<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tricerion Security Blog &#187; security</title>
	<atom:link href="http://blog.tricerion.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.tricerion.com</link>
	<description></description>
	<lastBuildDate>Tue, 17 Jan 2012 14:02:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Phishing is Phutile!</title>
		<link>http://blog.tricerion.com/2010/02/phishing-is-phutile/</link>
		<comments>http://blog.tricerion.com/2010/02/phishing-is-phutile/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 18:03:07 +0000</pubDate>
		<dc:creator>Kathy</dc:creator>
				<category><![CDATA[Cyberthieves]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[strong authentication]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=121</guid>
		<description><![CDATA[I was in a conversation this week with someone else in the online security space and I happened to mention that I think Tricerion&#8217;s Safe Login is pretty darn sweet. He was a proponent of a keyfob token that additionally used a USB chord and a card too. Yikes. That&#8217;s too complicated for me. In [...]]]></description>
			<content:encoded><![CDATA[<p>I was in a conversation this week with someone else in the online security space and I happened to mention that I think Tricerion&#8217;s Safe Login is pretty darn sweet. He was a proponent of a keyfob token that additionally used a USB chord and a card too. Yikes. That&#8217;s too complicated for me. In the course of our conversation he told me that Tricerion&#8217;s system is very user-friendly and elegant for enterprises, but&#8230; (so he said) it doesn&#8217;t protect against trojans or malware. WHAT?</p>
<p>Ahem. I&#8217;m here to clear up that awful myth that Tricerion strong mutual authentication is less secure than those irritating tokens. So here it is folks, the cold, hard facts.</p>
<p>Malware and trojans are all about stealing passwords. They steal them by capturing typed in passwords and login names. With Safe Login, passwords are never typed in &#8211; they&#8217;re entered on an on-screen keyboard using the mouse to select either alphanumeric characters or pictures that make up a password. To malware, it&#8217;s like grasping at air &#8211; there&#8217;s nothing for them to catch.</p>
<p>What makes Safe Login even more special is that it anticipates and protects against something that has never happened. See, virtually every (secure) login everywhere is protected by 128-bit encryption. No one has figured out how to crack it, but that doesn&#8217;t mean hackers aren&#8217;t trying. And if someone did crack it, the world would be their oyster. They&#8217;d have all logins and passwords in open text, able to hack just about anything, anywhere. Tricerion has this really elegant, intuitive system that separates data streams, so that if SSL 128-bit encryption were ever cracked, anyone using Tricerion&#8217;s system would be protected.</p>
<p><img class="alignnone dtse-img dtse-post-121" title="phishing is futile" src="http://www.safelogin.co.uk/images/trialogue.gif" alt="phishing is phutile" width="371" height="309" /></p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_121_permalink = 'http://blog.tricerion.com/2010/02/phishing-is-phutile/';
			dtsv.dtse_post_121_title = 'Phishing is Phutile!';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/02/phishing-is-phutile/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 reasons online banking is safer than paper</title>
		<link>http://blog.tricerion.com/2010/01/3-reasons-online-banking-is-safer-than-paper/</link>
		<comments>http://blog.tricerion.com/2010/01/3-reasons-online-banking-is-safer-than-paper/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 14:17:59 +0000</pubDate>
		<dc:creator>Kathy</dc:creator>
				<category><![CDATA[Banking]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Bank]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=102</guid>
		<description><![CDATA[We read stories about phishing and data breaches and we get worried. Some of us start thinking that maybe we&#8217;re better off (security-wise) with paper-based banking. Sending checks, receiving statements in the mail, paying bills the old fashioned way &#8211; manually with a checkbook and a stamp. But as Jean Chatzky said this morning on [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter dtse-img dtse-post-102" title="online banking more secure" src="http://www.chattahoocheebank.com/Portals/105/online%20banking.jpg" alt="" width="320" height="240" /></p>
