<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecureAuth Blog &#187; cloud security</title>
	<atom:link href="http://blog.gosecureauth.com/tag/cloud-security/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.gosecureauth.com</link>
	<description>SecureAuth Blog</description>
	<lastBuildDate>Mon, 14 May 2012 04:28:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>SecureAuth already mitigates the risk of the ASP.NET vulnerability (CVE-2010-3332)</title>
		<link>http://blog.gosecureauth.com/blog/secureauth-already-mitigates-the-risk-of-the-asp-net-vulnerability-cve-2010-3332</link>
		<comments>http://blog.gosecureauth.com/blog/secureauth-already-mitigates-the-risk-of-the-asp-net-vulnerability-cve-2010-3332#comments</comments>
		<pubDate>Thu, 23 Sep 2010 01:23:11 +0000</pubDate>
		<dc:creator>Milton</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[2factor]]></category>
		<category><![CDATA[ASP.NET]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[Identity Management]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[RSA Alternatives]]></category>
		<category><![CDATA[SecureAuth]]></category>
		<category><![CDATA[secureID]]></category>
		<category><![CDATA[SharePoint]]></category>
		<category><![CDATA[two factor]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=1097</guid>
		<description><![CDATA[Microsoft recently released Microsoft Security Advisory (2416728) about a vulnerability (CVE-2010-3332) in ASP.NET that allows the unauthorized access  to files that can contain sensitive data within an ASP.NET application such as web.config, and be able decrypt data sent to the client.  Microsoft has released a work around for the vulnerability, but they do not have [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft recently released <a href="https://www.microsoft.com/technet/security/advisory/2416728.mspx">Microsoft Security Advisory (2416728)</a> about a vulnerability (<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3332">CVE-2010-3332</a>) in ASP.NET that allows the unauthorized access  to files that can contain sensitive data within an ASP.NET application such as web.config, and be able decrypt data sent to the client.  Microsoft has released a work around for the vulnerability, but they do not have a patch out at this time.</p>
<p>Customers utilizing SecureAuth® <a href="http://www.multifa.com/multifactor-authentication-products/ms-apps.aspx">Identity Enforcement Platform</a> are already mitigating this risk from outside attackers for their ASP.NET applications.  Customers who have integrated their ASP.NET applications with SecureAuth® <a href="http://www.multifa.com/multifactor-authentication-products/ms-apps.aspx">Identity Enforcement Platform</a> are thwarting attackers who wish to utilize this attack by forcing strong bilateral authentication that authenticates both the user and the server before communication is allowed to the ASP.NET application.  Because the attackers are unable to communicate to the customer’s ASP.NET applications, such as Microsoft SharePoint 2010, the risk of this vulnerability has been mitigated from the unauthorized users.</p>
<p>In fact, SecureAuth is the only “Authentication Provider” that provides strong authentication for Microsoft SharePoint 2010 that is token-less, non-phishable, authenticates both the user and the server , easy to deploy, and does not require any agent, proxy, or VPN to be installed.</p>
<p><a href="http://www.multifa.com/contact-multi-factor-authentication-company/default.aspx">Contact us</a> to find out about what people are calling the “Game Changer” when it comes to a strong authentication and true identity enforcement that is also a 2-Factor, Web Single-Sign-On, and Identity Management solution that is low cost and easy to deploy.</p>
<p>SecureAuth believes in a defense-in-depth strategy and recommends that you patch this vulnerability once a patch is released.</p>
<p>More information about this vulnerability and work around can be found at:</p>
<p><a href="https://www.microsoft.com/technet/security/advisory/2416728.mspx">Microsoft Security Advisory (2416728)</a></p>
<p>Scott Guthrie’s Blogs: <a href="http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx">Important: ASP.NET Security Vulnerability</a> and <a href="http://weblogs.asp.net/scottgu/archive/2010/09/20/frequently-asked-questions-about-the-asp-net-security-vulnerability.aspx">Frequently Asked Questions about the ASP.NET Security Vulerability</a></p>
<p><a href="http://blogs.msdn.com/b/sharepoint/archive/2010/09/21/security-advisory-2416728-vulnerability-in-asp-net-and-sharepoint.aspx">Microsoft SharePoint Team Blog</a></p>
<p><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3332">CVE-2010-3332</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/secureauth-already-mitigates-the-risk-of-the-asp-net-vulnerability-cve-2010-3332/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA and VeriSign Partner on Cloud-Based OTP Service</title>
