RSA warned its customers yesterday that its network had been breached and data had been stolen that could affect customers using its popular SecurID token authentication technology. Although details are scarce, here's what we know so far.. What happened? Someone launched an "extremely sophisticated cyberattack" on RSA in the form of an Advanced Persistent Threat and data was stolen related to the SecurID technology, the company said in a statement on its Web site. APT attacks are often used for espionage, targeting source code and other information within a company or government agency. They typically involve knowledge of a target's network, key employees, and operations, and can use multiple techniques to get insider information such as social engineering and exploits of unpatched holes in software. APT attacks against Google and other companies that were revealed last year used an exploit for a vulnerability in Internet Explorer that could have been delivered to insiders via e-mail. RSA has declined to provide more details on the incident at this time. What is SecurID? SecurID is a two-factor authentication system that organizations use to provide more protection for sensitive data and networks than just a password. With two-factor systems, someone accessing a network needs to provide something they know, which is a password or PIN, and something they have, which can be a thumbdrive-size hardware token or keyfob, or software on a mobile device. The token provides a one-time eight-digit number a user types in along with the password so that the system can verify that the person is authorized to access the network. A different number is used every time the user logs in. The link for this article located at CNET is no longer available. . Explore the intricate cyber assault on RSA that jeopardized its SecurID authentication system.. RSA Breach, Cyberattack Overview, SecurID Implications. . LinuxSecurity.com Team
DERMALOG FingerLogin includes keyboard with fingerprint scanner, which utilizes high-performance optics and Live Finger Detection and can be connected via USB interface to PC or thin client. Solution also includes biometric software that compares scan with fingerprint database and password administration. Integrating in networks of public authorities, companies, and other organizations, such as hospitals or banks, product allows only owner of registered finger to retrieve authorized data. . Passwords may soon be a thing of the past. Today some laptops already provide the option to log in by fingerprint. Now this technology becomes available for the professional use in large networks. The biometrics specialist DERMALOG presents a new solution at CeBIT 2011, to make logging into networks of a company, bank, hospital or government much easier and much more secure - the DERMALOG FingerLogin, a keyboard with integrated fingerprint scanner, together with the appropriate biometrics software for IT networks. The new technology is already coming into use at the University Hospital Hamburg-Eppendorf (UKE) for more than 3.900 computers of the hospital. The link for this article located at ThomasNet News is no longer available. . Uncover the way DERMALOG FaceID transforms security access using facial recognition technology for protected systems.. DERMALOG FingerLogin, Fingerprint Technology, Biometric Solutions, Network Access Security, Data Protection Solutions. . LinuxSecurity.com Team
Authentication developers are preparing new systems that offer enhanced data security but reduce the burden strict access controls traditionally place on users. . . .. Authentication developers are preparing new systems that offer enhanced data security but reduce the burden strict access controls traditionally place on users. At the Inside ID Conference & Expo in Washington this week, RSA Security Inc. will unveil an SSO (single-sign-on) system for enterprises that is designed to eliminate the hassle of myriad passwords. Called Sign-On Manager, the system combines RSA's strong SecureID authentication with SSO technology to improve security, increase productivity and reduce calls to the help desk resulting from forgotten passwords, according to officials. The link for this article located at EWeek.com is no longer available. . Access control engineers enhance frameworks to improve data integrity and ease management tasks. Learn further.. Single Sign-On, Authentication System, User Productivity, Data Security, Password Management. . Anthony Pell
The Rekonix LTD company have introduced today a new version of their popular strong authentication system STADRIN 1.1.5 targeting the Linux platform using PAM authentication schemes with a Vasco tokens backend. The new version makes the implementation process more easy and . . . . The Rekonix LTD company have introduced today a new version of their popular strong authentication system STADRIN 1.1.5 targeting the Linux platform using PAM authentication schemes with a Vasco tokens backend. The new version makes the implementation process more easy and allows simple coexistence with current running authentication schemes for a simple switching to new one. STADRIN is being tested in VASCO laboratories. These test will assure, that the product matches all security requests and standards of VASCO company. After pass these tests the product will receive VASCO Ready status. The goal of the VASCO Ready Partner Program is to achieve optimal co-operation with integrators and vendors building products that integrate with Digipass and the Vacman product family. The link for this article located at stardin.com is no longer available. . The Rekonix LTD company have introduced today a new version of their popular strong authentication s. rekonix, company, introduced, today, version, their, popular, strong, authentication. . LinuxSecurity.com Team
