<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecureAuth Blog</title>
	<atom:link href="http://blog.gosecureauth.com/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.gosecureauth.com</link>
	<description>SecureAuth Blog</description>
	<lastBuildDate>Wed, 22 Feb 2012 19:00:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>The Cloud Makes it: &#8220;The 4 A&#8217;s of Authentication&#8221;&#8230;</title>
		<link>http://blog.gosecureauth.com/blog/the-4-as-of-authentication</link>
		<comments>http://blog.gosecureauth.com/blog/the-4-as-of-authentication#comments</comments>
		<pubDate>Tue, 21 Feb 2012 02:55:32 +0000</pubDate>
		<dc:creator>Garret</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2568</guid>
		<description><![CDATA[Your standard IT engineer involved in authentication &#8211; could easily recite the &#8220;3 A&#8217;s of Authentication&#8220;: Authentication Authorization Auditing But the 3 A&#8217;s were designed for the 1990&#8242;s &#8211;  e.g. &#8211; when all the resources were internal &#8211; and a gateway device was placed in front of these resouces for 1-stop authentication. The standard for [...]]]></description>
			<content:encoded><![CDATA[<div>Your standard IT engineer involved in authentication &#8211; could easily recite the &#8220;<a href="http://en.wikipedia.org/wiki/Authentication">3 A&#8217;s of Authentication</a>&#8220;:</div>
</p>
<ol>
<li>
<h4><strong>Authentication</strong></h4>
</li>
<li>
<h4><strong>Authorization</strong></h4>
</li>
<li>
<h4><strong>Auditing</strong></h4>
</li>
</ol>
<div>But the 3 A&#8217;s were designed for the 1990&#8242;s &#8211;  e.g. &#8211; when all the resources were internal &#8211; and a gateway device was placed in front of these resouces for 1-stop authentication.</div>
</p>
<div>The standard for AAA authentication was the  RADIUS protocol.   RADIUS allowed the gateways to generically pass collected authenitcation information to the RADIUS-compliant auth server.  (See <strong>Image #1</strong>.)</div>
</p>
<div><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/Traditional_Radius_Architecture.jpg"><img class="size-full wp-image-2569 alignleft" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/Traditional_Radius_Architecture.jpg" alt="" width="622" height="226" /></a></div>
<div><strong>Image #1</strong>:  Traditional AAA authentication, RADIUS, collects static information from the gateway and then passes the creds via UDP to the RADIUS Server.</div>
</p>
<h3>Problems with standard AAA (RADIUS) authentication:</h3>
<div style="padding-left: 30px">
<h4>1.  Limits enterprises to supported workflow and static data content</h4>
</div>
<ul>
<li>No flexibility in workflow</li>
<li>Restricts enterprise to out-dated authentication methods (SecurID, tokens, etc.)</li>
</ul>
<div style="padding-left: 30px">
<h4>2.  No support for new Cloud Applications</h4>
</div>
<ul>
<li>No way to pass identity to SaaS / PaaS providers</li>
<li>SaaS providers do NOT support RADIUS  (Seem image #2)</li>
</ul>
<div><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/Cloud_Radius_Architecture.jpg"><img class="alignleft size-large wp-image-2580" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/Cloud_Radius_Architecture-1024x586.jpg" alt="" width="573" height="328" /></a></div>
<div><strong>Image #2:</strong> Standard AAA authentication, e.g. RADIUS, provides no support for the exploding world of cloud apps.</div>
</p>
<h3>The 4th &#8220;A&#8221; &#8211; Identity &#8220;Assertion&#8221;</h3>
<div>In the modern world &#8211; there are <strong>(4) &#8220;A&#8217;s&#8221;</strong> for secure Authentication:</div>
<h4>
<ol>
<li><strong>Authentication </strong></li>
<li><strong>Authorization </strong></li>
<li><strong>Auditing </strong></li>
<li><strong>Assertion (<span style="color: #ff0000"><a href="http://www.gosecureauth.com/product/security-token-service/default.aspx">Identity Assertion</a></span>)</strong></li>
</ol>
</h4>
<div>This is WHAT IS MISSING with the traditional (AAA) RADIUS authentication &#8211; there is NO WAY to ASSERT the identity to outside parties.  (RADIUS is just a static mechanism to pass/query credential information).</div>
</p>
<h3><strong>What is needed:</strong></h3>
<div><strong> </strong></div>
<div><strong> </strong></div>
<h4><strong>1.  A flexible Authentication solution</strong></h4>
<ul>
<li>That Supports multiple authentication methods</li>
<li>Whatever auth method enterprise chooses</li>
</ul>
<h4><strong>2.  That &#8220;Asserts&#8221; the identity&#8230;</strong></h4>
<div>A mechanism to tell a relying party the ID</div>
<ul>
<li>Securely</li>
<li>Repeatably</li>
<li>Without APIs</li>
</ul>
<div>This is EXACTLY what the Securauth product is, a product that meets the (4) of authentication:</div>
<div><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/SecureAuth-AAAA-w-label.jpg"><img class="alignleft size-full wp-image-2603" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/SecureAuth-AAAA-w-label.jpg" alt="" width="576" height="336" /></a></div>
<div><strong>Image #3: </strong><a href="http;//www.gosecureauth.com"> SecureAuth</a> provides  (1) Authentication,  (2) Authorization, (3) Audit and (4) Assertion.</div>
<p><div>It is this assertion part of the authentication &#8211; that truely differents SecureAuth.  SecureAuth takes on the last part of the authenticaiton &#8211; the &#8220;Assertion of the IDentity&#8221; to the relying party (Web, VPN, Cloud.)  This is not left as an API excercise or a complicated coding project &#8211; but built into the SecureAuth product.  (See Image #4)</div>
<p><div style="text-align: left"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/SecureAuth_4-As2.jpg"><img class="alignleft size-full wp-image-2619" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/SecureAuth_4-As2.jpg" alt="" width="605" height="454" /></a></div>
<div><strong>Image #4: </strong> SecureAuth is the only solution that combines the required 4 AAAA&#8217;s of authentication.</div>
<p>
<div><a href="http://www.gosecureauth.com/support/images/rsa-2012-b.jpg"><img src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/rsa-20121.jpg" alt="" width="62" height="73" /></a> Please come by the SecureAuth booth @ the <a href="http://www.gosecureauth.com/support/images/rsa-2012-b.jpg">RSA Conference – Moscone Center, Booth #217</a> &#8211; or <a href="mailto:sales@gosecureauth.com">contact us</a> – and we’ll map a solution to your requirements.</div>
<div>—<br />
<a href="mailto:ggrajek@gosecureauth.com">Garret Grajek</a> is CTO and a  co-founder of <a href="http://www.gosecureauth.com/">SecureAuth</a>.    SecureAuth is a single appliance solution that delivers configurable 2-Factor  and SSO authentication for Web, VPN and SaaS based solutions.</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/the-4-as-of-authentication/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apps! Apps!  Apps are Everywhere!  How to Centrally Control???</title>
		<link>http://blog.gosecureauth.com/blog/apps-apps-apps-are-everywhere-how-to-centrally-control</link>
		<comments>http://blog.gosecureauth.com/blog/apps-apps-apps-are-everywhere-how-to-centrally-control#comments</comments>
		<pubDate>Fri, 17 Feb 2012 18:59:09 +0000</pubDate>
		<dc:creator>Garret</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2486</guid>
		<description><![CDATA[Please come by the Secureauth booth @ the RSA Conference &#8211;  Moscone Center, Booth #217 &#8211; IT admins face the explosion of apps, specifically cloud apps (like Google, Salesforce, Concur, Workday, SuccessFactors) &#8211; and need a way to manage these products. And by manage &#8211; i mean: Conduct Authentication Allow Single-Sign-On (web user experience) Utilize a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.gosecureauth.com/support/images/rsa-2012-b.jpg"><img class="alignleft size-full wp-image-2531" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/rsa-2012.jpg" alt="" width="50" height="58" /></a> Please come by the Secureauth booth @ the <a href="http://www.gosecureauth.com/support/images/rsa-2012-b.jpg">RSA Conference &#8211;  Moscone Center, Booth #217</a><br />
