Identity Management Systems, Logical and Physical Access, Convergence

Report: Problems with some two-factor authentication

Thursday, April 22, 2010

Most agree that using two-factor authentication for access to secure networks is better than simple user names and passwords, but a report from Gartner Research states that hackers have found ways to compromise these more advanced systems as well.

Trojan-based, man-in-the-browser attacks have found vulnerabilities to one-time password tokens and could also be used against biometric and smart card technology, says Avivah Litan, vice president and analyst at Gartner Research. A layered security approach can help protect individuals from these kinds of attacks.

There are 559 words in the rest of this article …

Library Access Required

Library subscribers have access to the full archives of more than 10,000 original news items and feature articles published by AVISIAN’s suite of ID technology publications (ContactlessNews.com, CR80News.com, DigitalIDNews.com, FIPS201.com, NFCNews.com, RFIDNews.org, SecureIDNews.com, and ThirdFactor.com).

For just $49, you receive unlimited password-protected access to content on all of AVISIAN’s sites for an entire year. Your subscription helps fund the continued creation of independent, insightful content. Find out more.

Sign in as a Subscriber

If you are already a subscriber, you may sign in now. Enter your Email Address and Password and click Sign In.

Email Address →
Password →
Action →

If you have forgotten your password, enter just your Email Address, and click Send Password.

Email Address →
Action →

Banca Monte Paschi Belgio, the Belgian branch of this banking group, has opted to implement Oberthur Technologies’ end-to-end smart authentication product.

Certified by MasterCard, the solution includes smart display cards, an authentication server and an access control server that will secure e-commerce services and provide a unique and innovative payment solution to Banca Monte Paschi Belgio customers.

read more »

With the implementation of its authentication security suite at Goldsworth Primary School, online identity protection provider Yubico has shown that its two-factor authentication and VPN connectivity are a viable solution in the education market.

read more »

Online identity protection provider Yubico and cloud server security provider CloudPassage have teamed up to provide authentication services for administrative network access in the cloud.

read more »

Gartner Group’s 2012 Magic Quadrant for unique and innovative user authentication products features Equifax’s multifactor authentication product Anakam TFA Two Factor Authentication.

Gartner predicts that by 2017 more than 50% of enterprises will use cloud-based authentication services like Anakam, up from 10% today.

read more »

ValidSoft partnered with Opus Research and released a report titled “Voice Biometrics Authentication Best Practices: Overcoming Obstacles to Adoption” that predicts the technology will be deployed in payment authentication assuming the best practices it lays out are followed.

read more »

SAPO, Portugal’s largest Internet Service Provider and Web portal, has selected Yubico’s YubiKey two-factor authentication hardware to ensure login security for its employees and end users.

read more »