Posts Tagged 'SSL VPN'

Barracuda and SMS PASSCODE® introduces two-factor authentication for the Barracuda appliances

The Barracuda NG Firewall now supports SMS Passcode’s advanced two-factor authentication for the Barracuda NG Firewall Network Access Client VPN authentication feature set. Recent high profile exploits have displayed a weakness in more traditional based authentication methods such as one-time-password tokens. The Barracuda post says “Barracuda Networks and SMS Passcode share a common view of providing products that are reliable, easy to use, with a low cost of ownership and provide superior security features that protect the modern, global businesses against future world attacks.” wich is a good way of describing the joint value.

To learn more click here.

SMS PASSCODE to join the F5 Networks Alliances Program

F5 Networks and SMS PASSCODE® have created a joint solution which seamlessly integrates SMS PASSCODE strong authentication into the log-in process of F5 BIG-IP® Access Policy Manager® and FirePass® SSL VPN devices to ensure easy and secure access to corporate resources. We just launched SMS PASSCODE’s participation in the F5 Networks partner program including a webpage and a joint solutions paper posted here.

SMS PASSCODE® 6 provides industry-leading end-to-end cloud authentication and password reset in a cutting edge real-time world

The new SMS PASSCODE version 6 introduces the industry’s first end-to-end cloud authentication solution designed to take advantage of the flexibility and ease of use of cloud services in combination with legacy remote access solutions. Specifically, it includes standardized cloud application protection for applications such as Microsoft Office365, Salesforce and Google apps via the Microsoft Active Directory Federation Services version 2.0, It includes support for global real-time delivery via SMS, voice or secure e-mail also as a cloud service and finally, it supports any SMS PASSCODE server to be deployed in any private or public cloud configuration. The release completes our  end-to-end cloud support, which has been a platform evolution strategy, where the SMS PASSCODE version 3 enabled cloud-distribution of the individual components such that it could be deployed on the fly to both public and private cloud services  This continued in Version 4 with our website protection and in Version 5 with our support for cloud delivery via Telesign and cloud key token co-existance support. To learn more click here.

Networkcomputing nominates SMS PASSCODE for ComputingSecurity Awards 2011 in two categories

Network  Computing and ComputingSecurity has announced that SMS PASSCODE® has become a finalist in two different categories for the Computing Security Awards 2011. The nomination is driven out of the technology leadership in real-time global two-factor authentication that the latest SMS PASSCODE version 5 represent via the real-time global platform that enables a real time login session specific code to be delivered either as SMS, voice call or secure e-mail.

The two categories are:
Identity and Access Management Solution of the year for SMS Passcode
> SME Security Solution of the year for SMS Passcode

You can learn more about SMS PASSCODE at www.smspasscode.com/product. To learn more about the Computing Security Awards, please click here.

90% of surveyed companies experienced a successful breach according to research

In a recently released report conducted for Juniper Networks by the Ponemon Institute, it is revealed that 90% of the hundreds of companies surveyed in the report successfully had their networks breached.  Furthermore, the data shows that the most exposed category of breaches was remote workforce access.  This further validates that protection of remote workforce access against modern hacking technologies yields a high return in terms of impacting the major area of hacker risks. You can learn more about this survey here. © Ponemon Institute and Juniper Networks.

SMS PASSCODE®’s real-time modern solution now available with global token trade-in offer

Before we talk about our reasoning behind the token trade-in program, the recent events publicly announced by a leading token technology vendor including the need to replace tokens is not for us to comment on except the point that it is unfortunate when any security technology is compromised as it brings customers at risk and we are sorry for that.

However, I think it cannot come as a surprise to many of us that a 20+ year old technology like the token has come under pressure from modern threats on the internet and a level of information sharing and a remedy plan on our behalf is obligated here. We believe there has been a lot of innovation in those 20 years, where we are recognized as one of them with a new generation more modern technology that has on the market for a while now and is a proven alternative.

The announced plans to replace tokens cannot only be good news to customers as they are exposed today and the physical replacement of tokens has a time delay and an administration cost often as high as the procurement price itself associated to it. Especially for the SMB and mid-market customers, where we have seen significant adoption, this appear a bigger issue than often anticipated.

We view the  recent events as sad, but also as validation points for our statement on the 20+ year old token technology. Allow us to use it as basis for us to maybe better and more objectively articulate what we mean, when we talk about the difference between the first generation pre-determined token code technology used by token and most SMS based two-factor technologies, and our new modern second generation more secure real-time technology. These first generation technologies have different ways by which they in advance generate a code or list of codes that is valid for a period of time or until used. If this basis technology that is used to pre-deterministic generate the code or list of codes ends in the wrong hands as seen, the ill-intended can get the codes.

Unlike these technologies, we are recognized for having a second generation more secure modern log-in process, where we first validate user ID and password, before we generate and send in real-time a code that is only valid for that log-in attempt (session). It is all happening in real-time. Thus, the code is not pre-determined and thus is not exposed to the type of hacking seen recently. We can do this as we have build a reliable and scalable platform designed specifically for real-time code generation and global delivery via SMS Text Messaging, voice or secure e-mail to any phone. We do this with an unrivaled level of load-balancing, redundancy and alternate code delivery capabilities. Instead of making a trade-off towards a 20 year old less secure pre-deterministic technology like everybody else driven by the belief that the code could not be delivered reliably real-time, we have designed a system that has the capabilities to do just that much more reliably than any physical technology that is perceived to be more available but is not as it is often misplaced, out-of-order or expired. **

In addition to being more secure, SMS PASSCODE® also do not require physical distribution of devices and thus according to our customer driven TCO calculations, it cost less than half that of regular tokens when compared over a project period of 3-4 years.