&#8211;</p>
<p>IT admins face the explosion of apps, specifically cloud apps (like Google, Salesforce, Concur, Workday, SuccessFactors) &#8211; and need a way to manage these products.</p>
<p>And by manage &#8211; i mean:</p>
<ul>
<li>Conduct Authentication</li>
<li>Allow Single-Sign-On (web user experience)</li>
<li>Utilize a single account (enterprise data store)</li>
<li>Log the authentication</li>
</ul>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/2012-SA-IEP3.jpg"><img class="aligncenter size-full wp-image-2565" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/2012-SA-IEP3.jpg" alt="" width="640" height="384" /></a></p>
<p style="text-align: left">&nbsp;</p>
<p><strong>Image #1: </strong><a href="http://www.gosecureauth.com"> SecureAuth</a> centrally manages authentication and identities for users &#8211; including 2-Factor, SSO, federation and logging.</p>
<p style="text-align: left">&nbsp;</p>
<h3 style="text-align: left"><span style="color: #ff0000">Centralized Management</span></h3>
<p style="text-align: left">SecureAuth is the revolutionary all-purpose tool for the enterprise that centralizing the functionality for several key IT domains:</p>
<ul>
<li>Access Control for Network Access</li>
<li>Access Control for Web Access</li>
<li>Access Control for Cloud Apps</li>
<li>2-Factor AuthenticationWeb/SaaS Portal</li>
<li>Identity Management of Enterprise UsersLogging of authentication</li>
</ul>
<p style="text-align: left">SecureAuth is able to become this centralized management tool &#8211; because of its powerful multi-tenanted architecture that allows it to create 100 distinct policies to manage the various enterprise resources.</p>
<h3><strong>Access Control for Web Access:</strong></h3>
<p style="text-align: left">Admins can consolidate the access controls of their web resources &#8211; in a single platform, SEcureAuth.   Web resources can include J2EE, .NET, Microsoft Sharepoint, IBM WebLogic, Oracle WebSphere and other platforms &#8211; all which can be collated into a single authentication portal.</p>
<p style="text-align: left">&nbsp;</p>
<p style="text-align: left"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/2b.Web-Access3.jpg"><img class="alignleft size-full wp-image-2553" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/2b.Web-Access3.jpg" alt="" width="534" height="321" /></a></p>
<p style="text-align: left"><strong>Images #2:</strong> <a href="http://www.gosecureauth.com">SecureAuth</a> centrally authenticates on-premise Web Applications.</p>
<h3><strong>Access Control for Network Access:</strong></h3>
<p>Admins can centralize authentication access control for their various network VPN and gateway devices in a single, consolidated tool &#8211; creating different for access policies for different users  utilizing similar or differentiating authentication mechanisms all supported from the same SecureAuth platform.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/1a.Network-Access.jpg"><img class="aligncenter size-full wp-image-2514" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/1a.Network-Access.jpg" alt="" width="535" height="307" /></a></p>
<p style="text-align: left"><strong>Images #3:</strong> SecureAuth centrally authenticates on-premise VPN/Gateway devices.</p>
<h3><strong>Access Control for Cloud Apps:</strong></h3>
<p style="text-align: left">SecureAuth can also collate an ever growing number of SaaS solutions solutions and provide access to enterprise users coming from the intranet and extranet.   SecureAuth can provide centralized access control to these apps, including managing the authentication, the workflow and the logging.    The key to the secureAuth solution is that it utilize on-premise IDs  (Active Directory) for acces to these cloud Apps.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/3b.Cloud-Access.jpg"><img class="aligncenter size-full wp-image-2498" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/3b.Cloud-Access.jpg" alt="" width="612" height="403" /></a></p>
<p style="text-align: left"><strong>Image #4:</strong> SecureAuth centrally authenticates and provides SSO for Cloud Applications.</p>
<h3 style="text-align: left"><strong>2-Factor Authentication</strong></h3>
<p style="text-align: left">SecureAuth centrally allows enterprise to control 2-Factor authentication to the VPN, WEb, Cloud Apps.     A unique SecuerAUth realm can be created for each resource, with a differentiating authenticaiton policiy.   SecureAuth authentication can be configured to utilize SMS, Telephony, E-Mail, KBA/KBQ, Help Desk, Password and X.509v3 Certificates.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/4b.2-Factor-Auth.jpg"><img class="aligncenter size-full wp-image-2497" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/4b.2-Factor-Auth.jpg" alt="" width="429" height="406" /></a></p>
<p style="text-align: left"><strong>Image #5:</strong> SecureAuth is a VASP  (a &#8220;Variable Authentication Service Platform&#8221;).  SecureAuth supports X.509, SMS, Telephony, E-mail OTP, KBA/KBQ (Knowledge-Based-Questions), Static PIN, Yubikey and Password.</p>
<h3><strong>Web/SaaS Portal:</strong></h3>
<p>&nbsp;</p>
<p>The enterprise portal can be hosted on the SecureAuth solution.   All access controls, including 2-Factor are built into the portal.  In addition, the web single-sign-on between the on-premise web applications and SaaS applications is all constructed and managed throught the SecureAuth administration tool.   SecureAuth can also integrate this web/SaaS sso to pre-existing portals.</p>
<p style="text-align: left"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/5a.Secure-Portal.jpg"><img class="size-full wp-image-2502" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/5a.Secure-Portal.jpg" alt="" width="622" height="466" /></a><strong>Image #6:</strong> SecureAuth is a revolutionary 2-Factor, portal &#8211; built-in with full authentication and SSO between internally and external apps.   Fully compatible for all devices.</p>
<p style="text-align: left"><span style="font-size: 15px;font-weight: bold"> </span></p>
<h3><strong>Identity Management for Enterprise Users:</strong></h3>
<p>SecureAuth is able to provide centralized identity managment tools for both internal  and external users.   In addition, these tools can be delegated to both users and enterprise admins &#8211; according to pre-existing user groups.   These tools include:</p>
<ul>
<li>Identity Provisioning</li>
<li>Profile Enrollment (1st time use)</li>
<li>2-Factor password Reset</li>
<li>User Profile Management</li>
<li>2-Factor Password Reset</li>
<li>Administration Management of User Accounts</li>
</ul>
<p style="text-align: left">All of these policies are accessible from user internally and external located &#8211; but enforcement of the policies can all be sent to one of more centralized datastores.</p>
<p><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/6.Identity-Management.jpg"><img class="aligncenter size-full wp-image-2504" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/6.Identity-Management.jpg" alt="" width="508" height="305" /></a><strong> </strong></p>
<p style="text-align: left"><strong>Image #7: </strong> SecureAuth has built-in identity Management:  User Profile On-Boarding, 2-Factor Password Reset, User Self-Management and Help Desk User Management.</p>
<h3><strong>Logging of Authentication:</strong></h3>
<p>SecureAuth provides the enterprise a centralized facility to log all access to SecureAuth protected resources &#8211; regardless if the resources are VPN, Web or Cloud resources.    SecureAuth can send the “who, what, where and when” of logging in the format the enterprise requires &#8211; both text and syslog format.  SecureAuth can send the syslog files to an on-premise SIEM (Syslog Information Event Management) server &#8211; or an office premise SIEM.   Secureauth also supports a GUI interface to cloud SIEM, Loggly.</p>
