pen-test
[Top] [All Lists]

Re: Hardware/software secureIDs - pros and cons.

To: "eladexposed@gmail.com" <eladexposed@gmail.com>
Subject: Re: Hardware/software secureIDs - pros and cons.
From: AdityaK <aditya1010@gmail.com>
Date: Fri, 29 Jun 2007 21:52:38 +0530
Cc: pen-test@securityfocus.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: pentest-list2@consult.net
Delivered-to: mailing list pen-test@securityfocus.com
Delivered-to: moderator for pen-test@securityfocus.com
Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=uI/hs8qZqRF3JoFNH0Or8cxdOzoQMqmFY5U2K7sAVEhaI/wN0iui4FejTjCvxxlXM4VC3Fm2u73vas4edS3hX/WSWR51ULJSjzT6ZMrmmszOFTBFFSQH9zy4HC37Nc6H/aKn6Ae27DRCTlWM5ohXDMvU1Jsll53zf+iKSuN4Pwo=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=fl7L7P33Kld6+CKGJUXuRKBfZa5LhD0oipfPB5RBCkR1cI+pcRc9m621MHDvq9+AU/sN+exmrmNQBuI7pNgVTlbqVuKdLcoRsLAX+kvryd9Zc2FJJSqQX1d/QnPjE+PnzxSRkt0yUTnw2+ybFt6N8Npuw8d3zallJmtE/jyYI1g=
In-reply-to: <20070628132640.17426.qmail@securityfocus.com>
List-help: <mailto:pen-test-help@securityfocus.com>
List-id: <pen-test.list-id.securityfocus.com>
List-post: <mailto:pen-test@securityfocus.com>
List-subscribe: <mailto:pen-test-subscribe@securityfocus.com>
List-unsubscribe: <mailto:pen-test-unsubscribe@securityfocus.com>
Mailing-list: contact pen-test-help@securityfocus.com; run by ezmlm
References: <20070628132640.17426.qmail@securityfocus.com>
Resent-date: Fri, 29 Jun 2007 10:15:20 -0600 (MDT)
Resent-from: pen-test-return-1078484509@securityfocus.com
Resent-message-id: <20070629161520.DA9052372AB@outgoing3.securityfocus.com>
Resent-sender: listbounce@securityfocus.com
Sender: listbounce@securityfocus.com
Hi
Pros of Using a Hardware Token:
-Extracting shared key through reverse engg is not as  easy and
involves higher cost compared to soft tokens.
-Works  on different OS,Environments and no headache of downlaoding
,reinstalling.
-Operating life is higher for hardware token
-If tied well with CAP/DAP can be used for different services

Regards
Aditya.K
Researcher


On 28 Jun 2007 13:26:40 -0000, eladexposed@gmail.com
<eladexposed@gmail.com> wrote:
Hello,

What are the pros and cons for using hardware RSA SecureID/Other and software 
with the same characteristics?


For example:

http://www.rsa.com/node.aspx?id=1313


Let's say there's a company that allow only customers using the hardware 
SecureID to connect its resources -

What might be the main arguments the company has to prefer the hardware and not 
the software?

From the customer's point of view it's better to have software installed 
(management, holding of multiple tokens, user usage etc)



Kind Regards,

Elad Shapira ("Zest")


"Security, however, is an art, not a science." - RFC 3631


------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/wf-spi
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Swap Out your SPI or Watchfire app sec solution for
Cenzic's robust, accurate risk assessment and management
solution FREE - limited Time Offer

http://www.cenzic.com/wf-spi
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>