Enterprise Password Management System

Archive for password management

Password security done right by LivingSocial

Accept it; cyber-attacks are happening to your company too. 

passwordYou may have seen in the news that LivingSocial recently experienced a cyber-attack where 50 million customers’ name, email address and password were exposed.  While that news typically makes the headlines, what is not being emphasized is everything that LivingSocial did right to safeguard their customer’s personal data.

 

Accept it; cyber-attacks are happening to your company too.  The hacker’s strategy is to prey on the psychology of employees.  Spear phishing, watering hole attacks, social media and poisoned SEO sites s are just some of the weapons of choice.  According to Symantec, businesses in 2012 with 2,500 or fewer employees were the targets of 50 percent of the attacks, and those businesses with fewer than 250 employees accounted for 31 percent of the attacks.  Here are some other 2012 statistics to confirm the statement that, “there are two types of businesses, those that have been hacked and those that don’t know it yet:” Read More→

Are your customers asking you for a Logical Access Solution?

Looking for a Logical Access Partner to handle all the IT concerns?

Logical AccessWe had a great presence at the ISC West 2013 conference in Las Vegas.  One recurring theme we heard from ID resellers was their desire to offer their existing customers a value add, card based, logical access solution for network security. 

I want to help you secure these new logical access business opportunities.

Companies, healthcare and government agencies are looking for multifactor cyber access control because of the increase in data breaches, implementation of privacy laws like HITECH, HIPPA and CJIS, and their overall concern for network security.  Our Power LogOn cyber access control allows you to add logical access to almost any type of ID badge your currently sell. And best of all, it only takes a few hours to install.

Access Smart wants to be your IT security partner.  It is our policy to work with you so you can offer your customers a multi-factor cyber access control solution.  Here is my promise to you:

     1.  You retain full ownership of your customer.

     2.  You will be a reseller of our Power LogOn.

     3.  We will assist you and your customer on all IT integration, training and support.

Logical access control does not need to be scary, cumbersome, or expensive when you have a partner with 20-years of industry experience.  If you are interested in expanding your business, up selling your existing customers and increasing revenue at no risk to your business, then please call me to learn more.

Data security begins with cyber access control. Cyber access control begins with Power LogOn.

 

Keep up with Cyber Access Control by subscribing to our blog headlines.

Best regards,

Dovell Bonnett
Founder and CEO
Access Smart, LLC
E: Dovell@access-smart.com
W: www.access-smart.com
P: 949-218-8754

Access Smart Shows Cyber Access at ISC West 2013

Cyber and Physical Access on One Card

Visit us at the Ingersoll Rand Booth #20029

Security experts agree that multi-factor authentication is the best way to safeguard against cyber attacks. Now businesses, agencies and institutions can secure the two most important front doors: The building and the computer network. Access Smart delivers a very extensive product offering where employees will no longer have to remember, type or know their computer passwords. Cyber security begins with network access authentication, and network access authentication begins with Power LogOn.

Access Smart will be demoing Power LogOn – Cyber Access Control work with aptiQ physical access in Ingersoll Rand’s booth #20029 at ISC West 2013 in Las Vegas. Click here to read our Data Sheet “Cyber and Physical Access Control – One Card

 Cyber Access Control

Power LogOn – Two Cybersecurity Modes

cybersecurity Mutifactor AuthenticationMultifactor Authentication Cybersecurity

Power LogOn offers IT the flexibility to determine how best to implement multifactor authentication cybersecurity. It has always been Access Smart’s belief that Power LogOn should allow custom configurations to meet a company’s security policy, and not force a company to change their security policy because of a product’s limitations.

Power LogOn can operate in either On-Card Mode or Server Mode. This flexibility allows Power LogOn to be installed in a small office to a large multi-international corporation. It’s the same product. So as a company grows they can use the same Power LogOn software to migrate from one mode to another.

I just finished our latest video on Power LogOn Administrator On-Card Mode. In this video you will understand where On-Card Mode is best placed. Please watch the video and contact us if you would like to know how Power LogOn best works in your business.

Link to Video

 

HITECT MultiFactor Authentication for McKesson HIS

Multifactor Authentication required by HIPPA & HITECH

Multifactor authenticationAccess Smart® adds multifactor authentication to McKesson’s Paragon Hospital Information System (HIS) software. Access Smart’s Power LogOn® application requires no modifications to the Paragon software so integration is fast and easy. With Power LogOn, hospitals, clinics and other health-care providers can now address their HIPAA and HITECH compliance concerns while protecting patient’s private records. “You can’t have the health-care reform act without electronic health records,” says Judy Hanover, a health-care technology industry analyst at IDC. True, but you can’t have privacy without first authenticating who is accessing your electronic health records.

Access Smart analyzed the Paragon HIS software and quickly updated Power LogOn to now auto-launch Paragon, auto fill-in the user name and password fields, and auto shutdown Paragon when the smart card is removed. Furthermore, Power LogOn ties into Active Directory so virtually any computer, network, internet site, cloud and application that requires a user name and password can easily be secured by the same smartcard. Power LogOn can also be added to RFID access control cards for a single card solution. Read More→

HIPAA Healthcare Data Breach Fines Climb

HIPAA Healthcare Data Breach Fines Climb With Enforcement Boost

Re-Post By Robert Westervelt, CRN 1:48 PM EST Tue. Jan. 08, 2013

HIPAA Healthcare pays millionsMillions of dollars in fines associated with alleged violations of the Health Insurance Portability and Accountability Act have been doled out over the last six months, a sign, according to experts, that HIPAA enforcement is shedding light on the fact that the industry lags behind others when it comes to information security.

