Viewing posts by admin
trusted-computing-for-mobile-devices
Posted by: admin 16 years, 3 months ago
There is a new specification for mobile phone security called the Mobile Security Specification. It is essentially trusted computing for cell phones.
The specification has been years in development, said Janne Uusilehto, head of Nokia product security and the chairman of the working group developing this technology. "It is a big deal. This is the first time that we have created such common security specifications for all handheld devices," Uusilehto said.More:
When these devices appear, they will make things more difficult for data thieves and mobile virus writers. Down the line, the technology could be used to build electronic wallets into mobile phones. In general terms, the specification calls on hardware vendors to store protected information in a secure area of the phones. Similar to the Trusted Platform Module used in PCs, this technology could be used to ensure that the phone's operating system, applications and data have not been tampered with.
All the usual trusted computing warnings apply here, but perhaps more so as cell carriers maintain a 'walled garden' and can limit the devices available. They are also essentially 'tri-opolies'. It seems likely that you will be able to buy a computer without TCP in the future. You might not be able to buy a cell phone without it (that works on a carrier).
when-the-cone-of-silence-isnt
Posted by: admin 16 years, 3 months ago
MOSCOW - Intentionally or not, the Russians fed out audio of Thursday’s closed lunch meeting between Secretary of State Condoleezza Rice and Russian Foreign Minister Sergey Lavrov, revealing a fractious exchange over the wording of an official Group of Eight statement on Iraq.
you-might-need-two-factor-authentication
Posted by: admin 16 years, 3 months ago
According to this VNUnet article Great North Eastern Railway "inadvertently printed system passwords in a magazine available to thousands of passengers".is-there-a-cheap-stock-issue-for-google-after-the
Posted by: admin 16 years, 3 months ago
I'm no lawyer not a securities expert, but I have sold some companies and one issue we had to deal with when selling to a public company was "cheap stock". The concern is that a company might distribute stock cheaply to insiders before going public, then sell it at a premium. (I guess the regulation protects the existing shareholders?) It is also an issue for employees who get options before an IPO. Options that are granted with the strike price equal to the value of the underlying are not taxed because there is no gain. But if the next day the stock triples because of an IPO, was the valuation correct? Are taxes owed? This regulation makes more sense to me, because Uncle Sam likes his taxes.
top-9-reasons-to-embrace-two-factor-authentication
Posted by: admin 16 years, 3 months ago
Passwords have been around forever and it's starting to show. The next level of authentication security is two-factor authentication. Your ATM card is an example of two-factor authentication: you need both possession of the card and knowledge of the PIN to get cash. There are a number of factors that are pushing two-factor authentication toward a tipping point.
Recent Posts
- Blast-RADIUS attack
- The latest WiKID version includes an SBOM
- WiKID 6 is released!
- Log4j CVE-2021-44228
- Questions about 2FA for AD admins
Archive
2024
2022
- December (1)
2021
2019
2018
2017
2016
2015
2014
- December (2)
- November (3)
- October (3)
- September (5)
- August (4)
- July (5)
- June (5)
- May (2)
- April (2)
- March (2)
- February (3)
- January (1)
2013
2012
- December (1)
- November (1)
- October (5)
- September (1)
- August (1)
- June (2)
- May (2)
- April (1)
- March (2)
- February (3)
- January (1)
2011
2010
- December (2)
- November (3)
- October (3)
- September (4)
- August (1)
- July (1)
- June (3)
- May (3)
- April (1)
- March (1)
- February (6)
- January (3)
2009
- December (4)
- November (1)
- October (3)
- September (3)
- August (2)
- July (5)
- June (6)
- May (8)
- April (7)
- March (6)
- February (4)
- January (427)
2008
- December (1)
Categories
- PCI-DSS (2)
- Two-factor authentication (3)
Tags
- wireless-cellular-mobile-devices (7)
- Two-factor authentication (10)
- Wireless, cellular, mobile devices (6)
- NPS (1)
- Phishing and Fraud (111)
- Active Directory (1)
- pam-radius (3)
- privileged access (2)
- Cloud Security (10)
- Mutual Authentication (60)
- Web Application Authentication (1)
- Authentication Attacks (99)
- pci (50)
- Security and Economics (97)
- WiKID (133)
- pam (2)
- VPN (1)
- Installation (2)
- RADIUS Server (1)
- Open Source (64)
- Tutorial (2)
- Strong Authentication (35)
- Information Security (137)
- Transaction Authentication (13)
- Miscellaneous (100)
- Linux (2)
- transaction-authentication (6)
- Two Factor Authentication (254)