<p style="text-align: left"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/7.Logging.jpg"><img class="aligncenter size-full wp-image-2501" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/7.Logging.jpg" alt="" width="613" height="294" /></a><strong> Image #8: </strong> SecureAuth provides full logging of all authentication &#8211; be it VPN, Web or SaaS.</p>
<p style="text-align: left">&nbsp;</p>
<div>
<p><a href="http://www.gosecureauth.com/support/images/rsa-2012-b.jpg"><img class="alignleft size-full wp-image-2532" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/rsa-20121.jpg" alt="" width="62" height="73" /></a> Please come by the SecureAuth booth @ the <a href="http://www.gosecureauth.com/support/images/rsa-2012-b.jpg">RSA Conference &#8211; Moscone Center, Booth #217</a> - or <a href="mailto:sales@gosecureauth.com">contact us</a> – and we’ll map a solution to your requirements.</p>
<p>—<br />
<a href="mailto:ggrajek@gosecureauth.com">Garret Grajek</a> is CTO and a  co-founder of <a href="http://www.gosecureauth.com/">SecureAuth</a>.    SecureAuth is a single appliance solution that delivers configurable 2-Factor  and SSO authentication for Web, VPN and SaaS based solutions.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/apps-apps-apps-are-everywhere-how-to-centrally-control/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>At RSA 2012 &#8211; Fill You Shopping Cart, or &#8220;Check-out&#8221; with SecureAuth</title>
		<link>http://blog.gosecureauth.com/blog/at-rsa-2012-fill-you-shopping-cart-or-check-out-with-secureauth</link>
		<comments>http://blog.gosecureauth.com/blog/at-rsa-2012-fill-you-shopping-cart-or-check-out-with-secureauth#comments</comments>
		<pubDate>Sun, 12 Feb 2012 17:18:53 +0000</pubDate>
		<dc:creator>Garret</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2437</guid>
		<description><![CDATA[&#8216;Tis the Season&#8230; Come Feb 27th to March 2nd, thousands of us &#8211; including myself, will be at the Moscone Center in scenic San Francisco for the RSA Conference, 2012.    (SecureAuth will be front row in the exhibit center, Booth #217.) The job of many of you &#8211; at this event &#8211; is to: Map [...]]]></description>
			<content:encoded><![CDATA[<p>&#8216;Tis the Season&#8230;</p>
<p>Come Feb 27th to March 2nd, thousands of us &#8211; including myself, will be at the Moscone Center in scenic San Francisco for the <a href="http://www.rsaconference.com/events/2012/usa/mightier.htm">RSA Conference, 2012</a>.    (SecureAuth will be front <a href="http://www.gosecureauth.com/support/images/rsa-2012-b.jpg">row in the exhibit center, Booth #217</a>.)</p>
<p>The job of many of you &#8211; at this event &#8211; is to:</p>
<ul>
<li>Map the requirements your company has around:
<ul>
<li>Identity Management</li>
<li>Access Management</li>
<li>Cloud Apps Access Control</li>
<li>Web Apps Access Control</li>
<li>VPN Access Control</li>
<li>2-Factor Authentication</li>
<li>Mobile, <a href="http://blog.gosecureauth.com/blog/its-a-byod-world-protect-whats-important-the-corporate-resources">BYOD Support</a></li>
</ul>
</li>
<li>To the Vendors at the event</li>
</ul>
<p>Well&#8230;</p>
<p>You can either:</p>
<ul>
<li>Fill your shopping cart  (See<a href="http://www.gosecureauth.com/support/images/secureAuth_2012_comparison.jpg"> Industry Competitive Matrix</a>)</li>
<li>Or &#8220;Check Out&#8221; with <a href="http://www.gosecureauth.com/contact/default.aspx">SecureAuth</a></li>
</ul>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/shopping_cart-vs1.jpg"><img class="aligncenter size-full wp-image-2442" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/shopping_cart-vs1.jpg" alt="" width="614" height="461" /></a></p>
<p><strong>Image #1: </strong> <em><a href="http://www.gosecureauth.com">SecureAuth</a> is a multi-functional, multi-tenanted authentication solution that combines the functionalities that previously required the &#8220;<a href="http://www.gosecureauth.com/support/images/secureAuth_2012_comparison.jpg">cobbling&#8221; of products </a>from multiple vendors.</em></p>
<p>The breakdown of the functionalites is very revealing.   (See <a href="http://www.gosecureauth.com/support/images/secureAuth_2012_comparison.jpg">image #2,</a> below).   Traditional vendors simply provide horizontal solutions that require enterprises to combine the functionalities together for a full soluiton.   It is these integrations which tend to tend to run up cost and create security weaknesses in the architecture.   Because <a href="http://blog.gosecureauth.com/blog/secureauth-first-2-factor-sts">SecureAuth is a single solution</a>, cost is lower &#8211; and the security posture in augmented.</p>
<p><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/STS_2012_Comparison1.jpg"><img class="alignleft size-full wp-image-2475" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/STS_2012_Comparison1.jpg" alt="" width="614" height="461" /></a></p>
<p style="text-align: left"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/key1.jpg"><img class="alignleft size-full wp-image-2462" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/key1.jpg" alt="" width="598" height="69" /></a></p>
<p style="text-align: left"><strong><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/key.jpg"></a></strong></p>
<p style="text-align: left"><strong>Image #2: </strong> <em><a href="http://www.gosecureauth.com/product/security-token-service/default.aspx">SecureAuth</a> combines the functionality required for Web, VPN, Cloud and Mobile Security into a single platform.  (<a href="http://www.gosecureauth.com/support/images/secureAuth_2012_comparison.jpg">Click for full-size image</a>)</em></p>
<p style="text-align: left">Please come by the Secureauth booth @ the <a href="http://www.gosecureauth.com/support/images/rsa-2012-b.jpg">RSA Moscone Center, Booth #217</a> - or <a href="mailto:sales@gosecureauth.com">contact us</a> &#8211; and we&#8217;ll map a solution to your requirements.</p>
<p style="text-align: left">—<br />
<a href="mailto:ggrajek@gosecureauth.com">Garret Grajek</a> is CTO and a  co-founder of <a href="http://www.gosecureauth.com/">SecureAuth</a>.    SecureAuth is a single appliance solution that delivers configurable 2-Factor  and SSO authentication for Web, VPN and SaaS based solutions.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/at-rsa-2012-fill-you-shopping-cart-or-check-out-with-secureauth/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Confessions of a Corporate Google Apps User&#8230;</title>
		<link>http://blog.gosecureauth.com/blog/confessions-of-a-corporate-google-apps-user</link>
		<comments>http://blog.gosecureauth.com/blog/confessions-of-a-corporate-google-apps-user#comments</comments>
		<pubDate>Sun, 12 Feb 2012 15:03:19 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2431</guid>
		<description><![CDATA[Alright so we all know that Google apps can save your company a lot of money, hundreds of thousands of dollars in some cases.    It also means that your company can do what it does best which is typically not manage email for your entire company. But, one downside to using any application in [...]]]></description>
			<content:encoded><![CDATA[<p>Alright so we all know that Google apps can save your company a lot of money, hundreds of thousands of dollars in some cases.    It also means that your company can do what it does best which is typically not manage email for your entire company.</p>
<p>But, one downside to using any application in the cloud is the fact that without something like SecureAuth in place, your corporate policies concerning password age &amp; complexity literally fly out the window.</p>
<p>So, let me tell you what an above average user is guilty of.</p>
