Source Tools for SecurityThe WiKID Strong Authentication System - Community Edition is #38 in the 50 Must-Have Open Source Tools for Security.
2008/10/29
Kaspersky Labs update on bank attacksHat tip: Securology. Kaspersky Labs has an updated analysis of banking attacks. You should read the whole thing, but I'll point out this section of the conclusion: While I assume they are talking about a hardware token, this is essentially what WiKID can do using two separate domains. Each domain has its own public/private key pair and thus are cryptographically distinct so the session authentication is completely separate from the transaction authentication. And there's no reason why we can't use the public keys to encrypt data that an attack can't guess a la Kaspersky's suggestion of the account number into which the funds are to be transferred. |
|
|||||||||||||||||||||||||||||||||||||||||||||||||
