SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Identity Management

Toronto company offers USB token two-fer

Toronto company offers USB token two-fer

By:  Briony Smith  On: 02 Apr 2008 For: ComputerWorld Canada Creator

Diversinet launches a one-time password authentication key that the CEO says will eliminate the PIN challenge that vexes so many users. Why cost is not the only barrier to adoption

Toronto-based security vendor Diversinet announced Wednesday the launch of its one-time password authentication key, the MobiSecure USBToken.

More in ComputerWorld Canada

End the endpoint security breaches

The company has been around for a couple of years, and used to concentrate on soft tokens that transmitted passwords to mobile devices. But, said CEO Albert Wahde, customers had been calling for hard tokens, too, that could be used with their PCs. The new USB-based product contains a PIN challenge and leaves no trace on the user’s computer.

“The one-time password is important,” said Brian Bourne, steering committee member of the Toronto Area Security Klatch, president of CMS Consulting and a contributor to ITWorldCanada’s Security Insider blog. “There could be keyloggers, or, if people are connecting from open wireless networks Internet cafes, or a business centre, so they can’t be trusted…However, almost everyone has that. It isn’t terribly unique.”

MobiSecure USBTokens don’t require any software installation, said Wahde, which is often part of the package with other tokens. Instead, the customer buys the MobiSecure Authentication Server package that provides all the required registration, validation, and token lifecycle management. Said Wahde: “One server infrastructure runs it all.”

This can also come in handy for those on the road. Said Bourne: “You can’t really go around installing device drivers, so the biggest challenge can be if you required a driver and couldn’t install it.”

The solution is geared toward organizations that require strong authentication from many users and device types, especially in the financial, government, and retail sectors, said Wahde. The market is also getting bigger via the growing mobile workforce, including salespeople and road warrior-style execs.

One hole that Bourne sees in the security of these devices, however, are enterprises that don’t implement their protection across the board. He said, “You need to implement it in all of them or none of them. Like if someone is using a token with SharePoint, but not for Terminal Server and Citrix, then that’s kind of silly, and you do see that too often.”

Another barrier to adoption of these technologies, said Wahde, is the cost. Diversinet’s ploy is to offer a two-fer to customers—for every USBToken purchased, the customer will also get a free MobiSecure SoftToken or PCToken. When it comes to actual prices, said Wahde, someone buying in the range of 10,000 units could expect a price of $16 per token (plus the free token).


Sign up for our Newsletters












Print |  Views: 1858   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Briony Smith Briony Smith is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Eyeing risks while cutting costs
Eyeing risks while cutting costsCharged with ensuring the confidentiality, integrity and availability of his company's systems and intellectual property, identifying areas for cost cutting did not come easy for security officer Mathias Thurman. Here are four key cut back areas which he came up with
Microsoft, RIM, Oracle release critical patches
Microsoft, RIM, Oracle release critical patchesPatch Tuesday becomes extra busy as Oracle and RIM joins Microsoft in releasing a bevy security updates
Canadian Liver Foundation takes IT off site
Canadian Liver Foundation takes IT off siteKeeping track of research, fundraising and financial data is difficult for an organization without an in-house IT staff. Why the managed service route trumped retrofitting the server room
Honeypots and the Accidental Hacker
i was intending to post something on the book virtual honeypots: from botnet tracking to intrusion detection, by google engineer niels provos and german grad student

Comments (1)

Subtitle and content mismatch?
by Allan 4/8/2008 12:00:00 AMThe subtitle says it 'will eliminate the PIN challenge that vexes so many users' but the content says 'The new USB-based product contains a PIN challenge...'. So does this mean the user no longer needs to enter a PIN? If so, what is the control if someone steals the USB device if the PIN isn't required?
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.