<p>NEVER changing my Google Apps password.  That&#8217;s right, since I&#8217;ve been with SecureAuth I&#8217;ve never once changed my Google Apps password&#8230;  Not only that but when I came on board, do you think I made a complex password that&#8217;s totally unique?  nope&#8230;  It&#8217;s so similar to my mail password it&#8217;s ridiculous.</p>
<p>Why would someone who&#8217;s very technical do this?  Because I&#8217;m busy, you probably are too.  If you&#8217;re one of the few people that utilize a password safe you&#8217;ve probably tried more than 2 different products and spent well over 40 hours fiddling with it during your use, it might be time well spent but that&#8217;s only if you actually have the time.</p>
<p>Think to yourself, how many times have you changed your password to your personal email account?  I&#8217;m betting just about never unless you had a scare of some sort.  We&#8217;re busy people and by nature we won&#8217;t make a change to something like a password unless we&#8217;re forced to.  Now, the list of companies that have had their Google corporate email exposed to the world becausesomeone was able to guess the password is very very long.  Why worry about being next?  Give us a call and we&#8217;ll show you how to shore up your security to SaaS applications.</p>
<p>&nbsp;</p>
<p>BRB, changing my Google Apps password!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/confessions-of-a-corporate-google-apps-user/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trustwave Root Certificates for Sale, Who Can You Trust?</title>
		<link>http://blog.gosecureauth.com/blog/trustwave-root-certificates-for-sale-who-can-you-trust</link>
		<comments>http://blog.gosecureauth.com/blog/trustwave-root-certificates-for-sale-who-can-you-trust#comments</comments>
		<pubDate>Thu, 09 Feb 2012 20:57:22 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2418</guid>
		<description><![CDATA[In light of recent news from Trustwave concerning their extremely bad decision to issue a Root Certificate to someone who paid them enough money.  Trustwave knew the company that purchased it would use to sign certificates for all websites not owned by the customer and they are now facing serious backlash. So, how can you ensure your [...]]]></description>
			<content:encoded><![CDATA[<p>In light of recent news from Trustwave concerning their extremely bad decision to issue a Root Certificate to someone who paid them enough money.  Trustwave knew the company that purchased it would use to sign certificates for all websites not owned by the customer and they are now facing serious backlash.</p>
<p>So, how can you ensure your CEO won&#8217;t have his email exposed to everyone in the world because he fell prey to the Man in the Middle?  it&#8217;s actually very simple when you use SecureAuth.  We&#8217;ve understood the need for not just 2-Factor authentication but also protection against Man in the Middle attacks from the onset.  We&#8217;ve done the work to ensure you can easily decide <em>exactly </em>which webserver you want to trust.</p>
<div id="attachment_2424" class="wp-caption alignleft" style="width: 636px"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/ScreenShot011.png"><img class="size-full wp-image-2424 " src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/ScreenShot011.png" alt="SecureAuth's protection against MitM attacks" width="626" height="212" /></a><p class="wp-caption-text">Figure 1. SecureAuth allows you to easily trust 1 SSL point</p></div>
<p>So there you have it, we all know it&#8217;s dangerous out there and events like this just prove it.</p>
<p>Keep in mind that SecureAuth is not only the first product that allows for 2-Factor location based authentication to internal and SaaS applications but we were the first and still the only product that allows for this level of granular control of what your end users will validate against.</p>
<p>Take a minute to contact our sales department for a demonstration of this functionality.  <a rel="noreferrer" href="mailto:Sales@gosecureauth.com">Sales@gosecureauth.com</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/trustwave-root-certificates-for-sale-who-can-you-trust/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It&#8217;s a BYOD World &#8211; Protect What You Can &#8211; The Corporate Resources</title>
		<link>http://blog.gosecureauth.com/blog/its-a-byod-world-protect-whats-important-the-corporate-resources</link>
		<comments>http://blog.gosecureauth.com/blog/its-a-byod-world-protect-whats-important-the-corporate-resources#comments</comments>
		<pubDate>Sat, 04 Feb 2012 14:47:40 +0000</pubDate>
		<dc:creator>Garret</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2371</guid>
		<description><![CDATA[Welcome to 2012 &#8211; It&#8217;s a BYOD World.       (That&#8217;s &#8220;Bring Your Own Device&#8221; in &#8220;IT&#8221; speak.) SecureAuth and Support of BYOD (Including Amazon Kindle demo) Enterprises are both: Encouraging users to use their own devices (For Cost Cutting) Being demanded to support End User devices (For Ease-of-use, Convenience) The Concept of enterprises: Supplying all client [...]]]></description>
			<content:encoded><![CDATA[<p>Welcome to 2012 &#8211; It&#8217;s a BYOD World.       (That&#8217;s &#8220;<a href="http://www.ft.com/cms/s/0/fd92894c-3658-11e1-a3fa-00144feabdc0.html#axzz1lQcY6sqz">Bring Your Own Device</a>&#8221; in &#8220;IT&#8221; speak.)</p>
<p><a href="http://www.youtube.com/watch?v=R73I2m0a08I&amp;feature=youtu.be"><img class="alignleft size-full wp-image-2414" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/youtube.jpg" alt="" width="68" height="18" /></a> <a href="http://www.youtube.com/watch?v=R73I2m0a08I&amp;feature=youtu.be">SecureAuth and Support of BYOD (Including Amazon Kindle demo)</a></p>
<p><strong> </strong></p>
<p><strong>Enterprises are both:</strong></p>
<ul>
<li>Encouraging users to use their own devices (For Cost Cutting)</li>
<li>Being demanded to support End User devices (For Ease-of-use, Convenience)</li>
</ul>
<p>The Concept of enterprises:</p>
<ul>
<li>Supplying all client side devices</li>
<li>Locking down all client side devices</li>
</ul>
<p>Well &#8211; is fantasy.</p>
<p>End user are able to access the internet, not just from the <a href="http://www.youtube.com/watch?v=5oWl8xQ16G4">millions of Apple iOS devices </a>- but  from everything from bubble-wrap Android Phones bought at Walmart (See Image #1),  Amazon Kindle devices for $175 (See image #2) &#8211; even including the Nintendo Wii gaming devices  (See Image #3).</p>
<p><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/walmart-android.jpg"><img class="size-full wp-image-2389 alignleft" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/walmart-android.jpg" alt="" width="220" height="293" /></a><br />
<strong>Image #1:</strong> <a href="http://www.walmart.com/search/search-ng.do?search_query=Straight+Talk+Android+Smart+Phone">Android Smart Phones</a>, with full app and browser ability can now be purchase in buble waps at Walmart.</p>
<p><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/amazon-kindle.jpg"><img class="size-full wp-image-2392 alignleft" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/amazon-kindle.jpg" alt="" width="342" height="303" /></a></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p><strong>Image #2:</strong> <a href="http://www.amazon.com/dp/B0051VVOB2/?tag=googhydr-20&amp;hvadid=8302881877&amp;ref=pd_sl_7gl7b2uwu2_b">Amazon Kindle Fire</a>, at a whopping $199 &#8211; are legitimate wifi-enabled, browser based device  &#8211; ready for corporate work &#8211; <a href="http://www.youtube.com/watch?v=WhlivmXqPgM">when protected by SecureAuth</a>.</p>
<p><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/Nintendo-wii.jpg"><img class="size-full wp-image-2395 alignleft" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/Nintendo-wii.jpg" alt="" width="363" height="225" /></a></p>
