Online and Digital Identification, Securing Web 2.0, PKI and Digital Certificates

Report: Problems with some two-factor authentication

Thursday, April 22, 2010

Most agree that using two-factor authentication for access to secure networks is better than simple user names and passwords, but a report from Gartner Research states that hackers have found ways to compromise these more advanced systems as well.

Trojan-based, man-in-the-browser attacks have found vulnerabilities to one-time password tokens and could also be used against biometric and smart card technology, says Avivah Litan, vice president and analyst at Gartner Research. A layered security approach can help protect individuals from these kinds of attacks.

There are 559 words in the rest of this article …

Library Access Required

Library subscribers have access to the full archives of more than 10,000 original news items and feature articles published by AVISIAN’s suite of ID technology publications (ContactlessNews.com, CR80News.com, DigitalIDNews.com, FIPS201.com, NFCNews.com, RFIDNews.org, SecureIDNews.com, and ThirdFactor.com).

For just $49, you receive unlimited password-protected access to content on all of AVISIAN’s sites for an entire year. Your subscription helps fund the continued creation of independent, insightful content. Find out more.

Sign in as a Subscriber

If you are already a subscriber, you may sign in now. Enter your Email Address and Password and click Sign In.

Email Address →
Password →
Action →

If you have forgotten your password, enter just your Email Address, and click Send Password.

Email Address →
Action →

Global Industry Analysts Inc. released a report forecasting the outlook on the global smart card market to reach 10.9 billion units by 2015.

GIA credits the growth driven largely by major initiatives in the financial, government and security sectors, with the telecom sector at the way ahead of the pack as the largest end-user. Increasing usage of contactless technology, newer applications and mandatory EMV migration across countries are also major drivers boosting the global market for smart cards.

read more »

The Indian start-up ArrayShield Technologies has entered the two-factor authentication market in India and is looking for value-added resellers, managed service providers and system integrators to help it become a player in this field, which it estimates to be nearly Rs 2 billion.

read more »

ValidSoft partnered with Opus Research and released a report titled “Voice Biometrics Authentication Best Practices: Overcoming Obstacles to Adoption” that predicts the technology will be deployed in payment authentication assuming the best practices it lays out are followed.

read more »

NEC Corporation has developed a new cloud security service that implements advanced authentication capabilities from CA Technologies.

NEC combined the CA ArcotID software credential with its NC7000-3A ID utilization infrastructure and NEC Mobile Security security countermeasure product to offer authentication services in the cloud through identity links found on multiple NEC websites. The CA ArcotID product offers integrated two-factor authentication and can be used on smart phones and tablets.

read more »

Yubico and SSO Easy have partnered to create a simplified two-factor authentication for single sign-on (SSO).

Designed for users who must implement strong two-factor authentication for access to SAML-based SSO servers, critical applications and sensitive information, this solution utilizes Yubico’s YubiKey driverless USB-token to log in with a one-time password.

read more »

With the implementation of its authentication security suite at Goldsworth Primary School, online identity protection provider Yubico has shown that its two-factor authentication and VPN connectivity are a viable solution in the education market.

read more »