<p style="text-align: left;">We read stories about phishing and data breaches and we get worried. Some of us start thinking that maybe we&#8217;re better off (security-wise) with paper-based banking. Sending checks, receiving statements in the mail, paying bills the old fashioned way &#8211; manually with a checkbook and a stamp. But as Jean Chatzky said this morning on NBC&#8217;s Today Show, online banking is actually safer than paper-based for a few reasons.</p>
<ol>
<li>People who use online banking check their account 4 times more often than those who use paper-based banking. That means if someone does fraudulently steal your identity or your banking information, you&#8217;ll find out about it more quickly and remedy the problem earlier, translating to potentially fewer losses.</li>
<li>Banks&#8217; online systems are more secure than your mailbox and trash bin. Sure, they may not be 100% impervious to attack, but they&#8217;re much harder to hack into than your mailbox at the curb or the trash can full of sensitive information (even if it is shredded).</li>
<li>You can&#8217;t &#8216;wash&#8217; an online transaction. Check washing still occurs today &#8211; where someone takes a legitimate check you signed, washes the original amount and payee information but retains your signature. They&#8217;re then free to put their own name and any amount they choose. Online transactions aren&#8217;t washable &#8211; they go where they&#8217;re meant to go, when they&#8217;re meant to go.</li>
</ol>
<p>Basically what it boils down to is, choose a <a href="http://blog.tricerion.com/2010/01/keyloggers-you-cant-touch-this/">secure password</a> that you can remember <a href="http://blog.tricerion.com/2010/01/why-try-to-remember-what-you-could-just-write-down/">without writing it down</a>. Keep your information to yourself, and don&#8217;t fall prey to scams inviting you &#8220;click here&#8221; to verify your information. You bank doesn&#8217;t need you to verify your information, and if they do they can find a more secure way to contact you than sending an email or putting a button on your Facebook page.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_102_permalink = 'http://blog.tricerion.com/2010/01/3-reasons-online-banking-is-safer-than-paper/';
			dtsv.dtse_post_102_title = '3 reasons online banking is safer than paper';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/01/3-reasons-online-banking-is-safer-than-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Problem with Passwords</title>
		<link>http://blog.tricerion.com/2010/01/the-problem-with-passwords/</link>
		<comments>http://blog.tricerion.com/2010/01/the-problem-with-passwords/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 20:22:32 +0000</pubDate>
		<dc:creator>Eugen</dc:creator>
				<category><![CDATA[Usability]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=61</guid>
		<description><![CDATA[Zack Whittaker’s post on whether we still need usernames/passwords is fueling an interesting debate at ZDNet.  The premise is familiar  &#8211; everyone is tired of storing their hundreds of passwords in an Excel sheet or a password management app.  Wouldn’t it be nice if all websites would just “join hands” so to speak, and create [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.tricerion.com/wp-content/uploads/2010/01/Passwords-mandatory.jpg"><img class="alignright size-full wp-image-73 dtse-img dtse-post-61" title="Passwords-mandatory" src="http://blog.tricerion.com/wp-content/uploads/2010/01/Passwords-mandatory.jpg" alt="" width="280" height="186" /></a>Zack Whittaker’s post on <a href="http://blogs.zdnet.com/igeneration/?p=2498" target="_blank">whether we still need usernames/passwords</a> is fueling an interesting debate at ZDNet.  The premise is familiar  &#8211; everyone is tired of storing their hundreds of passwords in an Excel sheet or a password management app.  Wouldn’t it be nice if all websites would just “join hands” so to speak, and create a magic unified ID access mechanism that would be simple, easy to use, super secure and not cost a zillion dollars to implement?</p>
<p>The debate on usability vs. security somehow always leans towards usability as the obvious choice (we all like “simple”).  Yet every day, all around us we are faced with the very same dilemma:</p>
<ul>