Healthcare organizations in Massachusetts and Idaho are the latest to agree to the fines for failing to protect sensitive patient data under the Health Insurance Portability and Accountability Act.

The former owners of a medical billing practice in Massachusetts and four pathology groups agreed to pay $140,000 for improperly disposing of medical records. The names, Social Security numbers and medical diagnoses of 67,000 patients were discovered in documents at a town waste transfer station. Read More→

Cyber Authentication – Google Weak on Password Management Systems

When it comes to cyber authentication, the weakest link is the user.

Cyber authenticationCyber authentication is a hot topic in today’s world of Malware, Cyber Warfare, BYOD, Cloud Computing and Hackers. In a recent Google Password Management blog, “Google Password Management Tips To Increase The Security Of Your Accounts” they asked if your Gmail account is safe. They then give seven tips on how to improve password security. These tips, while basically correct, are so old and have been said ever since the first password was issued that they fail to address the real problem: the human element.

We all know the problems with passwords: there are to many, they need to be complex, IT makes you change them every 90-days, and we can’t remember them all. These Google tips should also be classified as: Policy, Technique, or Management. Security typically is weaker when people are expected to securely “manage” the  ”techniques.” Finally, even if you followed all these Google tips you still will be vulnerable because of the password cracking tools and attacks being used. While some are saying that password security is dead. I full disagree since passwords are one of the fundamental cyber authentication methods. So let’s review these tip. Read More→

Dovell’s Three Laws of Computers

Network Access Authentication is essential to the Laws of Computers

Laws of Computers

The concept of mechanical devices that will do manual and menial labor can be traced back to Ancient Greece. Whether it’s an automaton by Hephaestus or Honda’s Asimo robot, they all have something in common, a human-written program that controls the machine’s behaviors and actions. In a 1942 short story “Runaround,” Isaac Asimov first introduced the “Three Laws of Robotics” that is accepted as gospel among roboticists. As recently as 2011, the Engineering and Physical Sciences Research Council (EPRSC) and the Arts and Humanities Research Council (AHRC) of Great Britain jointly published a set of five ethical “principles for designers, builders and users of robots” that built off of Asimov’s laws. But what is a robot?

Robots are basically computers with mechanical appendages that give them some form of mobility. There seems to be no consensus on which machines actually qualify as a robot, but many designs seem to mimic humans or animals. While Isaac thought it necessary to write laws for a fictitious device and the EPRSC published their five laws, the “brain” controlling robots is left to total anarchy: The Computer. There needs to be Three Laws of Computers.

Computers, unlike robots, are all around us. They help in cooking our food, powering our homes, communicating around the world, and traveling to the far reaches of space. Young kids today are more adept with a mouse than a pencil. Computers are being used for good things like producing clean drinking water to terrible things like spinning uranium to create nuclear weapons. With all its uses, it seems odd that the founders of the computer age – Charles Babbage,  Calvin Gotlieb, Michael Dell, Tom Watson, Steve Jobs, Bill Gates, Dr. Wang, Hewlett or Packard to name a few – never saw the need to write any Laws of Computers.

If robots are just mechanical extensions of computers, and a computer controls the robot’s actions, movements and tasks, then before one has laws on robotics shouldn’t there first be laws governing computers? Therefore, I have taken it upon myself to publish:

Dovell’s Three Laws of Computers.

 Law #1: Computers must not, or allow other computers to, harm humans or other sentient life forms as they complete their series of commands (program) given to it.

 Law #2: Computers must first positively authenticate the user, determine that user’s rights and privileges, and leave an accountability record before executing its programs.

 Law #3: Computers must automatically learn, configure and remember how each human wants it to behave and then instantly recall that configuration every time that human accesses it.

Read More→

Physical and Logical Access Control

Physical and Logical Access ControlUsing the Same Security Products!

Ingersoll Rand Security Technologies provides high-quality reader and credential products to customers in both the physical and logical access control markets.  All Ingersoll Rand readers and credentials are built on open standards, making it easy to combine physical and logical access applications, like Access Smart’s Power LogOn® solutions, along with a variety of other applications.

 

CREDENTIALS

Ingersoll Rand manufactures traditional 125 kHz proximity credentials, 13.56 MHz MIFARE® and aptiQ™ using MIFARE DESFire™ EV1 smart credentials, and multi-technology credentials.  These credentials are offered in a variety of form factors, including ISO-style cards, clamshell cards, key fobs, and PVC patches.

 

READERS

aptiQ smart and multi-technology readers and XceedID proximity readers provide for any facility’s needs.  As the pioneers in multi-technology reader development,  Ingersoll Rand is making it affordable for any company to migrate to smart  technology.

Find out more at securitytechnologies.ingersollrand.com, or talk to a sales representative at 1-855-248-0302.

Exporting Power LogOn

Network Access AuthenticationAccess Smart received their ECCN classification determination number today from the US Dept. of Commerce. We are classified as a 5D992b Information Security Software product which allows Access Smart to ship our Power LogOn software and licenses internationally.

Under this classification, no additional export documentation is required. Purchases can be made and shipped though the internet.

“We are very pleased to receive this classification since it allows our international customers faster and simpler fulfilment “, said Dovell Bonnett, Founder and CEO of Access Smart.

Please contact Access Smart for a no obligation consultation on how best to implement Authentication, Authorization and Non-Repudiation into your business. Access Smart – The Alternative to PKI.

“The first line of defense is authenticating who’s knocking on your network’s ‘front door’. That’s why data security begins with network access authentication, and network access authentication begins with Power LogOn.” – Dovell Bonnett, Founder and CEO of Access Smart