<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Two Factor Authentication</title><link>http://msmvps.com/blogs/russel/archive/2007/07/27/two-factor-authentication.aspx</link><description>I spent last night installing the latest version of AuthAnvil and RWW-Guard on our network. Between the two, we now have a far more secure environment that enforces Two Factor Authentication (TFA) for access to critical accounts and resources. Normal</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Two Factor Authentication</title><link>http://msmvps.com/blogs/russel/archive/2007/07/27/two-factor-authentication.aspx#1110519</link><pubDate>Tue, 14 Aug 2007 05:53:21 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1110519</guid><dc:creator>Matt</dc:creator><description>&lt;p&gt;Agree with xperts64 about MTTM. Not relevant and not realistic to most (if any) corporate remote sites.&lt;/p&gt;
&lt;p&gt;Another great Strong 2 Factor solution is CAT (Cellular Authentication Token)™. &amp;nbsp;The Token is a java application installed on the users cell phone. &amp;nbsp;The user enters a pin number and access the OTP on the cell phone. &amp;nbsp;Multiple Tokens can be installed on the one cellular device. &amp;nbsp;Very simple to use and real convenient. &amp;nbsp;A device the user always virtually always carries with them.&lt;/p&gt;
&lt;p&gt;Once a hard token user has experienced CAT they would only reluctantly go back to the old hard token.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1110519" width="1" height="1"&gt;</description></item><item><title>re: Two Factor Authentication</title><link>http://msmvps.com/blogs/russel/archive/2007/07/27/two-factor-authentication.aspx#1085630</link><pubDate>Sat, 04 Aug 2007 23:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1085630</guid><dc:creator>Charlie Russel</dc:creator><description>&lt;p&gt;While a theoretical Man in the Middle (MITM) attack is possible, it requires a phishing site that a user would be willing to use and that used the same OTP mechanism. Not relevant or realistic to most (if any) corporate remote sites. Definitely something to think about with a commercial site, where it would need to be combined with additional layers of protection. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1085630" width="1" height="1"&gt;</description></item><item><title>re: Two Factor Authentication</title><link>http://msmvps.com/blogs/russel/archive/2007/07/27/two-factor-authentication.aspx#1070429</link><pubDate>Sun, 29 Jul 2007 16:18:34 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1070429</guid><dc:creator>mitmwatcher</dc:creator><description>&lt;p&gt;I was wondering You might of heard of a Active MITM attack which will lame all these OTPs..It is no great Rocket Science to automate this attack as kits are found in underground &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1070429" width="1" height="1"&gt;</description></item><item><title>Charlie Russel on AuthAnvil </title><link>http://msmvps.com/blogs/russel/archive/2007/07/27/two-factor-authentication.aspx#1063514</link><pubDate>Sat, 28 Jul 2007 03:50:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1063514</guid><dc:creator>Scorpion Software Corporate Weblog</dc:creator><description>&lt;p&gt;If you follow the world of 64bit computing, you know Charlie Russel. He is a popular author of many computer books (I think there are like 40 you can buy up on Amazon) and is well regarded in his circle of influence. I find myself a fan of much of his&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1063514" width="1" height="1"&gt;</description></item><item><title>The Gummi Bear defense</title><link>http://msmvps.com/blogs/russel/archive/2007/07/27/two-factor-authentication.aspx#1062112</link><pubDate>Fri, 27 Jul 2007 19:25:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1062112</guid><dc:creator>E-Bitz - SBS MVP the Official Blog of the SBS "Diva"</dc:creator><description>&lt;p&gt;I still remember the stories by Steve Riley about the deployment issues with Biometrics. Everyone sees&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1062112" width="1" height="1"&gt;</description></item></channel></rss>