Viewing posts from March, 2011
Adding two-factor authentication to (web) applications
Posted by: admin 13 years, 8 months ago
This blog post has been in the offing ever since I read "Why is it so difficult to add two-factor authentication to online applications?" a couple of months ago. First, this should not be an issue. Most CMS systems and application frameworks support HTTP authentication and adding two-factor authentication to Apache for example) is quite simple.
The Baby and the Bathwater, SSL cert edition
Posted by: admin 13 years, 8 months ago
Background: Comodo, the SSL certificate authority was attacked and fraudulent certificates for a number of high-value sites were issued. Sites like mail.google.com, login.skype.com etc. as well as addons.mozilla.org.
My not-about RSA blog post
Posted by: admin 13 years, 8 months ago
There is a lot of speculation about the RSA SecuID attack. (Those are my top 3). The lack of information, while frustrating is understandable if there is an ongoing investigation and if the security of SecurID users is not truly at risk as RSA asserts. In general, I don't pay much attention to competition. I prefer to pay attention to customers, in particular prospective customers.
APT, open source and asymmetric encryption
Posted by: admin 13 years, 8 months ago
RSA just announced that they have been hacked:
Open forum for questions
Posted by: admin 13 years, 8 months ago
Ask any question you like. Typically, we would want this to go into the forums, but we want to test out the new Disqus commenting system.
Recent Posts
- Blast-RADIUS attack
- The latest WiKID version includes an SBOM
- WiKID 6 is released!
- Log4j CVE-2021-44228
- Questions about 2FA for AD admins
Archive
2024
2022
- December (1)
2021
2019
2018
2017
2016
2015
2014
- December (2)
- November (3)
- October (3)
- September (5)
- August (4)
- July (5)
- June (5)
- May (2)
- April (2)
- March (2)
- February (3)
- January (1)
2013
2012
- December (1)
- November (1)
- October (5)
- September (1)
- August (1)
- June (2)
- May (2)
- April (1)
- March (2)
- February (3)
- January (1)
2011
2010
- December (2)
- November (3)
- October (3)
- September (4)
- August (1)
- July (1)
- June (3)
- May (3)
- April (1)
- March (1)
- February (6)
- January (3)
2009
- December (4)
- November (1)
- October (3)
- September (3)
- August (2)
- July (5)
- June (6)
- May (8)
- April (7)
- March (6)
- February (4)
- January (427)
2008
- December (1)
Categories
- PCI-DSS (2)
- Two-factor authentication (3)
Tags
- wireless-cellular-mobile-devices (7)
- Two-factor authentication (10)
- Wireless, cellular, mobile devices (6)
- NPS (1)
- Phishing and Fraud (111)
- Active Directory (1)
- pam-radius (3)
- privileged access (2)
- Cloud Security (10)
- Mutual Authentication (60)
- Web Application Authentication (1)
- Authentication Attacks (99)
- pci (50)
- Security and Economics (97)
- WiKID (133)
- pam (2)
- VPN (1)
- Installation (2)
- RADIUS Server (1)
- Open Source (64)
- Tutorial (2)
- Strong Authentication (35)
- Information Security (137)
- Transaction Authentication (13)
- Miscellaneous (100)
- Linux (2)
- transaction-authentication (6)
- Two Factor Authentication (254)