How to enhance login/password weak authentication ?

How to enhance login/password weak authentication ?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How to enhance login/password weak authentication ? webmaster 01-18-2007
Posted by on January 18, 2007, 6:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I manage a social website with a large number of subscribers. We have a
regular login/password authentication for our subscribers. Recently we
had a problem - because of phishing or keylogger or breakin ( nobody
knows exactly) many accounts of the web site were hijacked. Someone
wrote a program (bot) that sent spam using private messages on our site
through hijacked accounts. We changed the passwords meantime and put
some captcha forms, but now we seek for a permanent solution to solve
this problem. We need stronger authentication than login/password.

I looked at hardware based authentication like RSAsecurity tokens, but
it is not acceptable for us because it is very expensive and we have
multinational user base. I also looked at software based solutions like
Bharosa, that is most suitable for us, but they mostly target finance
institutions and they are expensive.

Please, share your experience with a solution you use to prevent
account hijacking and bot logins, that enhance existing login/password
authenticatoin . Is there any scalable, easy to integrate, pay as you
grow authentication solution for consumer web sites? Thanks for any
feedback.


Similar ThreadsPosted
SSL Server authentication, SSL client authentication, SSL connection and SSL session August 14, 2006, 1:05 pm
WEP authentication, why WEP authentication scheme is flawed and how it can be attacked August 1, 2006, 12:51 pm
IKE authentication June 11, 2004, 8:50 am
P2P Authentication October 25, 2005, 6:42 am
authentication (SRP*, DH, TLS) April 14, 2006, 2:16 pm
authentication September 21, 2006, 5:45 pm
Sign On Authentication August 15, 2005, 7:56 pm
RSA SecurID authentication details July 16, 2004, 12:53 pm
AD authentication via Nortel 450 switch December 21, 2004, 1:17 pm
Question about IKEv2 authentication May 3, 2006, 4:46 pm

The site map in XML format XML site map

Contact Us | Privacy Policy