Posts

Will the Cloud bring life back to Africa ?

New life has started to bloom across this drought-ridden continent.     These green shoots are the fruit of the last decade and a half of increasingly feverish activity.     Democracy and mining spring to mind, but what about retail?   What about banking?   And of course mobile – the great enabler ! Chinese colonization proceeds with alacrity while their Global counterparts dawdle.    But is Sino capital and labour what Africa really needs?   Yes – but only if there is no alternative.    The rest of the World, suffering from post 2008 crisis lethargy, is slowly starting to realize that Africa should form part of their longer term plans.   The UK chugs along barely in positive territory while Osborn pats himself on the back for having squeezed the life out of the UK which he now kicks down the road and calls it growth !    The Tea Party almost dragged the USA (and the World) to the brink of an economic moras...

Oscar, celebrity and crowd sourced litigation

This was the week that Oscar Pistorius went on trial by media.   Forget about the lawyers -  this was ‘crowd sourced’  litigation at its finest;   fed by a torrent of tweets,  Tumblr images,  TV clips and banks of cameras that overwhelmed the tiny South African courtroom.   Opinions,  some informed, but mostly not,  spewed forth on social media proffering words of support and damnation in equal volume.     The tragic story of the horrific death of a beautiful young woman in her prime, the horror of an overcrowded courtroom and the legal sparring  (and this just the bail hearing!)  reveals the extent of modern society’s  collective voyeurism and pornographic  fascination with courtroom - celebrity mash up.     Oscar was a global icon after stepping off the Olympic podium last August in London.  This tragedy of death and fall from grace is one which has captivated the world.   The harsh ex...

Live Ensure® launches latest product features into US Market

  Live Ensure ® the SAAS  multi-factor authentication solution has spent the last year and a half field trialing the mobile version of the product with a few select customers who have collectively made millions of authentications without a single breach or failure.  Feedback provided valuable input which allowed the product to be further refined and streamlined making the user experience even better while making the solution stronger.   Live Ensure ® is easily integrated into an existing log-in form including SSO solutions like Twitter and Facebook.   This means that sites which allow users to log in e.g. with Twitter can now include a strong authentication layer thereby thwarting ID theft hacks which have become ubiquitous.   Examples are too numerous to mention but the weakness of password log-ins to emails ( Bush Hack )  and social media products (Twitter and Facebook) and their consequent failure are well documented. ...

FIDO, the password and Live Ensure®

Image
FIDO or Fast Identity Online was launched last week by a couple of Internet big hitters most notably PayPal.   They clearly have a vested interest in ensuring that their transactions are secure.     FIDO aims to provide specifications or standards to the industry that embody  an approach to authentication which starts to move away from the ‘security by obscurity ‘  or user name/password paradigm prevalent today.   The main reason why the incidence of hacking is sky-rocketing.   [ Twitter Hacked ] FIDO aims to leverage hardware devices such as phones and tablets as well as fingerprint readers, webcams, TPM ( Trusted Platform Module)  chips and tokens into an open-standard whereby there will be inter-operability between different systems but which comply to the standard.   A client/server architecture in combination with some hardware fingerprint starts to approach a much more secure approach th...

Out with the Old and in with the New

I was asked today by a board member to respond to a question from a prospective investor who wanted to know how Live Ensure (our service) differed from two other – lets call them ….the more traditional solutions.  For the sake of this blog we will call them the Old and the New solutions.   Let me describe the Old Co solutions to you briefly.  They both embody technologies which are over a decade old ( think RSA ) such as tokens and servers ( both physical and virtual).  Their solutions rely on the user entering a PIN into a browser and thereby satisfying the ‘something you know ‘ part of strong authentication.   Here it is slightly edited. The biggest weakness of both Old Co solutions are the vulnerability to MITM and MITB attacks. Both require the user to enter a PIN ( something you know ) ie a second factor over and above the user name and password ( the single factor or weak authentication ). The user enters this PIN back into the browser which is...

Why most security fails and LiveEnsure® does not ?

Image
Mary Meeker informs us that there are now 1.1bn  Smartphones  (17% of all mobile phones) and these are driving Internet growth with a total of 2.4bn people now connected to the Internet. Mary Meeker Internet trends The universe for hackers just grows and grows.    One of the most lethal of these attacks is Zeus (ZITMO) – which is aimed squarely at Smartphones. The Zeus attack is an example of several attacks now being launched that are based wholly on anticipated behavior, especially as it relates to social media, single-sign-on and BYOD. A sophisticated Zeus campaign stole an estimated €36 million, or $47 million, from over 30,000 customers across more than 30 banks in Europe this summer. The Eurograbber campaign, as it has been named, used custom versions of Zeus and Zeus in the mobile (ZITMO) Trojans to bypass the two-factor authentication measures to compromise customer bank accounts, Darrell Burkey, director of IPS products at Check Point Software Te...

Systems Integrators in a SAAS world

Picture the scene.   You are a SAAS provider.  Your products works for SME’s as well as large corporates.   You know you will need to sell through the channel to get to the larger enterprises.   You engage with the ones who have the best profile for your offering.    You have a great first round – they love your stuff – they say “ we want to sell your service .”    But first…………. we have a few questions.   Now you roll back the clock.   Sigh.   You are in a time warp as you read the questions :  • Where is [ product/service  name]  hosted ?  • Please give us Network, Application and Security Architecture diagrams • What is the models for enterprise clients to sign up?.  • What toolkits are available?  • How will we be able to assist our clients with implementation ?  • How do we monitor and support our clients ?  • Is your product IP protected? • Please provide reference...