Security News

Why biometrics will not fix all your authentication woes
2020-11-17 06:00

In recent years biometrics have increasingly been lauded as a superior authentication solution to passwords. With a detailed enough representation of a biometric marker, it's possible to spoof it and, with the rise of deep-fake technology, it will become even easier to spoof biometrics.

How to secure your Zoom account with two-factor authentication
2020-11-16 23:04

Follow these steps to better protect your Zoom account with a second layer of authentication. Zoom now provides an extra level of security to your account with two-factor authentication.

Windows Kerberos authentication breaks due to security updates
2020-11-16 10:56

Microsoft is investigating a new known issue causing enterprise domain controllers to experience Kerberos authentication problems after installing security updates released to address CVE-2020-17049 during this month's Patch Tuesday, on November 10. Kerberos replaced the NTLM protocol to be the default authentication protocol for domain connected devices on all Windows versions above Windows 2000.

Microsoft warns against SMS, voice calls for multi-factor authentication: Try something that can't be SIM swapped
2020-11-11 21:19

Multi-factor authentication, for those who haven't been paying attention, involves adding one or more additional access requirements to password-based authentication. At the same time, he argues people should avoid relying on SMS messages or voice calls to handle one-time passcodes because phone-based protocols are fundamentally insecure.

Can we trust passwordless authentication?
2020-10-20 05:00

Whether decreasing the number of passwords required through single sign-on or eliminating the password altogether in favor of a strong authentication factor, the priority is on the workforce experience. At the same time, we've asked users to create longer passwords, more complex passwords, unique passwords.

Authentication Bug Opens Android Smart-TV Box to Data Theft
2020-10-13 16:36

The streaming box allows arbitrary code execution as root, paving the way to pilfering social-media tokens, passwords, messaging history and more. A critical bug in the Hindotech HK1 TV Box would allow root-privilege escalation thanks to improper access control.

On Risk-Based Authentication
2020-10-05 16:47

Abstract: Risk-based Authentication is an adaptive security measure to strengthen password-based authentication. RBA monitors additional features during login, and when observed feature values differ significantly from previously seen ones, users have to provide additional authentication factors such as a verification code.

Is passwordless authentication actually the future?
2020-10-02 04:30

While passwords may not be going away completely, 92 percent of respondents believe passwordless authentication is the future of their organization, according to a LastPass survey. Passwordless authentication reduces password related risks by enabling users to login to devices and applications without the need to type in a password.

LexisNexis ID Compass Platform offers multi-layered approach to identity authentication
2020-10-01 02:30

LexisNexis Risk Solutions announced the availability of the LexisNexis ID Compass Platform for Insurance. A multi-layered identity access management solution, the platform combines physical and digital intelligence to help insurance carriers respond to identity risk and reduce friction for consumers seeking insurance quotes and other transactions.

YubiKey 5C NFC security key supports multiple authentication protocols
2020-09-09 11:18

Yubico announced the general availability of the YubiKey 5C NFC, a multi-protocol security key with smart card support, designed with both near-field communication and USB-C connections on a single device. "Users are no longer tied to just one device or service, nor do they want to be. That's why the YubiKey 5C NFC is one of our most sought-after security keys - it's compatible with a majority of modern-day computers and mobile phones and works well across a range of legacy and modern applications. At the end of the day, our customers crave security that 'just works' no matter what."