Device Authentication - The answer to attacks lauched using stolen passwords?

Device Authentication - The answer to attacks lauched using stolen passwords?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Device Authentication - The answer to attacks lauched using stolen passwords? Saqib Ali 09-02-2006
Posted by Saqib Ali on September 5, 2006, 11:00 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Single point of failure.

How so? Please explain.

Saqib
http://www.full-disc-encryption.com


Posted by =?ISO-8859-1?Q?Lassi_Hippel=E4 on September 6, 2006, 3:00 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Saqib Ali wrote:
>> Single point of failure.
>
> How so? Please explain.

If you loose the device, you are in trouble, because you loose all
services that are bound to that device.

It might be possible to subscribe to services with several redundant
devices, but that will cause problems with synchronization, DRM,
subscription cost, or any combination of the above.

-- Lassi

Posted by wt.eric@gmail.com on September 4, 2006, 10:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

Saqib Ali wrote:
> A recent "self-serving" report by Phoenix Technologies indicated that
> 84 of attacks could have been prevented only if Device Authentication
> was used in addition to user authentication.
>
> - Evidence Abound:
> =B7 Losses from stolen IDs and passwords far exceeded damages from
> worms, viruses, and other attack methods not utilizing logon accounts
> =B7 Vast majority of attackers, 78 percent, committed crimes from their
> home computers; most often using unsanctioned computers with no
> relationship to the penetrated organization
> =B7 88 percent, of those crimes were committed from a home PC using
> stolen IDs and passwords and following normal logon procedures.
>
> - Link to full report:
> https://forms.phoenix.com/cybercrime/docs/cyberdoc.pdf
>
> -Their solution?
> Use Trusted Platform Module to authenticate devices.
>
> - Problem?
> TPM can also be used to force DRM. (EFF and ACLU member don't like DRM
> to say the least)
>
> - Alternatives?
> 1) Be a sitting duck. Passwords WILL stolen and USED to cause financial
> damage;
> 2) Use software based device authentication. e.g. Passmark as used by
> Bank of America
> 3) Create a world-wide PKI, issue SSL certificates to machines as well
> as users, and then perform client side authentication from the server.
> 4) Use IP addresses to perform machine authentication.
>
> - Read more at:
> http://www.xml-dev.com/blog/index.php?action=3Dviewtopic&id=3D243
>
> Any thoughts?

I think some problems should be considered:
(1) Privacy: using such device authentication, every things that
everyone do can be recorded.
(2) System cost: security solution always consume many system
resources. if each operation of each computer should authenticated,
what will happen? Should a router authenticate each tcp packages
passing it?
(3) Convenience: in fact many existing systems have mature security
measurements but for convenience they are usually abandoned and
reversely these system are blamed for security risk (such as domain
server authentication and administration in WIN 2000/XP)
(4) How to prevent cheating of device: an hacker may imitate the tcp
packages he get from the network, etc.


Similar ThreadsPosted
Looking for system/device authentication solution for web app February 8, 2006, 9:12 am
stolen VA laptop question July 22, 2006, 8:02 pm
VA data files on millions of veterans stolen May 22, 2006, 4:06 pm
technologies available to track stolen or lost laptops June 19, 2008, 9:23 am
SSL Server authentication, SSL client authentication, SSL connection and SSL session August 14, 2006, 1:05 pm
WEP authentication, why WEP authentication scheme is flawed and how it can be attacked August 1, 2006, 12:51 pm
Are you financially frustrated? Relax! This is your answer. September 15, 2005, 11:03 pm
Request for help with a hacker project, or simple question answer sought August 5, 2006, 10:00 am
Find out a device by knowing IP March 17, 2005, 7:47 pm
Examination room computers accessed by tons of users: what's the answer? Biometrics? April 28, 2008, 2:44 pm

The site map in XML format XML site map

Contact Us | Privacy Policy