Wednesday, 2012-10-10

*** Skelroy has quit (Ping timeout: 246 seconds)08:29
*** Skelroy_ (~Skelroy@71-85-217-74.dhcp.stls.mo.charter.com) has joined #wikid08:29
*** Skelroy_ has quit (Ping timeout: 246 seconds)08:36
*** Skelroy_ (~Skelroy@71-85-217-74.dhcp.stls.mo.charter.com) has joined #wikid13:01
*** nowen (~nowen@adsl-98-66-180-42.asm.bellsouth.net) has joined #wikid14:03
*** nowen has quit (Remote host closed the connection)16:19
*** nowen (~nowen@adsl-98-66-180-42.asm.bellsouth.net) has joined #wikid16:19
*** __TOM (~wtfnom@38.103.49.130) has joined #wikid19:21
__TOMnick, you around?19:21
nowenyes19:21
__TOMhad a quick Q regarding unlocked vs locked soft tokens for windows/mac19:21
nowenok19:22
__TOMi guess im looking for an answer regarding how unlocked is less secure than the locked version19:22
__TOMwhen the token registers with the server do they not generate a seperate pub/priv keypair?19:22
__TOMso if user A has 2 computers19:22
nowenthe locked tokens pull data from the machine during registration such as the CPU identifier or mac address and hashes it19:23
nowenthis hash must match for each OTP request19:23
nowenit prevents unsophisticated users from moving the token19:23
nowenalso, it has a variable pin pad19:23
__TOMwith the unlocked token, they can choose to move it at will?19:23
nowenwhich may help thwart keyloggers19:23
nowenyes19:23
__TOMwouldnt they need to reregister?19:24
nowenno, they move the file that has the keys which are registered19:24
__TOMohhh19:24
__TOMi see.19:24
__TOMand if there are no additional steps for implementing a locked token, is there a reason one would not implement locked tokens only?19:24
__TOMand is this a concern for mobile devices like android as well?19:25
__TOMlike is the android client considered locked?19:25
__TOMFYI I'm starting a live pilot very soon, just as a heads up since I've had this installed under demoware for quite some time sitting idle.19:26
nowenit is not, but it is considered harder to get info off of it.  obviously, that is a moving target.  users certainly don't do it19:26
nowen on those devices we can add stuff like location down the road19:27
__TOMi see.  okay thanks.19:28
*** nowen has quit (Quit: Leaving.)21:00

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!