<li><strong>Airport security. </strong> Yes, I want to just show my ticket at the counter and go straight to the airplane door &#8230; no frisking, please.  Unfortunately, not all people are getting on the plane just to travel from A to B.  Some of them try to <a href="http://news.bbc.co.uk/2/hi/americas/8430612.stm" target="_blank">carry explosives on board</a>.  Our concern for safety will allow for more stringent access control to the planes.</li>
</ul>
<ul>
<li><strong>Government.</strong> The Bolshevik revolution started with the social ideal of universal equality.  The Communists believed that every man is inherently good, if he was only given the right tools and opportunities.  Give everyone an equal amount of food, money, clothes, housing, work, and paradise will descend upon us.  Of course, the masses should be defenseless because the State will protect them.  Being different or more gifted than others is also uncool, because you just make the others look bad (remember – universal equality).  If you had to live through that atrocious Communist experiment, would you rather have a meager, but stable and predictable existence where most of your basic needs are met, or would you chose total freedom and personal responsibility for your own success (and failures).  It is incredible, but usability (so to say) wins here too.  People want it easy when it comes to government – basic needs trump individual freedoms.  In a recent poll, <a href="http://english.pravda.ru/society/22-12-2009/111328-sovietnostalgia-0" target="_blank">60% of Russians still regret the break up of the Soviet Union</a>.</li>
</ul>
<ul>
<li><strong>Online Privacy. </strong> There’s been a major paradigm shift in how our society views personal issues.  We now easily discuss very private events and feelings with hundreds of our Twitter and Facebook followers.  Our trust in online privacy created a new (false) sense of security in believing that we still control the information. How much inconvenience would you bear (in terms of access security) to make sure that your social networking accounts are never compromised and misused?  My LinkedIn account is connected to many people I respect and appreciate.  The last thing I want is for someone to hijack my credentials and discredit my reputation or my network.</li>
</ul>
<p>-       Zack Whittaker asks “<em>How would you fix it?</em>” (the password clutter vs. security issue).</p>
<p>I’d like to suggest that <a href="http://en.wikipedia.org/wiki/G._K._Chesterton" target="_blank">G.K. Chesterton</a>’s response to the famous question “<a href="http://www.gutenberg.org/files/1717/1717-h/1717-h.htm" target="_blank">What is wrong with the world?</a>” applies in this case.  Chesterton’s response was written in a form of a letter to “The Times” which initially posted the question:</p>
<blockquote><p><em>Dear Sirs,</em><br />
<em>I am.</em><br />
<em>Sincerely yours,</em><br />
<em>G. K. Chesterton</em></p></blockquote>
<p>What is wrong with the username and password?  I am.  The user is.  As long as the user has the ability to share authentication credentials, he is vulnerable to social engineering (phishing) attacks.  We assume (much like the Communists did) that the user is generally smart and responsible . . . we just need to build higher walls for the enterprise technology or web services (firewalls, etc.).  I agree that the usability has to remain high, and mutual authentication, specifically <a href="http://www.safelogin.co.uk/" target="_blank">graphic passwords</a>, is one of the few security approaches that increases access security, while targeting the weakest link – password shareability.  When using graphic passwords, the user has no ability to easily share his password by typing it, disclosing it on fake websites, sending it by email or even writing it down on a piece of paper.</p>
<p>Our use of technology in everyday life has changed how we live now, 45 years after the first mainframe computers were built.  Yet, we continue to use a 1960s access control mechanism.   <a title="Are Tricerion revolutionising passwords? " href="http://www.it-director.com/business/security/content.php?cid=10590" target="_blank">Passwords have evolved into the 21<sup>st</sup> century</a> and it’s time to <a href="http://www.safelogin.co.uk/" target="_blank">benefit from it</a>.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_61_permalink = 'http://blog.tricerion.com/2010/01/the-problem-with-passwords/';
			dtsv.dtse_post_61_title = 'The Problem with Passwords';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/01/the-problem-with-passwords/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

