NewsThere are no actual news.What is Strong Authentication?Most security experts agree: Static passwords are not a safe way to protect vital systems. They prefer a "strong authentication" approach to system security. What is "Strong authentication"? Simply put, "Authentication" means verifying that people are who they say they are, before they are entrusted with access to your sensitive data. Strong Authentication means raising the ante on security, by preventing unauthorized users from simulating a legitimate user's identity. STADRIN with VASCO's Digipasss Family of products is specifically designed to deliver the exceptional authentication performance that your valuable electronic transactions require. In Applied Cryptography (2nd Edition, 1996) security expert Bruce Schneier writes: "The world's most secure algorithm will not help much it the users habitually choose their spouse's names for keys (passwords) or write their keys on little pieces of paper in their wallets." Cheswick & Bellovin comment in Firewalls and Internet (1994): "No security expert we know of regards passwords as a strong authentication mechanism. One can achieve a significant increase in security by using One-Time-Passwords. Traditionally organizations have used standards based access solutions such asRADIUS, the LAN and Web (HTTP) to not only provide access but to also handle authentication and authorization. The standards based RADIUS, LAN and Web solutions have provided reliable and cost effective access but have generally relied on static user-name and passwords for authentication. Static passwords offer a potential weakness at they can be trapped, guessed of forced to gain access to an otherwise secure network. Identity fraud is one of the biggest security issues facing organizations as they move more and more services over to electronic delivery. STADRIN with Digipass based token strategy eliminates the shortcomings of a "static password" approach, by delivering dynamic passwords trough a device that is highly portable; easy to integrate into any Linux environment; and inexpensive. In short, the Digipass solution provides "strong authentication" in a way that maximizes flexibility and minimizes the total cost of ownership. In Response-Only mode, the Digipass device delivers a dynamic password (OTP) upon request by the end-user. The following illustration highlights the Digipass 300 usage flow. Linux-PAMLinux-PAM (Pluggable Authentication Modules) is a suite of shared libraries written up into what are called modules. Each module has tis own tests, rules, and criteria that allow administrators to choose how applications either authenticate or reject users and/or programs. PurposeThe PAM software package STADRIN available form REKONix allows any Linux machine to become strong server for authentication requests. This provides an enhanced layer of protection against unauthorized access of valuable resources. |