Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Squantos

SecurID has never been approved on my projects.


9 posted on 05/27/2011 3:33:40 PM PDT by CodeToad (Islam needs to be banned in the US and treated as a criminal enterprise.)
[ Post Reply | Private Reply | To 3 | View Replies ]


To: CodeToad
I know it's an issue of semantics... but to say that they broke in to the network using copied SecureID tokens and the "other" required information is like me stealing your house key and then breaking in to your house. :-)

SecureID is one of those things I've always had misgivings with for high security needs simply because it's "obvious". It's like the wonks I used to work with who would keep STU-III keys on their keyring and they would be viewable "sometimes" when they pulled things out of their pockets at various places. IF somebody knows what the item is for, and they can get the rest of the required information, then the security is defeated.

If you compare this to IPSEC and a shared key, it's a lot more trouble even determining that IPSEC is using a shared key (at least for Phase-I). But SecureID is "visible". Somebody SEES it, and this tells them that the holder has access to information that somebody thinks is worth protecting. SecureID markets their product on the premise of high security, but no SCIF I ever worked in would have ever even permitted the token through the door simply based on what it does. :-)
16 posted on 05/28/2011 6:57:53 AM PDT by hiredhand
[ Post Reply | Private Reply | To 9 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson