|
|
Like this article? PLEASE +1 it! |
|
Don't Wait for Windows 8 to Secure Your Passwords
|
| Guest post by: Dovell Bonnett |
Article Overview: This week the press is all agog about how Windows 8 is going to “securely” manage passwords. Win 8 will do this with LiveID, syncing passwords across multiple computer platforms, using “TrustedID” to authenticate the computer, and storing all your long complex passwords in the cloud or on your device. But the sense of security is still misplaced.
![]() |
Free Download - Zappos Data Breach - Customer Safety and Security By Dovell Bonnett |
Don't Wait for Windows 8 to Secure Your Passwords
When it comes to security, multi-authentication is the first topic that comes up, and these are:
- Something you have. (Smart Card, token, etc.)
- Something you know. (Password, PIN or pattern)
- Something you are. (Fingerprint, iris scan, etc.)
First, storing passwords on the device that you will be using to access applications, sites, servers, etc., is a violation of “something you have.” Something you have has to be a completely separate piece of hardware that had to be brought together with another piece of hardware. That’s why we use smartcards, tokens, dongles, etc. So synchronizing and Trusted ID adds little to no security.
Second, jumping ahead to biometrics is the “something you are“. It does not matter if it is a fingerprint, iris image, facial recognition, voice print, etc. It all is digitally captured and turned into a bunch of 1’s and 0’s called a template. Capturing the template and doing a playback is a security risk, and storing your templates on multiple devices and sites increases the probability of theft. So off computer or on-token matching is the best solution, which ties back into “something you have”. Finally, if you opt out of biometrics then you have also dropped one more authentication factor.
Third, by eliminating the authentication of the first two factors, you are now down to Single Factor Authentication – the weakest security of all. Being left with the one password, “something you know“, to authenticate into LiveID is not secure. I have described in numerous bogs, articles and books how insecure user generated passwords are and how easy it is for hackers to crack. Also, keyloggers, post-it notes and over-the-shoulder surfers make typing in passwords insecure.
Finally, just the whole concept of having all my passwords stored on a single computer or on the web/cloud is very disturbing. It is these centrally located databases that are so attractive to hackers because once they get in they have access to numerous accounts and it makes no difference how long, secure or complex a password is because they will actually have the actual password in their possession. And this is a very valid concern; will the government or corporations also be able to collect my passwords thought court orders without my knowledge?
Power LogOn® by Access Smart® has been delivering multi-factor authentication, smartcard-based password management solutions for years. Users are able to store multiple passwords on a single smart card, no passwords are ever stored with in a computer that others can access our hack, and when the card is removed from the computer no critical logon data is left behind on the computer. If the card is lost or stolen all the passwords are protect because the card authentication includes a limited number of false entries before it is locked and needs IT assistance. From the users perspective a lost card is easily recoverable without having to change all your passwords. Users passwords need to be de-centralized and always in the possession of the user. Power LogOn is being used by individuals, small businesses, and large enterprises. So don’t wait for Windows 8 to think you can securely manage your passwords, implement today and protect your data. Complex passwords are recognized as the way to secure accounts. Power LogOn allows businesses to securely manage all those passwords and for IT to be put back in control of logon security..
Related Articles
Article Tags: identity theft, internet security, password management, smart cards
|
About the Author: Dovell Bonnett RSS for Dovell's articles - Visit Dovell's website Founded in 2005 and headquartered in Ladera Ranch, California, Access Smart delivers Access-as-a-Service (AaaS) solutions by way of a password manager for Windows authentication to reduce the risk of cyber-attacks. Access Smart implements AaaS using contact or contactless smartcards, magnetic stripe or 125kHz Prox technologies. The value that Access Smart brings is to offer more security functions and affordability onto a single employee ID badge. Security does not have to be cumbersome to be affective. That is why our products are designed using state-of-the-art security technologies while focusing on ease-of-use and low cost-of -ownership. Previously, smartcard technology was only available to governments and Fortune 500 companies. Access Smart has turned that model upside down by matching the technology to the needs, no annual subscription fees and fully transferable licenses to keep security affordable to even high employee/student turnover businesses. The Access Smart team has over 50 combined years in the smartcard and security industry. By addressing the very real problems from a systems mindset, Access Smart delivers everything for a company to implement AaaS within hours and not months/years. Please contact Dovell Bonnett at Access Smart as to discuss how best to implement Authentication, Authorization and Non-Repudiation into your business. Access Smart - The Alternative to PKI. Click here to visit Dovell's website MORE HACKING WHEN WILL IT STOP Data Security is Mandatory How Thieves Physically Steal Your Data The Law May Consider Your Business a Bank What To Do When Your Company Network Is Hacked |
Related Forum Posts
Share this article with your friends. Fund someone's dream.
Leave a comment below or share on the left and you'll help support entrepreneurs in Africa through our partnership with Kiva. Over $50,000 raised and counting - Please keep sharing! Learn more.
Get advice & tips from famous business
owners, new articles by entrepreneur
experts, my latest website updates, &
special sneak peaks at what's to come!
Hypotheticals, Scenarios and Foresight
When the Going Gets Tough, the Tough Log On
Are You Too Good for Your Job?
Email us your ideas on how to make our
website more valuable! Thank you Sharon
from Toronto Salsa Lessons / Classes for
your suggestions to make the newsletter
look like the website and profile younger
entrepreneurs like Jennifer Lopez.



