Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Mobile Phones Generate Passwords

New app puts two-factor authentication on handset

Jul 02, 2007 | 03:22 AM

By Kelly Jackson Higgins
DarkReading

New software from Secure Computing could soon let your mobile handset serve as a second factor of authentication for remote access to the enterprise network.

Secure Computing on July 9 will officially roll out SafeWord MobilePass, which generates one-time passcodes from a user's mobile phone, Dark Reading has learned.

"It's an alternative to the hardware token," says Stuart Rauch, director of product marketing for Secure Computing. "Since a lot of [enterprise] users have mobile phones with them now all the time, they can have this installed on the phone so they don't have to carry a hardware token."

Secure Computing has already begun quietly shipping the MobilePass application to some of its customers. The catch is that it's a tool for the company's SafeWord PremierAccess 4.0 authentication management software for remote access using Microsoft's Active Directory.

The user basically pulls up the app on a phone, pushes a button, and it generates a one-time password for logging onto the corporate network. MobilePass works on BlackBerry, Palm, Windows Mobile, and J2ME-enabled mobile devices, and Secure Computing plans to make the software available for Windows-based laptops and desktop machines as well.

Secure Computing's PremierAccess software starts at about $100 per user.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

  • Secure Computing Corp. (Nasdaq: SCUR)


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)