		<link>http://blog.gosecureauth.com/blog/373</link>
		<comments>http://blog.gosecureauth.com/blog/373#comments</comments>
		<pubDate>Thu, 22 Oct 2009 00:00:33 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[2factor]]></category>
		<category><![CDATA[cloud authentication]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[googleapps]]></category>
		<category><![CDATA[multifactor]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[secureID]]></category>
		<category><![CDATA[two factor]]></category>
		<category><![CDATA[verisign]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=373</guid>
		<description><![CDATA[RSA and VeriSign Partner on Cloud-Based OTP Service http://www.rsa.com/press_release.aspx?id=10462 This is an interesting response to MultiFactor Corporation’s cloud solution.   Having RSA and VeriSign try to tweak and then reposition what many view as cumbersome, old, expensive technology as “cloud-based” is validation of SecureAuth and our vision.  However, the problem is that their joint solution delivers [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;">RSA and VeriSign Partner on Cloud-Based OTP Service</p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><a href="http://www.rsa.com/press_release.aspx?id=10462"><strong><span style="font-size: 10.5pt; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; mso-font-kerning: 18.0pt;">http://www.rsa.com/press_release.aspx?id=10462</span></strong></a><strong></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;">This is an interesting response to MultiFactor Corporation’s cloud solution.<span style="mso-spacerun: yes;">  </span><span style="mso-spacerun: yes;"> </span>Having RSA and VeriSign try to tweak and then reposition what many view as cumbersome, old, expensive technology as “cloud-based” is validation of SecureAuth and our vision.<span style="mso-spacerun: yes;">  </span>However, the problem is that their joint solution delivers primarily on buzz words while keeping the hassles and challenges that users want to be free from.<span style="mso-spacerun: yes;">  </span>SecureAuth was designed from its inception on modern web architecture to provide its customers true browser-based, strong, secure access without the cost and burden of special hardware or client software. <span style="mso-spacerun: yes;"> </span><span style="mso-spacerun: yes;"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;">According to the headline on the joint press release, the new arrangement <strong><em>“</em></strong></span></span><strong><em><span style="font-weight: normal; font-size: 9pt; color: black; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;; mso-bidi-font-weight: bold;">allows channel partners to offer users managed, shared authentication to access multiple Websites”</span></em></strong><strong><span style="font-size: 9pt; color: black; line-height: 115%; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">.</span></strong><span style="font-size: small;"><span style="font-family: Calibri;"><span style="mso-spacerun: yes;">  </span><span style="mso-spacerun: yes;"> </span>It appears that you will need every user to own and carry an RSA SecurID token to access VeriSign VIP which then can be configured by their partners to let you into other “participating” websites.<span style="mso-spacerun: yes;">  </span><span style="mso-spacerun: yes;"> </span>What’s left out are enterprise applications and networks (VPNs). <span style="mso-spacerun: yes;"> </span>Additionally, users still need to type in little numbers from a plastic token or fat mobile phone application every time they log-in. <span style="mso-spacerun: yes;"> </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;">Quote from the release:<span style="mso-spacerun: yes;">  </span><em>&#8220;The alliance of two powerhouses with the integration of RSA SecurID technology into VIP will strengthen their combined market </em></span></span><a href="http://www.channelinsider.com/" target="_blank"><em><span style="color: windowtext; text-decoration: none; text-underline: none;"><span style="font-size: small; font-family: Calibri;">leadership</span></span></em></a><span style="font-size: small;"><span style="font-family: Calibri;"><em> and work to increase the collective clout of both VeriSign and RSA&#8221;.</em><span style="mso-spacerun: yes;">  </span><span style="mso-spacerun: yes;"> </span>We hope to keep our customers happy with an innovative product and good service, rather than wielding clout. <span style="mso-spacerun: yes;">  </span>Sounds like they want to keep customers locked into a lucrative, albeit dying, OTP cash cow business for both of them.