<p><strong>Image #3: </strong>Even the wonderful <a href="http://www.nintendo.com/consumer/systems/wii/en_na/gi_channels.jsp?menu=internet">Nintendo Wii</a>, is a legitimate member of the internet &#8211; and can be protected by SecureAuth.</p>
<h3 style="text-align: left"><strong><span style="color: #000080">If It&#8217;s Impossible to control the EXPLOSION of Client Devices &#8211; what is IT to do?</span></strong></h3>
<p>Control Access to your resources.    The laws/regualations around IT have not changed &#8211; just becasue their are browsers on bubble-wrap devices and gaming tools.</p>
<p>All the same rules/guidances are in tact &#8211; Enterprises must still follow the <a href="http://www.sans.org/reading_room/whitepapers/authentication/its-about-authentication_1070">3 A&#8217;s of IT Security</a>:</p>
<ul>
<li>Authentication</li>
<li>Authorization</li>
<li>Audit</li>
</ul>
<p>It does not matter &#8211; if the user came from a Apple Air or a Android HTC or Lenovo laptop.  The enterprise must still show:</p>
<ul>
<li>Which user accessed the resource?</li>
<li>What authentication mechanism was utilized?</li>
<li>Why the user was allowed the priviledged  (Authorization)?</li>
<li>When the user was given access?</li>
</ul>
<h3><strong><span style="color: #000080">The world has changed &#8211; And change is Good!</span></strong></h3>
<p>But we need to have the tools to manage/collaborate with the change.   Not only has their been a (wonderful) explosion of client devices &#8211; their has also been an explosion of enterprise resources.</p>
<p><strong>It&#8217;s NOT enough to put up a gateway around the perimeter!!</strong></p>
<p>The modern IT environment requires access at the following (3) accss points:</p>
<ol>
<li><a href="http://www.gosecureauth.com/solutions/web/default.aspx">Enterprise-Hosted Applications</a></li>
<li><a href="http://www.gosecureauth.com/solutions/vpn/default.aspx">Gateway/VPNs</a></li>
<li><a href="http://www.gosecureauth.com/solutions/cloud/default.aspx">Cloud-Based Resources</a></li>
</ol>
<p>This is the modern IT world &#8211; users need to be able to get to these resources &#8211; with whatever device they choose to use.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/02/SecureAuth-BYOD1.jpg"><img class="aligncenter size-full wp-image-2377" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/SecureAuth-BYOD1.jpg" alt="" width="538" height="403" /></a></p>
<p><strong>Image #4: </strong> <a href="http://www.gosecureauth.com">SecureAuth</a> becomes the authentication mechanisms that validates the user identity, regardless of device &#8211; and then provides access to the corporate resource.</p>
<h3><strong><span style="color: #000080">Don&#8217;t Authenticate the Device &#8211; Authenticate the User!</span></strong></h3>
<p>This is the SecureAuth mantra!   You are being asked <a href="http://www.gosecureauth.com/solutions/compliance/default.aspx">by the regulations </a>(<a href="http://www.gosecureauth.com/solutions/compliance/pci.aspx">PCI DSS</a>, <a href="http://www.gosecureauth.com/solutions/compliance/ncua.aspx">NCUA</a>, <a href="http://www.gosecureauth.com/solutions/compliance/ffiec.aspx">FFIEC</a>, <a href="http://www.gosecureauth.com/solutions/compliance/hipaa.aspx">HIPAA/HITECH,</a> <a href="http://www.gosecureauth.com/solutions/compliance/cjis.aspx">CJIS</a>) to identify the user and then allow access.   This is EXACTLY what SecureAuth is capable of doing.</p>
<p>SecureAuth uses flexible authentication mechanisms, mixed, matched &#8211; any way you choose, to allow access:</p>
<ul>
<li><a href="http://www.gosecureauth.com/solutions/mobile/default.aspx">From Any Device</a></li>
<li>To Your Web, Gateway and Cloud Resources</li>
</ul>
<p>SecureAuth supported authentication mechanisms include:</p>
<ul>
<li>SMS</li>
<li>Telephony</li>
<li>X.509</li>
<li>E-mail OTP</li>
<li>KBA/KBQ</li>
<li>Help Desk</li>
<li>Password</li>
</ul>
<p>All based on your enterprise-held identities &#8211; meeting all compliance criterias.  It&#8217;s a new world &#8211; and the new world is good.    Happy Wii&#8217;ing!</p>
<p>And <a href="mailto:sales@gosecureauth.com">contact us</a> &#8211; to learn how to protect your corporate resources &#8211; in BYOD wordl.</p>
<p>—<br />
<a href="mailto:ggrajek@gosecureauth.com">Garret Grajek</a> is CTO and a  co-founder of <a href="http://www.gosecureauth.com/">SecureAuth</a>.    SecureAuth is a single appliance solution that delivers configurable 2-Factor  and SSO authentication for Web, VPN and SaaS based solutions.</p>
<p><a href="http://www.youtube.com/watch?v=R73I2m0a08I&amp;feature=youtu.be"><img class="alignleft size-full wp-image-2414" src="http://blog.gosecureauth.com/wp-content/uploads/2012/02/youtube.jpg" alt="" width="68" height="18" /></a> <a href="http://www.youtube.com/watch?v=R73I2m0a08I&amp;feature=youtu.be">SecureAuth and Support of BYOD (Including Amazon Kindle demo)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/its-a-byod-world-protect-whats-important-the-corporate-resources/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecureAuth Secures Your Remote Users &#8211; Both to Enterprise and the Cloud</title>
		<link>http://blog.gosecureauth.com/blog/2340</link>
		<comments>http://blog.gosecureauth.com/blog/2340#comments</comments>
		<pubDate>Wed, 25 Jan 2012 05:48:30 +0000</pubDate>
		<dc:creator>Talton</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2340</guid>
		<description><![CDATA[Remote Users Giving access to remote users has become a pressing issue since more than ever companies are having their employees work from home or on the road with mobile devices. Today users have the ability to open up a IPad and show a presentation to people on the fly. That is why Enterprises have [...]]]></description>
			<content:encoded><![CDATA[<div>
<h3><a href="http://www.gosecureauth.com/news-events/press-detail.aspx?ID=30">Remote Users</a></h3>
<p>Giving access to remote users has become a pressing issue since more than ever companies are having their employees work from home or on the road with mobile devices. Today users have the ability to open up a IPad and show a presentation to people on the fly. That is why Enterprises have to secure these mobile devices but have found that it isn&#8217;t easy to do one never the less to deploy<a href="http://www.nextgov.com/nextgov/ng_20110726_9436.php?oref=topnews">17,000 </a>Google email accounts to mobile users.  This has become an even more of an issue since 2011 showed us that many organizations that don’t use <a href="http://www.gosecureauth.com/support/docs/SecureAuth_Mitigates_MITM_Attacks.pdf">bilateral authentication</a> were being <a href="http://www.gosecureauth.com/news-events/webinar-detail.aspx?ID=46">breached</a>.</p>
<p>&nbsp;</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/remote-access2.jpg"><img class="aligncenter size-full wp-image-2363" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/remote-access2.jpg" alt="" width="612" height="360" /></a></p>
<p style="text-align: left"><em><strong>Image #1: </strong> Enterprises are wrestling with (2) types of Remote Acesss:  (1) to the enterprise and (2) to the cloud.   <a href="http://www.gosecureauth.com">SecureAuth</a> helps with both.</em></p>
<p dir="ltr"><a href="http://www.gosecureauth.com/product/overview/features-and-benefits.aspx">SecureAuth</a> secures your remote users through your directory and gives them secure access to your <a href="http://www.gosecureauth.com/solutions/vpn/microsoft-uag.aspx">gateway</a>, <a href="http://www.gosecureauth.com/solutions/web/sharepoint.aspx">web</a>, <a href="http://www.gosecureauth.com/solutions/cloud/saml-portal-in-a-box.aspx">cloud</a> and mobile environment. Then SecureAuth logs the event in a syslog or text. SecureAuth wanted to make the process as seamless to the user as possible but also wanted to utilize the strength of <a href="http://www.gosecureauth.com/support/docs/SecureAuth-Security_X509_Certificates.pdf">X.509v3</a> certificates to reduce the risk of unauthorized access, phishing and password attacks. In addition allows your remote users to meet audit compliance like <a href="http://www.gosecureauth.com/solutions/compliance/pci.aspx">PCI</a>, <a href="http://www.gosecureauth.com/solutions/compliance/hipaa.aspx">HIPPA</a>, <a href="http://www.gosecureauth.com/solutions/compliance/ffiec.aspx">FFIEC</a>, <a href="http://www.gosecureauth.com/solutions/compliance/ncua.aspx">NCUA</a>, <a href="http://www.gosecureauth.com/solutions/compliance/cjis.aspx">CJIS</a>.</p>
