Enterprise Password Management System

Archive for identity theft

Access Smart Shows Cyber Access at ISC West 2013

Cyber and Physical Access on One Card

Visit us at the Ingersoll Rand Booth #20029

Security experts agree that multi-factor authentication is the best way to safeguard against cyber attacks. Now businesses, agencies and institutions can secure the two most important front doors: The building and the computer network. Access Smart delivers a very extensive product offering where employees will no longer have to remember, type or know their computer passwords. Cyber security begins with network access authentication, and network access authentication begins with Power LogOn.

Access Smart will be demoing Power LogOn – Cyber Access Control work with aptiQ physical access in Ingersoll Rand’s booth #20029 at ISC West 2013 in Las Vegas. Click here to read our Data Sheet “Cyber and Physical Access Control – One Card

 Cyber Access Control

Chicken Little Warns About Network Access Authentication

Network Access Authentication

Copyright: Walt Disney Productions

USB Smart Card Readers for Network Access Authentication are Still Safe.

A number of online computer news sites are abuzz about a security team’s prototype malware that hijacks USB smart card readers. It seems that a research team out of Luxembourg has issues a “Proof-of-Concept” malware attack that can take over your USB smart card reader. While any malware notice is important and needs to be monitored, business may be wondering the severity of the attack and if they need to rip out their smart card infrastructure because their network access authentication is in jeopardy.

Here are my thoughts:

  1. This is only a proof-of-concept and not a deployed attack.
  2. Every piece of computer hardware and software are susceptible to malware.
  3. Security relies on many barriers and layers. If you’re vulnerable to one attack you probably are vulnerable to many others.
  4. If the computer is vulnerable to malware, then other more dangerous programs will more likely be installed like key loggers or the Zeus Trojan Horse. In that case there is probably no need to attack the smart card since these other programs are far more destructive.

Conclusion:

Companies don’t need to rip out all their smart card readers and replace them with the expensive keypad ones. Smart card reader companies will look into the potential malware vulnerability and make whatever driver modifications necessary. IT needs to keep an eye out for any driver updates and install them.

Finally, security has many levels and points of attacks. If you are concerned about your company’s vulnerability then contact a consultant and ask for a security assessment. We list some leading companies on our site under the partners tab.

Ingersoll Rand Partners with Access Smart for Cyber Security

Ingersoll Rand Security Technologies / Access Smart Provide Cyber Security with Smart Cards

Affordable, smartcard based, enterprise password manager for Windows solution for network access authentication

cyber security begins with network access authenticationCARMEL, Ind – Sept. 6, 2012 – Ingersoll Rand Security Technologies, a leading global provider of security and safety solutions and manufacturer of contactless smart credentials and readers, announced that its aptiQ™ smart card users can now deploy the Access Smart® Power LogOn® as their password manager for Windows. No longer will employees have to self-manage their passwords, a practice which can easily lead to an expensive company security breach.

     “When employees self-manage their passwords, the network access authentication becomes very insecure. Passwords are written down, simple passwords are used and the same password is used for multiple sites and applications,” explains Dovell Bonnett, Access Smart founder and CEO. “IT administrators using Power LogOn in combination with aptiQ smart cards can now easily add secure network access authentication. Businesses of all sizes must comply with state and federal privacy protection laws and cyber criminals are aggressively targeting businesses. Power LogOn securely authenticates a user before they are allowed past the firewall.” Read More→

Employees Are Not Evil…

They Are Just Drawn That Way

PData security begins with network access authentication of employeesaraphrasing a line from Jessica Rabbit from the movie Roger Rabbit seems the appropriate comment from Geoffrey A. Fowler’s article “What’s a Company’s Biggest Security Risk? You.” Hence the headline: Employees Are Not Evil – They Are Just Drawn That Way. It is critical that employers be diligent in training their employees in online safety.

When your employees are online they are opening the door to danger. Be it opening phishing email attachments, writing passwords on sticky notes, plugging in USB drives found in the parking lot, using personal devices to access the company’s network, of hundreds of other social engineering attacks, data is the new currency of the internet age. And if it has value, there will always be someone wanting to steal it. Read More→

Large Password and User Names Heist

8.24 Million Passwords and User Names stolen and posted by hackers.

Data SecurityIf you use the online gaming site Gamigo, if your user name was your email address and you use the same password elsewhere then you need to be very, very concerned.  Cyber criminals will now start scouring the important networks and sites with your user name and passwords to your steal money, buy goods and change your settings.

While security pundits will tell you that you need strong passwords, every site should have different passwords and change passwords periodically, I’m going to tell you a few things they typically don’t.

