Posts

Showing posts with the label obscurity

Out with the Old and in with the New

I was asked today by a board member to respond to a question from a prospective investor who wanted to know how Live Ensure (our service) differed from two other – lets call them ….the more traditional solutions.  For the sake of this blog we will call them the Old and the New solutions.   Let me describe the Old Co solutions to you briefly.  They both embody technologies which are over a decade old ( think RSA ) such as tokens and servers ( both physical and virtual).  Their solutions rely on the user entering a PIN into a browser and thereby satisfying the ‘something you know ‘ part of strong authentication.   Here it is slightly edited. The biggest weakness of both Old Co solutions are the vulnerability to MITM and MITB attacks. Both require the user to enter a PIN ( something you know ) ie a second factor over and above the user name and password ( the single factor or weak authentication ). The user enters this PIN back into the browser which is...

WHAT IS SECURITY BY OBSCURITY AND WHY HAS RSA STUMBLED?

The breach at RSA just goes to show that security by obscurity never works. And you are probably wondering just what is ‘security by obscurity’ ? Lets use a simple metaphor that is familiar to us all to help explain the concept. We have all at one time or another left a spare key under the doormat, just in case we are locked out of the house, or we leave it for someone else to use to get in.   Well,  simply put, that is - security through obscurity. The theoretical security vulnerability is that anybody could break into the house by unlocking the door using the spare key from under the mat.    Add to that scenario the reality that any burglar worth his salt will check out the most obvious hiding places, and so we, the house owner, run a  greater risk of a burglary by hiding the key in this way, since the effort of finding the key is likely to be less effort to the burglar than breaking in by another means. We have in effect added a vulnerability  (...