<p>With a number of organizations going to Google Apps, everyday <a href="http://www.google.com/apps/intl/en/business/gogoogle.html">thousands </a>of companies go with Google. SecureAuth developed <a href="http://blog.gosecureauth.com/blog/secureauth-auto-apple-ios-provisioning-of-accounts-for-google-apps">auto-profile provisioning</a> for IOS devices allowing SecureAuth to verify a user though AD put a randomized password in the correct Google Domain at the same time store it in your IOS AcitiveSync profile. This allows the user to securely sync his Google email to his IOS device.</p>
<p>If you have remote users that are using mobile devices that are not secure, <a href="http://www.gosecureauth.com/contact/default.aspx">call today</a>. We can have you up and running by the end of next week so take advantage of or free proof of concept before it is to late.</p>
</div>
<div>&#8211;</div>
<div><a href="https://www1.gotomeeting.com/register/448383904"><img class="alignnone size-medium wp-image-2341" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/register-now-300x97.jpg" alt="" width="91" height="29" /></a> <a href="https://www1.gotomeeting.com/register/448383904">SecureAuth Webinar:  Google Devices &#8211; iOS Provisioning </a></div>
<div>Thurs, Feb 23rd 10am PST</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/2340/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We&#8217;re &#8220;Going Google&#8221; &#8211; Why Should We Look @ SecureAuth?</title>
		<link>http://blog.gosecureauth.com/blog/im-going-to-google-why-should-i-look-secureauth</link>
		<comments>http://blog.gosecureauth.com/blog/im-going-to-google-why-should-i-look-secureauth#comments</comments>
		<pubDate>Sun, 22 Jan 2012 02:58:55 +0000</pubDate>
		<dc:creator>Garret</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2238</guid>
		<description><![CDATA[&#160; &#160; Had a great week last week &#8211; talking Google and SecureAuth from San Francisco to Houston to Atlanta to Ft Lauderdale. The bottom line question is: If Google Apps is such a complete package, why do I need SecureAuth? Well &#8211; let me help.. I created a Google/SecureAuth Matrix to help understand when [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center">&nbsp;</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/secureauth-google.jpg"><img class="aligncenter size-full wp-image-2246" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/secureauth-google.jpg" alt="" width="566" height="90" /></a></p>
<p>&nbsp;</p>
<p><span style="color: #000000">Had a great week last week &#8211; talking Google and SecureAuth from San Francisco to Houston to Atlanta to Ft Lauderdale.</span></p>
<p><span style="color: #000000">The bottom line question is:</span></p>
<h3><strong><span style="color: #000080">If Google Apps is such a complete package, why do I need SecureAuth?</span></strong></h3>
<p><span style="font-size: 13px;font-weight: normal;color: #000000">Well &#8211; let me help..</span></p>
<p><span style="color: #000000">I created a </span><em><span style="text-decoration: underline"><a href="http://www.gosecureauth.com/support/docs/SecureAuth_for_Google-funct_Matrix.pdf"><span style="color: #000080">Google/SecureAuth Matrix</span></a></span></em><span style="color: #000000"> to help understand when SecureAuth is needed.</span></p>
<p><span style="color: #000000">And&#8230;</span></p>
<p><span style="color: #000000">Since it&#8217;s a blog &#8211; put it in easy question/answer form:</span></p>
<h3><span style="color: #000080">Q:    I need 2-Factor authentication but why do I need SecureAuth, Google offers 2-Factor, right?</span></h3>
<p><strong>A: </strong>Google&#8217;s 2-Factor allows user&#8217;s to opt-in, opt-out.   It is a GREAT feature for <span style="color: #ff0000"><strong>users</strong></span> deployed in environments where the company doesn&#8217;t offer SecureAuth &#8211; but the user wants security.   But this should NOT be confused with <span style="color: #ff0000"><strong>ENTERPRISES</strong></span> who have to meet security compliance measures (PCI DSS, FFIEC, NCUA,  HIPAA/HITECH, etc) authentication regulations.</p>
<p>These (and other) authentication regulations require a NON-OPTIONAL 2-Factor authentication &#8211; e.g. a system that FORCES the user to conduct 2-Factor.   <a href="http://www.gosecureauth.com/solutions/cloud/googleapps.aspx">SecureAuth</a> is this solution for Google.</p>
<h3><span style="color: #000080"><strong>Q:    So if I want to use Google Apps for resources/apps that have to meet compliance standards &#8211; I should use SecureAuth?</strong></span></h3>
<p><strong>A: </strong> Yes &#8211;   SecureAuth meets all the authentication regulations  (PCI DSS, NCUA, FFIEC, SOX, GLB, etc).    It&#8217;s one of the primary reasons enterprise deploy SecureAuth &#8211; to take advantage of the wonderful applications that Google offers &#8211; and still meet the regulatory compliance measure.</p>
<p>Not just for authentication but for:</p>
<ul>
<li><strong>User Lifecycle Management</strong></li>
<li><strong>Data Store Management</strong></li>
<li><strong>Authentication Flexibility</strong></li>
<li><strong>Logging</strong></li>
</ul>
<h3><span style="color: #000080"><strong>Q:  I love Google Apps, its so amazing with all its growing functionality &#8211; but i don&#8217;t want to issue my users a new ID &#8211; can SecureAuth help?</strong></span></h3>
<p><strong>A: </strong>Exactly.   This is exactly the point of the SecureAuth solution. <span style="color: #000000"> (<a href="http://www.multifa.com/images/content/SecureAuth-Google-Apps-2.jpg">See diagram</a>.) </span>SecureAuth utilizes existing the existing datastore &#8211; and thus the user does NOT have know/remember their, new, Google ID.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/Google-SecureAuth-Cloud1.jpg"><img class="aligncenter size-full wp-image-2300" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/Google-SecureAuth-Cloud1.jpg" alt="" width="554" height="312" /></a></p>
<p style="text-align: left"><strong>Image #1: </strong><a href="http://www.gosecureauth.com/solutions/cloud/googleapps.aspx">SecureAuth</a> utilizes the existing enterprise directory (AD and other) for both internal SSO and external 2F authentication.</p>
<h3><span style="color: #000080">Q:    OK &#8211; but do these users now have a new password?</span></h3>
<p><span style="color: #000000"><strong>A:   NO!  No new password is needed!</strong></span></p>
<p><span style="color: #000000"><strong> </strong>This is the whole point of the </span><a href="http://www.multifa.com/images/content/SecureAuth-Google-Apps-2.jpg"><span style="color: #000000">SecureAuth architecture</span></a><span style="color: #000000"> &#8211; the user only has to remember their EXISTING userID/password  (most often, but not restricted, to Active Directory)- and NOT learn/remember the Google ID/password.</span></p>
<h3><span style="color: #000080">Q:   OK &#8211; so if I can use my existing Active Directory &#8211; can&#8217;t I just use the AD domain logon ID &#8211; and not have my users log in again, at the browser?</span></h3>
<p><span style="color: #000000"><strong>A: </strong>Yes.   SecureAuth is uniquely architected to utilize the EXISTING domain logon &#8211; if the user has logged into the enterprise domain &#8211; the user does NOT need to log in again.   SecureAuth picks up the user and logs the user directly into Google.   (With no prompt.)</span></p>
