Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

6/20/2013
02:56 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Clavid Launches Authentication As A Service

Clavid enables users to combine the authentication methods that are already in place so they can use one single login to access all Internet services

ST. GALLEN, Switzerland, June 20, 2013 /PRNewswire/ --

We disclose much that is private and confidential on the Internet. That's why "Internet" and "security" go hand in hand. Recurring attacks by hackers against online shops, cloud services or social networks make it even more essential for us to provide better protection for our own data. However, many Internet services have serious weaknesses in this regard. These gaps are easy targets for hackers. But they don't have to be! Clavid is launching the solution to this problem by offering Authentication as a Service.

Picture can be downloaded under:

http://www.presseportal.ch/go2/clavid_illustration

Closing security gaps on the Internet

Various good authentication processes are available that can guarantee a high level of security and keep hackers at bay. But what use are these excellent tools if operators of online shops, cloud services or web portals fail to use them? Many Internet services simply carry on operating their unsafe login procedures - mostly consisting of a user name and password - without any clear idea of the consequences of potential abusive access. Why do they run this unacceptable risk?

The authentication services that are available saddle Internet service providers with high implementation expenses for installation and licences, as well as considerable extra logistics costs depending on whether tokens (such as USB

sticks) are also sent. At the same time, users are expected to go through a separate login procedure for each service. In the worst case, they have to carry several hardware tokens around with them. Why not choose a simpler option?

Clavid has developed a solution that eliminates the weaknesses of existing systems and makes security comfortable.

One key, access from anywhere, low costs

Clavid's innovative interface technology combines all the authentication procedures currently available on the market into one service. What we offer is unique in the world: Authentication as a Service (AaaS). Internet service providers use this simple solution from Clavid as an authentication procedure that delivers enhanced comfort and security for themselves and their customers.

At the same time, they cut their costs substantially - and their customers will also be delighted: Clavid gives them simple and secure access to all the Internet services they use. Users log into Clavid with the login method that they select personally, and then they are simply and unambiguously identified and accredited as authorised persons. No other provider anywhere in the world can currently offer such strong, simple and secure authentication.

Life made simpler and safer for private Internet users

At present, it is often the case that Internet service users can only log in with an insecure combination of a user name and a password. Most Internet services do not offer strong authentication, and private users have to keep records of numerous user names and passwords. This is impractical and complicated, and it is not secure. The same applies to service providers, because password renewals account for over 30% of IT costs. Clavid enables users to combine the authentication methods that are already in place so they can use one single login to access all Internet services - and then they can continue to surf safely.

Lower risks and costs for business customers

Clavid's Single Sign-On (as it is known) gives companies a convenient way of regulating their employees' access and user rights. Managers no longer have to bother with individual access methods for different systems and platforms.

Clavid implements the company's wishes and requirements without expenses for every single integration of a large number of services.

Cutting costs for Internet service providers

Internet companies no longer have to opt for one authentication procedure. This significantly cuts implementation costs, support expenditure and outage risks.

Now they only pay one predictable installation fee while Clavid takes care of everything else.

Reduced outlay for authentication procedure producers

Producers of authentication procedures currently incur huge costs in order to market their services to the operators of countless Internet services. Separate contracts have to be negotiated with each of them, at enormous expense. This is why the producers are eager to have a joint market presence with Clavid so that they can launch their new methods across the globe in one fell swoop.

"Swiss Privacy" makes the Internet world more secure

Clavid's innovative offering delivers benefits to private and commercial Internet users, Internet service providers and producers of authentication procedures. It makes digital identification more secure and easier to implement, and it saves time and money. Thanks to Clavid, "Swiss Privacy" - one of Switzerland's core competences - is now also available for the Internet.

Let's use Clavid the key for your safety in our digital world

About Clavid AG:

Clavid AG offers high-calibre services, solutions and products for the professional IT security environment. Our core competences focus on authentication and authorisation in the digital world.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
WannaCry Has IoT in Its Crosshairs
Ed Koehler, Distinguished Principal Security Engineer, Office of CTO, at Extreme Network,  9/25/2020
Safeguarding Schools Against RDP-Based Ransomware
James Lui, Ericom Group CTO, Americas,  9/28/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-26120
PUBLISHED: 2020-09-27
XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can elicit an XSS attack via jQuery's parseHTML method, which can cause image callbacks to fire even witho...
CVE-2020-26121
PUBLISHED: 2020-09-27
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a mishandled distinction between an uploa...
CVE-2020-25812
PUBLISHED: 2020-09-27
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML.
CVE-2020-25813
PUBLISHED: 2020-09-27
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
CVE-2020-25814
PUBLISHED: 2020-09-27
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an <a> ...