Vasco, an alternative to RSA SecurID hardware tokens

digipass-go3.jpgAs a security consultant with exposure to many large enterprises I admit I’m biased to RSA SecurID tokens. During penetration tests, our company has cracked tens of thousands of passwords. When I’m standing in front of a customer explaining why their password policies failed, they want to believe that changing this policy will help them. Secretly I know that humans will defeat the spirit of any password policy and that the best approach is to take the responsibility of password composition away from the end user. (When you stare at thousands of clear text passwords you develop a cynicism.)

August2007, you’ve been a good password, but it’s time I move on to owning enterprises with September2007.

The other day a friend asked me if there are any other products like SecurID he should be evaluating for his company as part of their plan to introduce two-factor authentication. Apart from SecurID the only other device that left me thinking “Hey this thing works” is Vasco’s Digipass. Any two factor system worth its weight in salt should provide authentication hooks to the popular services. If you plan to use the solution with custom web applications, you may need to dig a little deeper…maybe a lot deeper. Most solutions have hook-in APIs, but it takes some effort to piece it all together.

If you are evaluating two factor authentication devices make a list of the top services you need authentication for:

  • Network devices
  • Windows authentication
  • Unix authentication
  • VPN users
  • Wireless user authentication

If a solution can cover 80% of your authentication needs and is cost effective, go with it. 80% coverage is 80% better than letting humans pick passwords; chances are with a little effort and creativity you can put something together to rein in the residual 20%. If you don’t have a two-factor solution, evaluate Vasco with the others.

-higB

Digg this

4 Comments so far

  1. Judy Anjowski August 28th, 2007 1:43 pm

    I would suggest you also take a look at http://www.cryptocard.com. When competing head to head against Vasco and RSA, we win 99.9% of the time.

  2. higB August 28th, 2007 7:36 pm

    Cryptocard looks like it has a good solution too.

    Once an organization has all of its humans on two-factor they only have to worry about all those service account and application passwords they can’t change for fear of breaking something. ;)

  3. horse dung November 29th, 2007 1:49 pm

    A new concept is available called Open Authentication tokens (Google for: OATH tokens). Several vendors are already manufacturing and shipping. These are based on open cryptographic standards (which makes some people feel happier) but they are also about a tenth of the cost of RSA SecurID.

    While enterprises no doubt will continue to enjoy RSA’s long history of providing rock solid security there are times when the cost is just too high… even for the Fortune 500 enterprises out there.

  4. Jash Sayani June 26th, 2008 2:29 am

    I tried out both.

    But I say that RSA SecurID is much better!

Leave a reply

the best natural fertilizers pirodr! 666