<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/" > <channel><title>Comments on: Web Security &#8211; Authentication Factors</title> <atom:link href="http://www.dragonblogger.com/web-security-authentication-factors/feed/" rel="self" type="application/rss+xml" /><link>http://www.dragonblogger.com/web-security-authentication-factors/</link> <description>Blogging Tips, Technology news, with Movie Reviews and Entertainment posts mixed in for fun.</description> <lastBuildDate>Sun, 12 Feb 2012 17:13:27 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>By: Dragon Blogger</title><link>http://www.dragonblogger.com/web-security-authentication-factors/comment-page-1/#comment-33958</link> <dc:creator>Dragon Blogger</dc:creator> <pubDate>Mon, 31 Oct 2011 17:26:16 +0000</pubDate> <guid isPermaLink="false">http://www.dragonblogger.com/?p=2884#comment-33958</guid> <description>Identity Profiling based on history is also gaining in popularity, look at any credit bureau login to see what it looks like.</description> <content:encoded><![CDATA[<p>Identity Profiling based on history is also gaining in popularity, look at any credit bureau login to see what it looks like.</p> ]]></content:encoded> </item> <item><title>By: Sentry Safe</title><link>http://www.dragonblogger.com/web-security-authentication-factors/comment-page-1/#comment-3571</link> <dc:creator>Sentry Safe</dc:creator> <pubDate>Sat, 24 Oct 2009 19:23:03 +0000</pubDate> <guid isPermaLink="false">http://www.dragonblogger.com/?p=2884#comment-3571</guid> <description>I think there are a lot of options in true factor.  Voice recognition in addition to personal PINS and passwords is becoming very popular in online banking.</description> <content:encoded><![CDATA[<p>I think there are a lot of options in true factor.  Voice recognition in addition to personal PINS and passwords is becoming very popular in online banking.</p> ]]></content:encoded> </item> <item><title>By: dragonblogger</title><link>http://www.dragonblogger.com/web-security-authentication-factors/comment-page-1/#comment-2121</link> <dc:creator>dragonblogger</dc:creator> <pubDate>Wed, 12 Aug 2009 14:29:44 +0000</pubDate> <guid isPermaLink="false">http://www.dragonblogger.com/?p=2884#comment-2121</guid> <description>I should have mentioned OTP (One Time Passwords) as an additional layer of security, though it is still in the &quot;Something You Have&quot; category and is not true two-factor unless combined with one other category.</description> <content:encoded><![CDATA[<p>I should have mentioned OTP (One Time Passwords) as an additional layer of security, though it is still in the &#8220;Something You Have&#8221; category and is not true two-factor unless combined with one other category.</p> ]]></content:encoded> </item> <item><title>By: Nakkiran</title><link>http://www.dragonblogger.com/web-security-authentication-factors/comment-page-1/#comment-2119</link> <dc:creator>Nakkiran</dc:creator> <pubDate>Wed, 12 Aug 2009 06:56:37 +0000</pubDate> <guid isPermaLink="false">http://www.dragonblogger.com/?p=2884#comment-2119</guid> <description>Hi, have a look at FireID. Instead of carrying hardware fobs, your OTP is generated on your mobile phone itself, ie., no SMS&#039;s. And the application is PIN protected, ensuring a secure two-factor authentication method using everyone already has :)</description> <content:encoded><![CDATA[<p>Hi, have a look at FireID. Instead of carrying hardware fobs, your OTP is generated on your mobile phone itself, ie., no SMS&#8217;s. And the application is PIN protected, ensuring a secure two-factor authentication method using everyone already has <img src='http://cdn.dragonblogger.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p> ]]></content:encoded> </item> <item><title>By: dragonblogger</title><link>http://www.dragonblogger.com/web-security-authentication-factors/comment-page-1/#comment-2118</link> <dc:creator>dragonblogger</dc:creator> <pubDate>Tue, 11 Aug 2009 23:18:07 +0000</pubDate> <guid isPermaLink="false">http://www.dragonblogger.com/?p=2884#comment-2118</guid> <description>This is called 1+ Factor authentication and leverages two &quot;Something you Know&quot; items.  It is the same category as having a username/password and some security questions, it is not true 2-factor authentication, in most cases it is completely useless since you often already entered the username/password and just accept past the image, it doesn&#039;t prompt you for another passphrase.  From a web security perspective there is no additional security benefit by showing you a picture with a little phrase (ING does it as well), it is more to throw up a warning in case you logged into a different account or site, or if your image doesn&#039;t match what you remember it could mean someone changed it, but that is extremely unlikely.</description> <content:encoded><![CDATA[<p>This is called 1+ Factor authentication and leverages two &#8220;Something you Know&#8221; items.  It is the same category as having a username/password and some security questions, it is not true 2-factor authentication, in most cases it is completely useless since you often already entered the username/password and just accept past the image, it doesn&#8217;t prompt you for another passphrase.  From a web security perspective there is no additional security benefit by showing you a picture with a little phrase (ING does it as well), it is more to throw up a warning in case you logged into a different account or site, or if your image doesn&#8217;t match what you remember it could mean someone changed it, but that is extremely unlikely.</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Database Caching 12/25 queries in 0.413 seconds using disk: basic
Content Delivery Network via cdn.dragonblogger.com

Served from: www.dragonblogger.com @ 2012-02-12 11:36:54 -->
