Re: Someone's knocking on my door



Hans Georg Schaathun wrote:

[*] For an annual fee, you can have an electronic pseudo-random
generator instead of this card. I am not quite sure how that works;
if it provides any (real) additional security.

Theoretically, yes it does. If you've got two 'factors', ie something you
have and something you know, then you can only lose one at a time.

http://en.wikipedia.org/wiki/Securid

I presumed these things used something like a Rugby clock to make sure they
were synced properly with the server, but apparently not. Note that an RSA
Securid server for 250 users costs £30k, and 250 tokens costs £10k, so it's
no wonder that there's an 'annual fee'!

--
<http://ale.cx/> (AIM:troffasky) (gebssnfxl@xxxxxxxxxxx)
20:26:37 up 9 days, 5:15, 3 users, load average: 0.44, 0.89, 0.80
This is my BOOOOOOOOOOOOOOOOOOOOOMSTICK

.



Relevant Pages

  • [REVS] Cryptanalysis of the Random Number Generator of the Windows Operating System
    ... Get your security news from a reliable source. ... Cryptanalysis of the Random Number Generator of the Windows Operating ... of the algorithm and found a non-trivial attack: ... WRNG design. ...
    (Securiteam)
  • Bush forcing National ID Cards on States
    ... Didn't the Republicans have a cow over a national ID card in 1993 when Clinton was President? ... Dispute Over New Rules For Driver's Licenses Could Prevent Millions From Boarding Planes ... The government is proposing a national ID card in the interest of security. ... But federal officials are in no mood for further compromises or any more delays in implementing a plan the 9/11 Commission called a priority three and a half years ago, reports CBS News correspondent Bob Orr. ...
    (alt.politics.bush)
  • Risks Digest 25.73
    ... German electronic health card system failure ... Risks of the Cloud: Liquid Motors ... Oakland 2010, IEEE Symposium on Security and Privacy, CFP ... A friend's facebook account was hacked recently (a neat little short-term ...
    (comp.risks)
  • Re: OT TAN: POS Data Mining (was Re: Google at the Pump?!)
    ... Distracted Driver (Hector Goldstein)" ... With the systemwe have in place, we have an encryption key, but do ... and pay attention to how the cashier handles your card. ... security group, can review the videoat their convenience, looking ...
    (rec.autos.driving)
  • Tell me again how we are so much more secure?
    ... Homeland Security accepts fake ID ... The Department of Homeland Security allowed a man to enter its headquarters ... federal rules that say the Mexican-issued card is not valid ID at government ... Mexican government publicly acknowledges is not a secure document. ...
    (alt.politics)