Posts

Showing posts with the label one time password

FIDO, the password and Live Ensure®

Image
FIDO or Fast Identity Online was launched last week by a couple of Internet big hitters most notably PayPal.   They clearly have a vested interest in ensuring that their transactions are secure.     FIDO aims to provide specifications or standards to the industry that embody  an approach to authentication which starts to move away from the ‘security by obscurity ‘  or user name/password paradigm prevalent today.   The main reason why the incidence of hacking is sky-rocketing.   [ Twitter Hacked ] FIDO aims to leverage hardware devices such as phones and tablets as well as fingerprint readers, webcams, TPM ( Trusted Platform Module)  chips and tokens into an open-standard whereby there will be inter-operability between different systems but which comply to the standard.   A client/server architecture in combination with some hardware fingerprint starts to approach a much more secure approach th...

Why most security fails and LiveEnsure® does not ?

Image
Mary Meeker informs us that there are now 1.1bn  Smartphones  (17% of all mobile phones) and these are driving Internet growth with a total of 2.4bn people now connected to the Internet. Mary Meeker Internet trends The universe for hackers just grows and grows.    One of the most lethal of these attacks is Zeus (ZITMO) – which is aimed squarely at Smartphones. The Zeus attack is an example of several attacks now being launched that are based wholly on anticipated behavior, especially as it relates to social media, single-sign-on and BYOD. A sophisticated Zeus campaign stole an estimated €36 million, or $47 million, from over 30,000 customers across more than 30 banks in Europe this summer. The Eurograbber campaign, as it has been named, used custom versions of Zeus and Zeus in the mobile (ZITMO) Trojans to bypass the two-factor authentication measures to compromise customer bank accounts, Darrell Burkey, director of IPS products at Check Point Software Te...

SITES DONT GIVE A DAMN ABOUT YOUR SECURITY

The sheer volume of reportage on hacking is overwhelming.   The sites being hit are the ones that you and I use every day.   Some provide useful information, some, valuable services and others perhaps just news or trivia.   We use them multiple times a day – sometimes without even being fully aware that we are,  like DropBox.   We use these sites  to store personal and business information, to connect us with potential clients, employers and employees, to help us choose insurance providers, to send us our groceries and some, to just play on.   Dropbox allows us to seamlessly log in by re-referencing a cookie they have planted on our computer to ‘verify’ our identity.   LinkedIn also uses the same technique when we log in.    A user name and password.  How secure is that ?    Well,  not very,  given that both of these sites have been hacked and your and my perso...

DROPBOX HACK – WHY YOU SHOULD CARE ?

DropBox is flying as a company.  More and more of us are entrusting our data to their servers in the Cloud.    I am one of those.  The service is great, it works and it works from multiple devices.  However there is just one thing.  It is not secure.  Read about their latest breach here. ( http://www.zdnet.com/dropbox-gets-hacked-again-7000001928/ )  and also here ( http://gigaom.com/cloud/dropbox-yes-we-were-hacked/ ) I have been going on about passwords and their manifest weakness for months here and in other media.   DropBox have come back to their customers saying that they promise to do more – better passwords – better security …..blah blah blah. So what kind of solution should they use? Well first of all they have millions of customers.  So whatever they go for is going to have to be easy to deploy and should not require the distribution of some kind of hard token OTP generator a la all of...

The End of Passwords

Finally it seems … the penny has dropped.   Passwords are a poor substitute for real online security.   There is more and more ‘chatter’ about it.    Robin Henry writing in the Sunday Times on New Years Day talks of the end of ‘password hell’ invoking solutions in the pipeline from the Web Gods – Apple and Google.  The talk is of new biometric solutions such as facial and hand movement recognition.  Even IBM is talking this way.  ( http://www.forbes.com/sites/thestreet/2011/12/20/ibms-tech-predictions-for-the-next-5-years/ )  I agree with the notion that passwords are a dying breed but not that biometrics will become vogue.   They are fraught with problems of their own such as reliability, accuracy and the need for referencing of data-bases ( fail !) .    Why are passwords defunct?   Basically they are difficult to remember and they are easy to steal.    The solutions needed are those that require no cognitive l...

You need authentication

I am constantly amazed at the lassez faire attitude that the majority of businesses, large and small, have about their online security.  Those that require their users / members to log on will provide a user name and password log in to verify their identity – and that’s it.  I suppose that if the large players like Amazon and iTunes can get away with it then the smaller guys think that’s all they need to. The reality is that if the big boys get a hit – they have the firepower to deal with it.  But SME’s just need one bad hack and they are out of business.    2011 is going down as the year of the ‘Hack’ (  http://www.infosecurity-magazine.com/view/22481/year-of-the-hack-/?utm_source=twitterfeed&utm_medium=twitter)  with many high profile victims like SONY, RSA and Epsilon losing millions of their users personal information.    Despite this there seems to be the attitude that ‘ it cant happen to me’ .  ...