  1. Get a secure password manager solution so you don’t have to remember or type passwords again. Not all password managers are secure.
  2. Don’t make your user name your email address and have bogus emails if the site requires one.
  3. Don’t use the same user name everywhere either. Make it gibberish too.
  4. Many of the little tricks about remembering passwords are stupid and don’t work. They are designed only to make you think you have security.
  5. Don’t save passwords in your browser. Read More→

Company’s Identity Theft Worries Elevate to Cyber Crime

Cyber Crime Protection – Evaluate and Segment Data

Data SecurityIt only seemed like yesterday that when business owners were asked about network security their focus was on identity theft protection and/or compliance with the different state and federal privacy laws. Those concerns are now elevating to the more destructive and finacially devistating risks of cyber crimes. At the beginning of this year I wrote a blog about how I was advancing my security skills from identity theft protecter to cyber warrior. I even posted a chapter-by-chapter review of the book “Cyber Warfare”, by Jason Andress and Steve Winterfeld. It doesn’t mater what industry your in, the size of your company , or the complexity of your computer network because if you can be found on Google, Bing, Yahoo, LinkedIn, FaceBook, Twitter, etc.then your business is at risk. All you can do now is limit your exposure and midigate the damages.

Here is a recent article on how cyber crime is targeting companies.

A Risk-Based Approach to Combating Cyber Crime

—by Rich Baich, principal, and Peter Makohon, senior manager, Deloitte & Touche LLP and leaders of the Deloitte Center for Security & Privacy Solutions. Read More→

Password Manager for Windows in Africa

Access Smart Announces a New Password Manager for Windows Reseller in Africa

enterprise password managerAccess Smart® is pleased to announce a new Power LogOn - Password Manager for Windows – reseller in Africa. Pure Access IT, LTD, located in Abuja, Nigeria, is adding password manager for Windows to their extensive line of IT services. The addition of Power LogOn provides Pure Access IT customers with a complete secure network solution.

With data breaches and identity theft at epidemic levels, businesses and government agencies need network access authentication to identify a person prior to them getting past the firewall. Passwords are the most common way people use to log onto a computer, network and internet; but, the way individuals choose, use and manage their passwords makes them vulnerable to attack. Power LogOn delivers a secure means to manage passwords with multi-factor authentication, plus user convenience  of never having to remember, type or know their passwords. Power LogOn can also be tied in to Active Directory to keep IT as the central manager of access rights and privileges.

“Secure user authentication should never be a luxury and never a barrier to preventing cyber-attacks,” said Dovell Bonnett, Founder and CEO of Access Smart. “We are so pleased to have Pure Access IT as a strong partner.”

Pure Access IT Ltd is a multi-disciplined information technology integrator that offers IT solutions, training as well as expert implementation of the best technologies for website architecture and design, data access, transactions, Internet Service provision and information security. We work with leading companies to deliver to government and businesses at the highest level of technology, integration, and services. Pure Access is also engaged in the provision of software outsourcing services. Today hundreds of small and medium sized businesses including Government rely on the superior technical expertise of the Pure Access Team to support their Systems, network infrastructures, and to provide the necessary support to keep their businesses running.

“Access Smart adds those additional layers of security, low cost of ownership and user convenience needed to authenticate the user,” said Wasiu Olatundun, CEO of Pure Access IT.

Please contact Access Smart or Pure Access IT for more information.

 

Google may be doing Harm

Google is gathering your personal and corporate data.

Cloud security Google Inc. (GOOG) motto is, “do no harm.” But who defines what is harmful? Employees recently testified to the U.S. Federal Communications Commission that they didn’t initially know that their mapping-service project software was gather personal data, even though an undisclosed engineer told a few fellow workers. The software would access payload data like e-mails, text messages, passwords, internet-usage, and other highly sensitive personal information. The FCC ended up not penalizing Google for data gathering, but assessed a $25,000 fine for not cooperating with the FCC during the initial inquiry. The fine would not even be considered a slap on the wrist. Read More→

Cyber Warfare: Chapter 5

Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners by J. Andress and S. Winterfeld

Cyber warfare is real. That’s why each Friday I will post a review on this book: Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners, and today I am sharing what I am reading in…

Chapter 5: Logical Weapons.Cyber Warfare Techniques Tactics and Tools for Security Practitioners - Book review by Dovell Bonnett of Access Smart.com

This chapter is chocked full of valuable information. Instead of going through the details of all the tools discussed, I think that startling insight into the defense of these attack tools is more important. I do, however, strongly suggest your read this chapter to get a better perspective on the types and capabilities of the available logical access weapons.

The weapons or tools available to cyber warriors are vast and many are free and open sourced. The non-government and non-military attackers are using common or customized tools. At times the same tools used to investigate an attack are also the same tools used to attack. While many may believe that the government and military warriors have highly specialized tools, the authors suggest that they are using some of the same commercially available tools.

Read More→

Network Access Authentication with MagStripe Cards

Network Access Authentication using a Magnetic Stripe Card

network access authenticationAccess Smart®, LLC expands our network access authentication product line for data security. Power LogOn for MagStripe allows any issued magnetic stripe card to be used to log onto a computer and network. Imagine the cost savings and convenience of not having to re-issue cards, and the convenience for customers to use their existing loyalty card for network access authentication into a computer network. Some of the key markets are hotel lobby and airport kiosks, internet cafes Read More→