Risk
9/17/2010
06:44 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Apps Adds Two-Step Verification

Enhanced security is now available to Google Apps enterprise customers via their mobile phones.

Google security product manager Travis McCoy says that the widespread adoption of cloud computing means that employees are often off-premises and outside corporate security controls when they access company data. This has created a challenge: making external points of access as safe as internal ones.

McCoy says that Google's security team determined that improving login security would have the most impact on user security. "The user name and password model is fundamentally flawed in several ways," he said in a phone interview.

Gartner VP Avivah Litan says that Google is taking a step in the right direction, though she argues that more needs to be done. "It's better than just passwords," she said in a phone interview.

Two-factor authentication has become popular as a way to give users confidence in cloud computing services, she said, pointing to several recent identity access management acquisitions, such as VMware's acquisition of TriCipher.

"Enterprise customers don't want their accounts being taken over, especially if they're using them to store intellectual property or business plans," she said.

Litan observes that verification codes won't prevent unauthorized access if the user's computer is already compromised by malware like the Zeus trojan and McCoy concedes that point. "It's not a panacea but we do think it's a significant step forward," he said.

Google has already taken a number of such steps to improve online security. In 2004, it added SSL support to Gmail and made SSL the default earlier this year. The company has also made an encrypted version of Google Search available and had taken steps to allow Gmail users to see when and from which IP address their Gmail account was last accessed.

Litan notes that two-factor authentication is no longer enough for many banks and she suggests that Google will have to move on to monitoring for suspicious use patterns. While McCoy declined to provide specifics about Google's future security plans, he points to Gmail's IP address login records as evidence that Google is already moving in the direction that Litan advocates.

"We have to assume there is no security system we can deploy that's bulletproof," he said. "At that point, it makes sense to switch to notification."

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: You should see what I wear on my work from home days!
Current Issue
The Changing Face of Identity Management
Mobility and cloud services are altering the concept of user identity. Here are some ways to keep up.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio

The cybersecurity profession struggles to retain women (figures range from 10 to 20 percent). It's particularly worrisome for an industry with a rapidly growing number of vacant positions.

So why does the shortage of women continue to be worse in security than in other IT sectors? How can men in infosec be better allies for women; and how can women be better allies for one another? What is the industry doing to fix the problem -- what's working, and what isn't?

Is this really a problem at all? Are the low numbers simply an indication that women do not want to be in cybersecurity, and is it possible that more women will never want to be in cybersecurity? How many women would we need to see in the industry to declare success?

Join Dark Reading senior editor Sara Peters and guests Angela Knox of Cloudmark, Barrett Sellers of Arbor Networks, Regina Wallace-Jones of Facebook, Steve Christey Coley of MITRE, and Chris Roosenraad of M3AAWG on Wednesday, July 13 at 1 p.m. Eastern Time to discuss all this and more.