Security Experts:

long dotted

NEWS & INDUSTRY UPDATES

An alliance of Internet giants, including PayPal and Lenovo, are tackling the identity problem head-on with a new authentication system designed to do away with passwords and improve online security.
After suffering a breach last week that impacted some 250,000 accounts, Twitter is looking to bolster security by investing in two-factor authentication.
Security researchers discovered a backdoored version of the SSH daemon on compromised servers used during recent rootkit attacks.
Cyber-Ark Software released its new SSH Proxy solution, an offering designed to secure, audit, and report on privileged SSH activity within UNIX environments.
Identropy has launched its SCUID Lifecycle identity and access management service with a focus on ease of deployment.
BeyondTrust announced that it has acquired Blackbird Group, a provider Windows system management software.
While attackers can break into networks using complex techniques, the reality is that most data breaches occur when attackers manage to get their hands on login credentials to administrator and other super-user accounts.
Accenture Federal Services has received a five-year contract with a ceiling of $250 million to create and manage a new identity management and credentialing system for the Transportation Security Administration (TSA).
RSA Distributed Credential Protection (DCP) provides a bump in protection by splitting secrets and authentication decisions across two servers.
Microsoft has acquired PhoneFactor, a provider of phone-based multi-factor authentication (MFA) technology.

FEATURES, INSIGHTS // Identity & Access

rss icon

Mark Hatton's picture
Despite the billions of dollars spent annually by government and private industry to protect their networks and critical data assets, the large majority of breaches can be tied directly to human error and/or a breakdown in protocol.
Chris Hinkley's picture
Without the internal and external safeguards working in conjunction, your vulnerability will spike and your performance will suffer as a by-product -- two things you can’t afford to have happen.
Tal Be'ery's picture
When it comes to setting the standards for crucial internet functionality such as authentication, the Internet community must remain vigilant and carefully examine and scrutinize change proposals, to ensure they support the greater good of all of the Internet users.
Mike Lennon's picture
Enjoy this selection of top picks for 2010, listed in no particular order. Happy New Year!
Tom Grubb's picture
The day after Twin Towers fell, all kinds of security measures changed and new ones were implemented overnight. Is there a Web identity 911 equivalent wake-up call coming—a single event that will suddenly jolt us into enforced standards overnight?
Ram Mohan's picture
Are your passwords safe? Three simple ways to create memorable yet secure passwords
Jimmy Sorrells's picture
The WikiLeaks exposure highlights a clear need for a change in the way many classified networks are architected and managed, the way organizations manage their most sensitive information, and should also be looked at as a red flag by enterprises.
Markus Jakobsson's picture
In 1998, Intel announced the introduction of processor identities. Anti-fraud practitioners celebrated, security experts busied themselves thinking of the research implications, and privacy advocates were terrified...