Authentication in ' context'

con·text /ˈkƤntekst/ The circumstances that form the setting for an event, statement, or idea, and in terms of which it can be fully understood and assessed. authenticate [É”ĖĖˆĪøÉ›ntɪˌkeÉŖt] vb (tr)   to establish as genuine or valid What does context have to do with authentication? When you log on to a web site and enter your user name and password so as to ‘authenticate’ yourself all you are presenting are self reported credentials to the site.  If you present the correct credentials then the site accepts you as - who you say you are.   It takes you at face value.  It identifies you.  Liken it to a knight of old arriving at castle and announcing himself.   When you log on to a web site and it asks you to log in with a user name and password – you are in effect – announcing yourself – identifying yourself.   What happens if someone steals your password?   Then they can log on as you – the site is none the wiser – the thief has presente...

HSBC EMBRACES OLD TECHNOLOGY IN ITS BATTLE AGAINST HACKERS

 If you live in the UK and are somehow involved in the business world and exposed to media you could not help but have noticed the extensive advertising campaign that HSBC has been running on its new (sic) ‘security device’ for online banking - Secure Key.    ( I was tempted to refer to them as  ‘ large UK bank’  - but it is so obvious who it is – no point in pretending. ) A lot of money has been thrown at this campaign – I would guess millions.  ( http://www.youtube.com/watch?v=Jx0Z5CiQMIw )   Full page spreads in large circulation newspapers cost big bucks not to mention prime time TV slots.   So here you have the worlds largest retail bank splashing millions on advertising and even more on a ‘cool’ little device that looks like a mini-calculator  - but basically a technology that has been around for about a decade.   This will be rolled out to 4m retail customers worldwide at a reported cost of up to £50 per pop!...

ANONYMOUS / LULZSEC /ANTI-SEC ARE DOING MORE GOOD THAN HARM !

I know,   I know – I hear the howls of protest even before finishing this first sentence.   “What about all the innocent lives exposed by the irresponsible publication of peoples names in positions of authority or in sensitive roles. ?”    But where does the fault lie ?  With those doing the breaking and entering?   Or those not providing adequate protection??  It is liked leaving your house locked without an alarm system, going on holiday, and coming back and finding it broken into.   Don’t be surprised.  You have no one to blame but yourself.  “ But these are criminals ! “  – I hear the sounds of self righteous chest thumping.    Maybe, but what they have done – I hope – is scare the s**t out of anyone who has anything (data) that is accessible via the Web  - and into ensuring that their ‘security’ ( if any ) - is rapidly upgraded.    This ranges from personal users who ...

ONLINE BANKING STAYS IN THE DARK AGE

 A large ( big 4 )  UK bank recently sent its corporate customers a letter advising them of their  ‘new’ security solution.   Here is an extract from the letter : " Online banking fraud and identity theft is increasing across the UK - in 2009 fraud across all UK banks exceeded £59m.  Fraudsters are becoming ever more sophisticated in their efforts to obtain personal information and gain access to accounts.  We're committed to keeping your Internet Banking service safe, so we're introducing a more secure way to bank online using a card reader.  A card reader is a small handheld device which you will need every time you bank online.  We'll send one to every registered user within your business.   " Talk about being underwhelmed.  If I was a customer I would be seriously unhappy.   But most  customers probably will not.  That is because they (probably)  don’t realize that :  1)    THEY are g...

What the Analyst said ....Why LiveEnsure and SiteKey/SitePass are not the same.

  So there I was on the phone to an Analyst today explaining (at a fairly high level )   some of the basic features of LiveEnsure TM   when he says – “   ahh – I get it – this is identical to Bank of America’s SiteKey/Site Pass system .”    Not having the details of said banks system at my fingertips – I was unable to correct the Analyst on his incorrect conclusion with any hard science.    We were also running out of time,   it was a bad line and…all I could say was – it is not the same – there is much,   much more going on under the hood with LiveEnsure TM .     So why is BofA’s SiteKey TM / Site Pass TM authentication system NOT identical to LiveEnsure TM   ? ·                 Device ID.    Although both ostensibly have a ‘hardware device recognition’ component – the BofA solution relies upon the re-referencing of a cookie (dow...

