Skip to main content

The WiKID Blog

Viewing posts from January, 2009

mutual-authentication

In our continuing effort to promote the idea that one-time passwords should be combined with strong host authentication, we have published a quick and easy how-to on the subject over at howtoforge.com.

msn-korea-site-hosted-malware-for-days

An update from Forbes on the MSN Korea attack:

myopenid-security-fix

Josh Hoyt has a preliminary notice about a security fix for MyOpenID. It's limited (at least on MyOpenID) to Safari users, so it's not a big deal. Josh considers it a flaw in the way Safari handles javascript security. But it is clear that OpenID is going through some growing pains as a protocol, which is natural and healthy. I'm impressed with the way the community is handling this vulnerability.

mutual-authentication-and-ssl-based-vpns

Much of the discussion of the need for strong mutual authentication has focused on consumer applications - in particular the failings of non-cryptographic, image-based solutions. However, there is also a risk for corporate VPN access where SSL-based VPNs are deployed. Creating a man-in-the-middle attack that thwarts SSL-based VPNs is trivial with the proliferation of WiFi networks.

network-world-on-virtual-appliances

Hat Tip: Virtualization Daily. Network World has a great article pointing out the benefits of virtual appliances

Recent Posts

Archive

2024
2022
2021
2019
2018
2017
2016
2015
2014
2013
2012
2011
2010
2009
2008

Categories

Tags

Authors

Feeds

RSS / Atom