Brian

Archive

Should World Password Day Become World 2FA Day?

Checking the National Day Calendar today, I see that it is World Password Day. I found it interesting that the primary website dedicated to this seems not to have been updated since last year (maybe...

GreenRADIUS v2.0

The following new security features have been updated or added in GreenRADIUS v2.0: Underlying OS updated to Ubuntu Server 14.04 LTS Webmin console has been moved to port 443 instead of the Webmin default of...

Background Noise as Authentication data?

So new this week is the idea of “Sound Proof” authentication. The idea is that the microphone on your device would listen to the background noise where you are and determine if you are who...

Almost 40% of Companies Still Use Only Passwords

So I ran across this article the other day about the number of companies still using password-only authentication. Now looking at the actual survey, and it says that in 2015, 39% of respondents reported using...

OpenSSH Vulnerable to Unlimited Authentication Attempts

Possibly the biggest security news this past week was the announcement of a bug in OpenSSH that opens it to password cracking. Normally, OpenSSH restricts the number failed authentication attempts that can occur on an...

Emoji Authentication?

So I ran across this article where a UK bank is replacing PIN codes with emoji. I get the point. One of the main problems with PIN codes is that in general they are only...

FIDO Alliance accepted by US Government

The FIDO Alliance announced today that the US and UK governments have signed up to support the FIDO standard. This is great news as it starts the conversation for allowing the use of a FIDO...

“Brainprints” anyone?

So I ran across this interesting article on a new biometric, this time a brain scan while you think about specific acronyms. The thing I like most about this is that it seems to answer...

It’s Only a Matter of Time Before Your Insurance Requires 2FA

So I came across this interesting article about an insurance company that paid for the cost of a breach is now suing to get the money back from the insured company because of poor security...

Great news on the FIDO front!

So last week it was announced at the FIDO Plenary in Dublin, Ireland (I wish I would have been able to attend) that 18 different companies and 31 different products have been FIDO certified. This...