pen-test
[Top] [All Lists]

RE: Hardware/software secureIDs - pros and cons.

To: <eladexposed@gmail.com>, <pen-test@securityfocus.com>
Subject: RE: Hardware/software secureIDs - pros and cons.
From: "David M. Zendzian" <dmz@dmzs.com>
Date: Fri, 29 Jun 2007 09:43:10 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Importance: normal
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
Resent-date: Fri, 29 Jun 2007 09:49:26 -0600 (MDT)
Resent-from: pen-test-return-1078484506@securityfocus.com
Resent-message-id: <20070629154926.55D3E2B5E5B@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
I think they are great tools. You may want to check out cryptocard. They are 
much less expensive ($500 gets you 5 tokens and server license for primary and 
failover servers), they have lots of hard and soft tokens and hard tokens never 
expire and can have batteries  easily changed. One other nice feature is you 
can set it to generate a new token with every button press vs waiting 30 to 60 
sec for new number...which is fun when needing to sign on to many servers at 
once (nothing like taking 6 to 10 min to get on servers during an outage.

Good luck
David


-----Original Message-----
From: eladexposed@gmail.com
To: pen-test@securityfocus.com
Sent: 6/28/07 9:26 AM
Subject: Hardware/software secureIDs - pros and cons.

Hello, What are the pros and cons for using hardware RSA SecureID/Other and 
software with the same characteristics?   For example: 
http://www.rsa.com/node.aspx?id=1313  Let's say there's a company that allow 
only customers using the hardware SecureID to connect its resources -  What 
might be the main arguments the company has to prefer the hardware and not the 
software?  From the customer's point of view it's better to have software 
installed (management, holding of multiple tokens, user usage etc)   Kind 
Regards, Elad Shapira ("Zest")  "Security, however, is an art, not a science." 
- RFC 3631 
------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/wf-spi
------------------------------------------------------------------------




------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/wf-spi
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>