Global trade-in program

While the removal of token distribution hassles makes it practically free for customers to migrate to SMS PASSCODE®, to entice customers to reconsider avoiding the hurdles to replace tokens, we today launched a global campaign offering customers a financial incentive in the shape of trade-in discount for any valid token, when augmenting existing two-factor token technologies with SMS PASSSCODE ®.  SMS PASSCODE® comes out of the box with support for co-existence to both regular tokens as well as more modern SaaS based token technologies for easy migration.  This enables customers to immediately increase security at lower cost than the token replacement alternative by implementing SMS PASSCODE® side-by-side to the existing token technology and migrate users on a need-to basis fitting your preferred time schedule.  The program, available in select markets through the third calendar quarter of 2011, offers a discount on the procurement of SMS PASSCODE ®  when it replaces a valid token. The trade-in discounts are set on a regional level.

To learn more about the details and the discounts, contact our distributor in your territory listed at www.smspasscode.com or contact us at our web form. You may also call me directly here: Lars Nielsen, phone +45 21 26 81 98.

** The likelihood a SMS PASSCODE user has to call the help desk to gain access is significant less than a physical token system as the misplacement and error rates are much higher than the likelihood a user cannot get a text, voice call or secure e-mail.

New SMS PASSCODE® program for concerned token users provide upgrade to SMS via easy co-existence

First there were the Zeus malware designed specifically to compromise tokens using pre-issued either ‘time-based’ or ‘until used’ codes. Now a leading token manufacturer has had a recent online break-in that has caused concerns. Everybody knows that these threats is something that can cause concerns in corporations resulting in work and efforts to re-evaluate security.  To increase security quickly during such security reviews or to augment existing solutions with the secure SMS PASSCODE two-factor authentication via SMS solution, we today announced a new co-existence program enabling legacy two-factor authentication customers that are concerned with modern internet threats to migrate smoothly to SMS PASSCODE at their own pace. Both last years Zeus malware and the recent online break-in has put the core concept of the traditional tokens ‘pre-issued’ codes under pressure.

However, these threats against legacy two-factor authentication technologies also help demonstrate the subtle but very important difference between these and new generation solutions like SMS PASSCODE®, where the code is generated and send in real time based on the individual login session and thus cannot be phished and re-used or calculated in advance.

It is natural that corporations are hesitant to make major changes to the existing security infrastructure over night. Therefore, when unforeseen threats like above arrive, it is often a desire to have a rapid response that do not require major rework. SMS PASSCODE® responds to this need with the support of a co-existence configuration in which customers can run a legacy token system and SMS PASSCODE side-by-side during a migration and architecture decision process. It solves the immediate security threat pain without a major effort.

How do SMS PASSCODE co-exist with tokens

With SMS PASSCODE, the user first validates user ID and password and it is not until that has been validated that it generates and sends a code in real-time that is only valid for that log-in session. This is more secure than any other alternative on the market. SMS PASSCODE has garnered international recognition for this more secure log-in process with many awards including Secure Computing Top 5 global innovator, Citrix Ready Partner of the year finalist, White Bull Top 30 IT company and most recently the Red Herring Global 100 most interesting IT companies.

When customers run SMS PASSCODE and a legacy token system side-by-side, SMS PASSCODE will forward users that enter the token code on to the token system while the rest are prompted to enter a SMS PASSCODE. It is done very transparent and very easy to deploy.

The SMS PASSCODE co-existence configuration is a proven configuration that is part of the standard product and come at no extra cost. As customers migrate legacy tokens, the program offers trade-in options on a case-by-case basis. Please visit www.smspasscode.com to find our local representative or to request more information. To learn more about SMS PASSCODE or try it out live on your own mobile phone, visit: https://demo.smspasscode.com

The World leading Danish Crown meat processing firm chooses SMS PASSCODE® for remote access

This week, we announced that the world leading Danish Crown meat processing firm with more than 23,000 employees have standardized on SMS PASSCODE for secure employee remote access. At Danish Crown, the online threats drove a comprehensive security review including review of alternative methods of protection. This review resulted in the company choosing the SMS PASSCODE solution which has been recognized and awarded as a new generation of two-factor authentication solutions based on SMS.  Briefly explained, SMS PASSCODE first authenticates user ID and password. Once validated, the system creates and sends in real-time a code only valid for that particular user log-in session.

“There are three primary reason for selecting SMS PASSCODE and not a more traditional token approach. First, we save about 30% alone on eliminating hardware purchases as all users today carry a mobile phone. Secondly, the administration burden of our approximately 1.750 users with SMS PASSOCDE is less than that of about 20 traditional token users. Thirdly, it is a very straight forward solution that fully cover our needs” says Soren Sloth, and explains that all employees in Danish Crown has been very positive and receptive to using the solution.

“They think it is brilliant, as they always carry the key to the network in their hand. This has increased the employee efficiency at Danish Crown considerably. It makes it much faster and easier to log on and get to work”

You can learn more about the news and the solution here.

New demonstration of Microsoft ISA / TMG protection released

In our series of client demonstrations, today we launched a demonstration of the Microsoft ISA / TMG (Threat Management Gateway) client used to protect a website resource. The ISA/TMG client support was among the clients released in the latest SMS PASSCODE® version 4 – the technology leading two-factor SMS Authentication solution.

You can see the demonstration video here.

OpenVPN strong authentication with SMS PASSCODE®

Hot off the press is a new authentication client demonstration showing OpenVPN two-factor authentication using SMS authentication. This video demonstration shows once more the seamless integration the technology leading SMS PASSCODE® two-factor SMS authentication solution and how it works as an integral component in all the leading login client systems.

You can see the demonstration video here.

Next Page »



Follow

Get every new post delivered to your Inbox.