<span style="mso-spacerun: yes;">  </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Calibri;">If you are truly interested in a two factor authentication and identity solution that has been designed to meet enterprise cloud security needs, please allow MultiFactor to show you what our customers know:<span style="mso-spacerun: yes;">  </span>There is a better alternative to RSA SecurID and VeriSign.<span style="mso-spacerun: yes;">  </span>Of course, we also can offer the same, singular solution for secure websites, web applications, enterprise applications, identity management systems, IPSec VPNs and SSL VPNs. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;">In the next post we’ll explore how these dinosaurs are responding with their own SecurID token alternatives.<span style="mso-spacerun: yes;">   </span>RSA calls it the “RSA Decision Tree”.<span style="mso-spacerun: yes;">  </span>For those willing to give up more security and flexibility, they’ll go a bit easier on the price.<span style="mso-spacerun: yes;">  </span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/373/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cloud Security Concerns (that is what we are here for)</title>
		<link>http://blog.gosecureauth.com/blog/cloud-security-concerns-that-is-what-we-are-here-for</link>
		<comments>http://blog.gosecureauth.com/blog/cloud-security-concerns-that-is-what-we-are-here-for#comments</comments>
		<pubDate>Tue, 18 Aug 2009 20:58:06 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[cloud identity]]></category>
		<category><![CDATA[cloud migration]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[cloud SSO]]></category>
		<category><![CDATA[SaaS authentication]]></category>

		<guid isPermaLink="false">http://blog.gosecureauth.com/?p=274</guid>
		<description><![CDATA[    Good article in IBD http://tiny.cc/Cloud246 back in June I came across discussing the growth of cloud computing from a business perspective.  Cloud security seems to be one of the few concerns restraining the rapid adoption.  We see ourselves as an enabler which mitigates security while retaining the promise of low cost and flexibility of cloud computing.     [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"> </p>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"> </p>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"><span style="COLOR: #1f497d"><span style="font-size: small;"><span style="font-family: Consolas;">Good article in IBD <span style="COLOR: #1f497d"><span style="font-size: small;"><span style="font-family: Consolas;"><span style="color: #0000ff;"><a href="http://tiny.cc/Cloud246">http://tiny.cc/Cloud246</a></span></span></span></span> back in June I came across discussing the growth of cloud computing from a business perspective.  Cloud security seems to be one of the few concerns restraining the rapid adoption.  We see ourselves as an enabler which mitigates security while retaining the promise of low cost and flexibility of cloud computing.  </span></span></span></p>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"> </p>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"> <span style="COLOR: #1f497d"><span style="font-size: small;"><span style="font-family: Consolas;">Quote from <span style="color: #000000;">Investor&#8217;s Business Daily, June 9, 2009</span>:</span></span></span></p>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"> </p>
<blockquote>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Consolas;"><em>&#8220;Cloud computing&#8217;s growth is outpacing the industry overall. Global revenue from cloud services is expected to jump 21% this year to $56.3 billion from $46.4 billion, says market-tracker Gartner. It sees sales of more than $150 billion in 2013.</em></span></p>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Consolas;"><em>These (business) efforts highlight the growing acceptance of cloud computing, even as executives concede concerns remain.</em></span></p>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Consolas;"><em>There are downsides, perhaps led by technical issues in integrating cloud computing with an existing network. <strong>Some critics also question reliability and whether users lose some control over security.&#8221; </strong></em></span></p>
</blockquote>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"><span style="font-size: small; font-family: Consolas;">That last sentence is the key to MultiFactor&#8217;s SecureAuth value proposition.  SecureAuth automatically enforces identity policy already built into an enterprise&#8217;s existng directory.  The administrator retains total control over access to cloud applications while securing those cloud applications from unauthorized access.  </span></p>
<p class="MsoPlainText" style="MARGIN: 0in 0in 0pt"> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.gosecureauth.com/blog/cloud-security-concerns-that-is-what-we-are-here-for/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