<h3><strong><span style="color: #000080">Q:   Does that mean I have to put something on my AD Domain Controller?  My AD admin has already told me &#8211; that he finds those solutions kludgy and will possibly break my audits?</span></strong></h3>
<p><span style="color: #000000"><strong>A: </strong><a href="http://www.gosecureauth.com/solutions/cloud/googleapps.aspx">SecureAuth for Google</a> is uniquely designed to PLACE nothing on the AD.   No components, no modifications.     It&#8217;s the only solution cloud or appliance based that the AD admins approve of of AD IWA SSO.  (That&#8217;s what the &#8220;desktop SSO feature&#8221; is called &#8211; Active Directory IWA [Intergrated Windows Authentication])</span></p>
<h3><span style="color: #000080"><strong>Q:   Ok &#8211; so you got my internal users covered &#8211; what about external &#8211; what are my authentication options?</strong></span></h3>
<p><span style="color: #000000"><strong>A: </strong>Great question.   That&#8217;s where SecureAuth excels.   Not only can it ENFORCE a User/ID Password (for AD or other) &#8211; but it also can enforce a 2-Factor authetnication, based on the secutrity requirements of YOUR enterprise.</span></p>
<p><span style="color: #000000">SecureAuth is what Gartner refers to as a V.A.S.   (Versatile Authentication Service).   SecureAuth authentication comes standard &#8211; with these authentication mechanism &#8211; BUILT IN:</span></p>
<ul>
<li><strong><span style="color: #000000">SMS OTP </span></strong></li>
<li><strong><span style="color: #000000">Telephony OTP</span></strong></li>
<li><strong><span style="color: #000000">E-Mail OTP</span></strong></li>
<li><strong><span style="color: #000000">Knowledge Based Authentication (KBA/KBQ)</span></strong></li>
<li><strong><span style="color: #000000">Static PIN</span></strong></li>
<li><strong><span style="color: #000000">X.509 </span></strong></li>
<li><strong><span style="color: #000000">CAC Cards</span></strong></li>
<li><strong><span style="color: #000000">YubiKey</span></strong></li>
<li><strong><span style="color: #000000">Password</span></strong></li>
</ul>
<h3><span style="color: #000080"><strong>Q:   Yes &#8211; but i need 2-Factor,  but more importantly, I can&#8217;t have a high friction experience for my users &#8211; like a SMS call every time.</strong></span></h3>
<p><span style="color: #003366"><span style="color: #000000"><strong>A:</strong> </span>S</span><a href="http://www.gosecureauth.com/support/docs/SecureAuth-2-Factor_Authentication_WhitePaper.pdf"><span style="color: #003366">ecureAuth is a revolutionary multi-technology</span></a><span style="color: #003366"><span style="color: #000000"> that does NOT require users to understand how to conduct a 2-Factor authentication. </span> (</span><a href="http://www.gosecureauth.com/support/docs/secureauth-end_user_experience.pdf"><span style="color: #003366">SecureAuth User Authentication Experience</span></a><span style="color: #003366">).</span></p>
<p>The paradigm of authentication is:</p>
<ul>
<li><strong><span style="color: #000000">It must be secure</span></strong></li>
<li><strong><span style="color: #000000">It must be seamless to the user</span></strong></li>
</ul>
<p>SecureAuth does this through browser based walk-thru authentication, and advanced PATENTED crypto-authentication.</p>
<p>The 2-Factor is:</p>
<ul>
<li><strong>Non-Phishable</strong></li>
<li><strong>Resist DNS attacks</strong></li>
<li><strong>And&#8230;</strong></li>
<li><strong>Seamless to the users</strong></li>
</ul>
<h3><strong><span style="color: #000080">Q:      You haven&#8217;t said anything about SSO to other apps?</span></strong></h3>
<p><span style="color: #000000">A:    You haven&#8217;t asked. </span></p>
<h3><span style="color: #000080"><strong>Q:   I have other SaaS (Concur, Salesforce) Apps &#8211; can SecureAuth help?</strong></span></h3>
<p>A:  Yes &#8211; <a href="http://www.gosecureauth.com/solutions/cloud/googleapps.aspx">SecureAuth for Google</a> provides TRUE web SSO between multiple SaaS apps &#8211; the user does NOT need to log on again.   And can conduct, first &#8211; an internal authentication &#8211; or an external authentication.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/SecureAuth_for_SaaS_SSO_Google3.jpg"><img class="aligncenter size-full wp-image-2326" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/SecureAuth_for_SaaS_SSO_Google3.jpg" alt="" width="575" height="368" /></a></p>
<p style="text-align: left"><strong>Image #2: </strong> SecureAuth provides SSO into Google and other SaaS applications, in addition&#8230;</p>
<h3><span style="color: #000080"><strong>Q:   I have on-premise Web Apps (ASP.NET, IBM WebSphere, Oracle WebLogic &#8211; I would like SSO into &#8211; can SecureAuth help? </strong></span></h3>
<p>A:  Yes &#8211; SecureAuth provides TRUE web SSO between Google and on-premise web applications.  In a secure manner that doesn&#8217;t require extra proxy components.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/SecureAuth_for_web_sso_Google1.jpg"><img class="aligncenter size-full wp-image-2324" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/SecureAuth_for_web_sso_Google1.jpg" alt="" width="576" height="335" /></a></p>
<p style="text-align: left"><strong>Image #3:</strong> SecureAuth also provides SSO into the legacy on-premise applications for Google deployments.</p>
<h3><strong>Q:    OK &#8211; SaaS SSO and Web SSO &#8211; do I have to build my own portal?</strong></h3>
<p><strong>A: </strong> No &#8211; that&#8217;s the coolest thing about SecureAuth 6.2 &#8211; it has a portal built in for both Web and SaaS SSO.</p>
<p>It is the only SSO appliance that has built in:</p>
<ul>
<li><strong>Web/SaaS Portal</strong></li>
<li><strong>SAML Support  (1.1, 2.0)</strong></li>
<li><strong>OpenID Support</strong></li>
<li><strong>OAUTH Support</strong></li>
<li><strong>Microsoft FBA Suport </strong></li>
<li><strong>Sharepoint Support</strong></li>
<li><strong>IBM LTPA Support</strong></li>
<li><strong>WebService Authenticaiton Support</strong></li>
<li><strong>And:</strong>
<ul>
<li><strong>2-Factor Authentication</strong></li>
<li><strong>Password Reset</strong></li>
<li><strong>User Self-Management</strong></li>
<li><strong>Help Desk Support</strong></li>
</ul>
</li>
</ul>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/secureauth-portal.jpg"><img class="aligncenter size-full wp-image-2304" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/secureauth-portal.jpg" alt="" width="486" height="541" /></a></p>
<p><strong>Image #4: </strong>SecureAuth has a built-in SaaS/Web SSO portal for Google and other apps.</p>
<h3><span style="color: #000080"><strong>Q:    What about mobile &#8211; does SecureAuth do anything for my mobile users?</strong></span></h3>
<p><strong>A: </strong>Yes &#8211; SecureAuth solves the (2) hardest problems for mobile users:</p>
<ul>
<li><strong>Deployment</strong></li>
<li><strong>Security</strong></li>
</ul>
<p>Secureauth is able to provision the mobile user with:</p>
<ul>
<li><strong>Google ID</strong></li>
<li><strong>Google Domain</strong></li>
<li><strong>Google Password</strong></li>
</ul>
<p>Without the user or the enterprise knowing the Google ID or password.   It&#8217;s a really amazing solution that Google is recommending to their customers.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/iOS-Google-w-SecureAuth-w-yellow2.jpg"><img class="aligncenter size-full wp-image-2334" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/iOS-Google-w-SecureAuth-w-yellow2.jpg" alt="" width="574" height="300" /></a></p>
<p style="text-align: left"><strong>Image #5: </strong><a href="http://blog.gosecureauth.com/blog/secureauth-auto-apple-ios-provisioning-of-accounts-for-google-apps"> SecureAuth provision the iOS device</a> with the user&#8217;s Google ID and Password and at the same time provisions the ID/Password at Google &#8211; for a painless helpdesk free iOS provisioning process to Google.</p>
