[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Secure Token-two factor Authentication

Posted on 2013-11-26
2
Medium Priority
?
186 Views
Last Modified: 2015-08-17
Hello,

I was wondering if anyone out there is using a token to replace the username/password domain authentication process for internal users to access network resources?  If so, can you recommend a provider?  How difficult was the move? What is the second authentication factor either password or challenged response, etc.
Thank you,
Christine
0
Comment
Question by:christine_allen
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 2000 total points
ID: 39680471
First: http://www.experts-exchange.com/Security/Misc/A_12368-Two-Factor-Authentication-Added-layers-are-not-always-added-security.html
Second you can try the yubikey products, they are cheaper than many and very goo.

2FA doesn't work at the lower levels of the network, read my article for more information.
-rich
0
 
LVL 65

Expert Comment

by:btan
ID: 39680524
2FA simply means more than what we know and to incorporate either what we have (separate device like phone, OTP generator or smartcard) OR/AND what we are (biometric primarily). Most common is to have "what we have"

OTP - can be software or hardware authenticator. common one is securID. you need an authenticator server provision though so that this one time password is sync when you keyed in. See this comparison for summary
https://store.emc.com/Product-Family/EMC-Store-Products/c/EMCStoreProducts/layout?layoutType=false&page=0&grid=true&q=:relevance:ProductFamily:RSA%20SecurID%20Products&PID=EMC_PRD-RSASIDSAM-D99E_SPLSH


Phone based

- There is one called PhoneFactor that allows a server to communicate a one-time additional code with the user’s mobile phone at the time of access. It is now under Microsoft suite and support Azure Cloud (Amazon Cloud has MFA and using smartcard or token if I recalled correctly, is gemalto)
https://www.phonefactor.com/solutions.shtml
Some example using include https://2factor.musc.edu/2fa/

- And even google has apps for mobile called the authenticator
https://code.google.com/p/google-authenticator/

We do try to avoid going too complex with PKI and lesser footprint but at the same time able to scale and stay flexible. Hence smartcard wasnt always the liking though it is more secure compared to simple OTP...of course if machine has keylogger or browser MITM, the PIN and OTP can easily be siphoned ...
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
An overview of cyber security, cyber crime, and personal protection against hackers. Includes a brief summary of the Equifax breach and why everyone should be aware of it. Other subjects include: how cyber security has failed to advance with technol…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question