Welcome to the ViewPoint Security Blog

Informal ramblings and updates from the team at ViewPoint

Tuesday, March 13, 2007

Two Factor Authentication (Strong Authentication)

Or why does RSA/EMC have a monopoly on this stuff, anyway? Don't get me wrong - SecurID is a good product, with wide support and a large user base. However, it uses proprietary algorithms (we're big fans of open source), and is getting a bit tattered around the edges with age. I recently came across an interesting new approach from WikID Systems - WikID Strong Authentication. An open source commercial app, it is written from the ground up to be "Web 2.0" aware (hate marketing buzzwords) in that it is extensible with PAM, java, etc. Basically, the technology works like this. A secure token client on your local machine passes your PIN to the WikID server, using the server's public key for encryption. The server then returns a one time password to your client, which is then used to complete authentication. I've run some quick tests with the client, and it looks promising. Test it for yourself here, or they also offer an evaluation. We'll be doing some real world evaluation, and will follow up with a later post. BTW - ViewPoint is not affiliated with WikID Systems in any way - these are just my observations, and YMMV.

Microsoft's Antivirus Deletes User's Emails

According to postings on Microsoft's OneCare forum, erasures have been caused when the antivirus programm finds a virus in an email attachment. Instead of then quarantining that single email, users have reported that entire .pst or .dbx files have been deleted, along with other important emails.



read more | digg story

OpenID: Too many providers, not enough consumers

There have been a spate of announcements recently with a number of companies both large and small announcing that their products will ’support’ OpenID. Each of these announcements was met with a rousing standing ovation by the bloggers over at Techmeme. First Microsoft (with Hypercard), then AOL, Digg, Wordpress, SmugMug and many more.



read more | digg story

First post ;-)

Everybody's gotta have one, right? So I finally got off my ass and started a blog for ViewPoint Security. This will be an informal site where the ViewPoint guys will share observations and experience from the field, as well as our opinions. We'll also try to post relevant security bulletins and articles of interest to he community.

Hopefully it will be of use to our clients, associates, and anybody else who feels like stopping by.