<p style="text-align: left">&#8211;</p>
<p style="text-align: left">It&#8217;s really a very powerful story &#8211; <a href="http://www.gosecureauth.com/solutions/cloud/googleapps.aspx">SecureAuth Google</a> &#8211; and we highly recommend you <a href="mailto:sales@gosecureauth.com">contact us</a> to learn more.</p>
<p>﻿—</p>
<p><a href="mailto:ggrajek@gosecureauth.com">Garret Grajek</a> is CTO and a  co-founder of <a href="http://www.gosecureauth.com/">SecureAuth</a>.    SecureAuth is a single appliance solution that delivers configurable 2-Factor  and SSO authentication for Web, VPN and SaaS based solutions.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/im-going-to-google-why-should-i-look-secureauth/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2011 Another Record Year For SecureAuth</title>
		<link>http://blog.gosecureauth.com/blog/2011-another-record-year-for-secureauth</link>
		<comments>http://blog.gosecureauth.com/blog/2011-another-record-year-for-secureauth#comments</comments>
		<pubDate>Thu, 19 Jan 2012 21:12:35 +0000</pubDate>
		<dc:creator>Craig</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[SecureAuth Mobile iOS Cloud Computing]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2221</guid>
		<description><![CDATA[Thank you to all of our customers and partners for making 2011 another record year for SecureAuth Corporation. We added over 100 of the biggest names in business and government to our customer list last year and Q1 is already busier than ever. Stay tuned for major product announcements in a few weeks at the [...]]]></description>
			<content:encoded><![CDATA[<p>Thank you to all of our customers and partners for making 2011 another record year for <a href="http://www.gosecureauth.com ">SecureAuth Corporation</a>. We added over <a href="http://www.gosecureauth.com/clients/default.aspx">100 of the biggest names</a> in business and government to our customer list last year and Q1 is already busier than ever. Stay tuned for major product announcements in a few weeks at the RSA show that will broaden our <a href="http://www.gosecureauth.com/solutions/cloud/default.aspx">Cloud</a> and <a href="http://blog.gosecureauth.com/blog/secureauth-auto-apple-ios-provisioning-of-accounts-for-google-apps">Mobile</a> platform even more.</p>
<p><strong>For details visit:</strong><br />
<a href="http://www.marketwatch.com/story/secureauth-closes-2011-fourth-consecutive-year-of-record-growth-2012-01-19"><img class="alignleft size-full wp-image-2228" title="marketwatch" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/marketwatch.jpg" alt="" width="146" height="44" />&nbsp;&nbsp;</a> <a href="http://www.marketwatch.com/story/secureauth-closes-2011-fourth-consecutive-year-of-record-growth-2012-01-19">SecureAuth Closes 2011: Fourth Consecutive Year of Record Growth</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/2011-another-record-year-for-secureauth/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecureAuth joins Cloud Sherpas 2012 Sales Kickoff!</title>
		<link>http://blog.gosecureauth.com/blog/secureauth-kicks-off-cloud-sherpas-2012-sales-meeting</link>
		<comments>http://blog.gosecureauth.com/blog/secureauth-kicks-off-cloud-sherpas-2012-sales-meeting#comments</comments>
		<pubDate>Thu, 19 Jan 2012 14:22:52 +0000</pubDate>
		<dc:creator>Garret</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=2206</guid>
		<description><![CDATA[It was an honor to be invited and present, in person, for the newly annointed #1 Google Authorized Reseller in the world &#8211; Cloud Sherpas. &#160; Image #1 &#8211; The assembled Cloud Sherpas team for their 2012 Sale kick-off. Cloud Sherpas is the enterprise Google reseller &#8211; and now a worldwide reseller.  With expansion across [...]]]></description>
			<content:encoded><![CDATA[<p>It was an honor to be invited and present, in person, for the newly annointed #1 Google Authorized Reseller in the world &#8211; <a href="http://www.cloudsherpas.com/">Cloud Sherpas</a>.</p>
<p>&nbsp;</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/2012-01-18_16-47-31_385.jpg"><img class="aligncenter size-large wp-image-2207" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/2012-01-18_16-47-31_385-1024x768.jpg" alt="" width="590" height="442" /></a><strong>Image #1</strong> &#8211; The assembled Cloud Sherpas team for their 2012 Sale kick-off.</p>
<p>Cloud Sherpas is the enterprise Google reseller &#8211; and now a worldwide reseller.  With expansion across the U.S. and Asia Pacific through aggressive acquisitions.    Cloud Sherpas is truly poised to be the major player in Google integrations, across the globe.</p>
<p>And that&#8217;s why Cloud Sherpas became and <a href="http://www.cloudsherpas.com/partners/single-sign-on-sso/secureauth/">early partner</a> of <a href="http://www.gosecureauth.com">SecureAuth</a> &#8211; for the purpose of integrating and deploying security minded and enterprise level customer.</p>
<p>SecureAuth is that solution &#8211; and the right solution for enterprises that are trying to INTEGRATE google into their current enterprise.   Whether that means:</p>
<ul>
<li>Integration with their current Data Store (AD</li>
<li>Integration with their current Apps  (.NET, ShaprePoint, WebLogic, etc)</li>
<li>Integration with their other SaaS apps  (Salesforce, Concur, Workday, etc)</li>
<li>Integration with their mobile devices</li>
</ul>
<p>On the last point &#8211; SecureAuth was able to impress the extended team (above) with SecureAuth world-unique integration into <a href="http://blog.gosecureauth.com/blog/secureauth-auto-apple-ios-provisioning-of-accounts-for-google-apps">Apple iOS devices for Google.</a> SecureAuth can provision a user to utilize Google Apps:</p>
<ul>
<li>Without the user knowing their Google Domain Name</li>
<li>Without the user knowing their Google ID</li>
<li>Without the user knowing thier Google password</li>
</ul>
<p>And the enterprise does not need ot know the Google password of the user as well.   It&#8217;s an amazing integration that has impressed both Cloud Sherpas and Google.   (See <a href="http://www.youtube.com/watch?v=tnG3auXeClc">YouTube </a>video).</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/ios-provision.jpg"><img class="aligncenter size-full wp-image-2210" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/ios-provision.jpg" alt="" width="470" height="353" /></a><strong> </strong></p>
<p style="text-align: left"><strong>Image #2:</strong> SecureAuth showed it&#8217;s amazing new <a href="http://blog.gosecureauth.com/blog/secureauth-auto-apple-ios-provisioning-of-accounts-for-google-apps">Apple iOS Google provisioning product</a> at the event.</p>
<p>But back to our freinds at Cloud Sherpas.</p>
<p>It&#8217;s been amazing ride for the founders of Cloud Sherpas,  Michael Cohn, Eran Gil and David Hoff.   (See Eran and David below.) All of us at SecureAuth tip our hats to their amazing work, passion for accomplishment and vision.   Here&#8217;s to 2012.</p>
<p style="text-align: center"><a href="http://blog.gosecureauth.com/wp-content/uploads/2012/01/2012-01-18_16-48-44_642.jpg"><img class="aligncenter size-large wp-image-2211" src="http://blog.gosecureauth.com/wp-content/uploads/2012/01/2012-01-18_16-48-44_642-1024x768.jpg" alt="" width="430" height="323" /></a><strong> </strong></p>
<p style="text-align: left"><strong>Image #3: </strong>Cloud Sherpas founders:  Eran Gil and David Hoff.   (Michael Cohn not in picture.)</p>
<p style="text-align: left">—<br />
<a href="mailto:ggrajek@gosecureauth.com">Garret Grajek</a> is CTO and a co-founder of <a href="http://www.gosecureauth.com/">SecureAuth</a>.    SecureAuth is a single appliance solution that delivers configurable  2-Factor and SSO authentication for Web, VPN and SaaS based solutions.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/secureauth-kicks-off-cloud-sherpas-2012-sales-meeting/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

