Re: No lockout policy... why not?



Dave Nickason [SBS MVP] wrote:
The biggest thing that relieves my anxiety about remote access
attacks is two-factor authentication. This applies to all of the
accounts, not just Administrator. I'm currently using Cryptocard,
but a more appropriate SBS-sized solution has been released since I
bought Cryptocard. Without the authentication token and PIN, you
can't even get to a password prompt to attempt to use a Windows
password.
See http://www.scorpionsoft.com/ or come to Jeff Middleton's NOLA
conference to check this out for yourself
http://www.conference2007.sbsmigration.com/


I think we're long over due on two (or multi) factor authentication
everywhere. Nice link Dave, thanks.
--
/kj


.



Relevant Pages

  • Re: FW1 Authentication and WWW Server Authentication
    ... OK got it to work if I use the following format in the password prompt ... > I am implementing "SSL User authentication with the HTTP Security Server" ... > If I input the FW username/password I get a new password prompt: ...
    (comp.security.firewalls)
  • Re: Q: pub key login still asks for password??
    ... > is prevent ssh from trying to read anything from the terminal; ... Jason doesnt state that his authentication was failing - he states that he ... and that is why he received a password prompt. ... my key is authenticated because I will still get a successful connection. ...
    (comp.security.ssh)
  • Re: Q: pub key login still asks for password??
    ... Both you and Darren suggest that the key authentication failed, ... > and that is why he received a password prompt. ... encrypted keys on disk keys available to the client -- more than the ... which succeeds without user interaction. ...
    (comp.security.ssh)
  • Re: Sign On Authentication
    ... >>Isn't this normally done with a username and password prompt? ... A user name and prompt can be passed from Bob ... > X to Charles Y and Charles Y can then take the test for Bob X. ... there are very few things you can use for authentication that are ...
    (sci.crypt)
  • Re: Sign On Authentication
    ... >>Isn't this normally done with a username and password prompt? ... A user name and prompt can be passed from Bob ... > X to Charles Y and Charles Y can then take the test for Bob X. ... there are very few things you can use for authentication that are ...
    (comp.security.misc)

Loading