One swallow does not a summer make

Experts from Gartner have said that the recent 'froth' of M&A activity in the security space does not constitute a 'trend'.   While 'one swallow does not a summer make'  I would contend that this is in fact a trend and that it set to hold for at least another year.   Why? Well first of all the 'froth' was in fact more like a large set of Atlantic rollers breaking on the Cape coast!!!  Consider the number of deals that have taken place in the last 6 months ( see previous blog) crowned by the recent announcement by HP of its acquisition of Arcsight for $1.5bn. "   Hewlett-Packard  has agreed to buy high-end technology security company ArcSight for $1.5bn to profit from its customers’ increasing concerns about  protecting their data from hackers . The cash offer of $43.50 a share for Silicon Valley neighbour ArcSight was more than 50 per cent above where the company was trading before reports last month that it was courting buyers. It value...

SECURITY M&A GONE A BIT CRAZY ....

The tech sector and in particular the security sector within  has been extremely active during the past 6 months.  There have been numerous acquisitions that indicate an increased appetite for quality security assets.    Perhaps the most high profile of these was the recent acquisition of MacAfee by Inte l ( a $7.8bn transaction ) representing a premium of over 50% to the then prevailing market price.  A PE multiple of about 48 and 3.8 x Revenue. This was Intel’s largest ever acquisition. Symantec acquired Verisign’s Authentication business for $1.28bn - approximately 4 x revenues. (Second quarter revenues from this Unit was about $100m )  ( May ) ; CA has announced it will acquire Arcot systems for $200m in Q4 2010.  Arcot provides Identity Access Management and Authentication products  ( www.ca.com/www.arcot.com ) ;  VMWare has announced it will acquire Integrien and TriCipher .  (Sep)  HP has just announced it will acquire ...

SMB/E's underestimate the cost of cyber security breaches

I found this article at www.smallbusinesscomputing.com and I am repeating it here verbatim because I believe that it captures the essence of the challenges that lie ahead and the need for education and the provision of simple but effective authentication solutions.  What SMBs Don't Know About Security Can Hurt You April 23, 2010 Small and midsized businesses might be the lifeblood of the U.S. economy, but according to the latest Internet security survey from Panda Security, their generally lackadaisical efforts to protect consumer data is also making them a prime target for cyber thieves. More disturbing, particularly for customers swiping their credit cards or purchasing products and services online, the survey reveals that the vast majority of SMBs claim they don't know how to effectively prevent identity theft, lack the resources to install the technology that could thwart the majority of cyber attacks and, worse, seem to believe that it's really not their probl...

MOBILE INTERNET CYCLE DRIVING PRIVACY SECURITY SOLUTIONS

With over two billon Internet users and five billon mobile phone users these global networks bring people ever closer together. These technologies which include broadband (terrestrial) and 3G (wireless) allow for more and more data to be carried. We have entered the next Tech Cycle which is called the Mobile Internet. It was preceded by four tech cycles starting in the 1960’s with the Mainframe cycle. Approximately every decade thereafter we have had a new cycle; Mini-computers - 70’s; PC’s - 80’s and desktop Internet - 90’s. The Mobile Internet cycle triggered by the launch of the iPhone will see mobile internet access overtake fixed access by 2014. This will be driven by smart phone take up and 3G/4G rollout. We are already at the critical point of over 1bn 3G users. Other drivers are video ( YouTube); Social networking (Facebook) and VOIP. Much of this take up is occurring in emerging markets; there are 5 babies born every second - but there are 30 new mobile ph...

PERSONAL INFORMATION - ONLINE CODE OF PRACTICE

If you found my previous post somewhat disconcerting then have a look at this link which is the UK Information Commissioners Guide to the new legislation. " The code explains how the Data Protection Act applies to the collection and use of personal data online. It also provides good practice advice for organisations that do business online and are therefore subject to the DPA. " http://www.ico.gov.uk/ebook/ebook.htm and if you want more in depth information about the legislation itself then have a look at this video from Stewart Room. It makes it somewhat more accessible.

YOUR PRIVACY IN A VERY PUBLIC AND CONNECTED WORLD

So how do you value your privacy in the Facebook age ? Does it matter to you that the calls you make, the emails you send, your credit card transactions, the Internet sites you visit, the images of you travelling to work, your social networking posts are now stored at data centres in the Cloud and retrievable by myriad marketers, Government agencies and companies ? None of whom you ever entrusted with your information in the first place. Your digital footprint is a permanent record of your every move. Data is the pollution of the Information age. Everything we do generates data, and a secondary spin-off of Moores law is that every year it gets cheaper to store and process this data. So rather than sort through our e-mails and delete the ones we don’t need – we just keep them all – it is easier and cheaper to do so. The same thing happens with all of our data now. Most of ‘your’ data actually belongs to someone else. All of your G-mails, everything you ...