Swindle, 65, is one of five commissioners at the Federal Trade Commission. The FTC's responsibilities involve policing the Internet for fraud and privacy violations; the agency recently compelled Microsoft to make changes to its Passport authentication system. . .. Swindle, 65, is one of five commissioners at the Federal Trade Commission. The FTC's responsibilities involve policing the Internet for fraud and privacy violations; the agency recently compelled Microsoft to make changes to its Passport authentication system . Swindle believes the private sector typically is better at resolving online problems than are government bureaucrats. It's not a new argument: When the FTC voted 3-2 in May 2000 to ask Congress for more power to regulate Web sites, Swindle was one of the two dissenters. Appointed to the FTC by then-President Clinton in December 1997, Swindle previously worked as an assistant secretary in the Commerce Department under President Reagan. He was a Marine aviator in Vietnam, and his plane was shot down in 1966. Swindle, who spent the next six years in a prisoner of war camp, won two Purple Hearts during his combat service. CNET News.com recently caught up with Swindle to get his views on Microsoft, Internet privacy and spam, among other subjects on his radar. . Swindle examines the FTC's involvement in tackling challenges related to internet privacy, guidelines for spam control, and how to maintain an equilibrium with private enterprises.. Internet Fraud, Privacy Policy, Online Safety, Spam Control, FTC Regulations. . LinuxSecurity.com Team
EnGarde is the next generation in Linux security providing a complete suite of e-business services, intrusion alert capabilities, improved authentication and access control utilizing strong cryptography, and complete SSL secure Web-based administration capabilities. Imagine a cohesive suite of Open Source applications . . . . EnGarde is the next generation in Linux security providing a complete suite of e-business services, intrusion alert capabilities, improved authentication and access control utilizing strong cryptography, and complete SSL secure Web-based administration capabilities. Imagine a cohesive suite of Open Source applications converging to provide the level of security required for corporate environments as well as security-conscious Internet users. Imagine the ability to manage and create secure Web sites, configure DNS, e-mail, SSL certificates, and other administrative tasks using a secure Web-based front-end. Now visualize the ability to create complete e-business storefronts. This suite of applications would then provide all the components necessary for an organization to securely conduct business on the Web, perform the function of a network intrusion detection system, and securely host Web sites. That is precisely what Guardian Digital has done with the creation of EnGarde, an easy-to-use, low maintenance, ultra high secure Linux server distribution. On March 30, 2001, at 00:01 EST, Guardian Digital, the Open Source security company, will unveil EnGarde Finestra, a stable and revolutionary release like none before it. The link for this article located at Guardian Digital, Inc. is no longer available. . Fortress provides cutting-edge Windows protection featuring tools for online commerce, encrypted management access, and breach notification systems.. EnGarde Secure Linux,E-business Solutions,Secure Web Management. . LinuxSecurity.com Team
Illinois has decided to standardize its electronic transaction authentication system, but questions remain about how it will work. The state's public-key infrastructure program, which uses digital certificates to authenticate users for electronic transactions, will be standardized on Entrust Technologies Inc.'s . . . . Illinois has decided to standardize its electronic transaction authentication system, but questions remain about how it will work. The state's public-key infrastructure program, which uses digital certificates to authenticate users for electronic transactions, will be standardized on Entrust Technologies Inc.'s system, said Brent Crossland, deputy technology officer for Illinois, speaking Monday at the Entrust SecureSummit 2001 conference in San Diego. The link for this article located at FCW is no longer available. . Illinois seeks to unify electronic transaction verification using Entrust's PKI system, prompting worries about deployment challenges.. Entrust Technologies, Electronic Transaction Authentication, Public Key Infrastructure, Cybersecurity. . LinuxSecurity.com Team
Secure Computing Corporation, from the RSA Conference 2000, today announced first customer availability of SafeWord, the leading scalable authentication solution in the industry, on the Linux operating system (OS). Traditionally, SafeWord running on the UNIX platform has a history of being . . . . Secure Computing Corporation, from the RSA Conference 2000, today announced first customer availability of SafeWord, the leading scalable authentication solution in the industry, on the Linux operating system (OS). Traditionally, SafeWord running on the UNIX platform has a history of being the highest performing, most robust and scalable authentication solution available. SafeWord v5.1.1 will bring those benefits to the Linux platform providing enterprise and service provider customers the safe secure environment needed for e-commerce and e-business. Secure Computing's SafeWord v5.1.1 positively identifies users connecting to Web and other applications. It provides a portable authentication (strong or medium) solution based on the organization's needs. By providing a username and password, either dynamic or fixed, generated by a SafeWord token, external users are granted access only to the specific resources designated by the organization's security policy. Once authorized, users can only access Web sites and applications as they are individually authorized and all activities are monitored for auditing purposes. SafeWord v5.1.1 interoperates with the widest range of firewalls, communication servers and virtual private network (VPN) servers via RADIUS and supports all major host/operating system platforms. It scales to millions of users and is built to be fault tolerant. The link for this article located at Secure Computing is no longer available. . GuardianTech unveils TrustPass for Unix, improving safe login processes for businesses and service institutions.. Authentication Solution, Secure Access, Linux Security, Enterprise Authentication. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.