<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Stronger and simpler authentication</title>
	<atom:link href="http://blogs.kuppingercole.com/kuppinger/2009/06/30/stronger-and-simpler-authentication/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.kuppingercole.com/kuppinger/2009/06/30/stronger-and-simpler-authentication/</link>
	<description>KuppingerCole</description>
	<lastBuildDate>Wed, 08 Feb 2012 09:08:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Neil</title>
		<link>http://blogs.kuppingercole.com/kuppinger/2009/06/30/stronger-and-simpler-authentication/comment-page-1/#comment-160</link>
		<dc:creator>Neil</dc:creator>
		<pubDate>Mon, 10 Aug 2009 09:41:04 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.kuppingercole.com/kuppinger/?p=189#comment-160</guid>
		<description>Actually, we thought up a way round that too, it&#039;s a PoC at present, but usign the base concept, then add in a transaction specific grID, and a second channel...   Simple for the user, no additional hardware &amp; secure from MitM. </description>
		<content:encoded><![CDATA[<p>Actually, we thought up a way round that too, it&#039;s a PoC at present, but usign the base concept, then add in a transaction specific grID, and a second channel&#8230;   Simple for the user, no additional hardware &amp; secure from MitM.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack</title>
		<link>http://blogs.kuppingercole.com/kuppinger/2009/06/30/stronger-and-simpler-authentication/comment-page-1/#comment-115</link>
		<dc:creator>Jack</dc:creator>
		<pubDate>Thu, 02 Jul 2009 19:57:22 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.kuppingercole.com/kuppinger/?p=189#comment-115</guid>
		<description>Wouldn&#039;t this be susceptible to a Man in the Middle attack, just like using a more conventional One Time Password would be?  The attack is: (1) website displays grid to MITM; (2) MITM displays grid to victim; (3) victim enters correct sequence of numbers; (4) MITM collects correct sequence of numbers and replays to website. 
 
I wish someone would come up with a way of making client-side certificates practical.  Wouldn&#039;t that be the best way to do strong authentication? </description>
		<content:encoded><![CDATA[<p>Wouldn&#039;t this be susceptible to a Man in the Middle attack, just like using a more conventional One Time Password would be?  The attack is: (1) website displays grid to MITM; (2) MITM displays grid to victim; (3) victim enters correct sequence of numbers; (4) MITM collects correct sequence of numbers and replays to website. </p>
<p>I wish someone would come up with a way of making client-side certificates practical.  Wouldn&#039;t that be the best way to do strong authentication?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stronger and simpler authentication &#124; Martin Kuppinger</title>
		<link>http://blogs.kuppingercole.com/kuppinger/2009/06/30/stronger-and-simpler-authentication/comment-page-1/#comment-114</link>
		<dc:creator>Stronger and simpler authentication &#124; Martin Kuppinger</dc:creator>
		<pubDate>Tue, 30 Jun 2009 19:19:37 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.kuppingercole.com/kuppinger/?p=189#comment-114</guid>
		<description>[...] See the original post here:  Stronger and simpler authentication &#124; Martin Kuppinger [...]</description>
		<content:encoded><![CDATA[<p>[...] See the original post here:  Stronger and simpler authentication | Martin Kuppinger [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: code technology</title>
		<link>http://blogs.kuppingercole.com/kuppinger/2009/06/30/stronger-and-simpler-authentication/comment-page-1/#comment-113</link>
		<dc:creator>code technology</dc:creator>
		<pubDate>Tue, 30 Jun 2009 17:15:39 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.kuppingercole.com/kuppinger/?p=189#comment-113</guid>
		<description>The appeal, of course, is that the organization doesn&#039;t have to provision a physical device or card.  And unlike SMS text and grid cards, the memorizing of a pattern eliminates the risk of interception (except for the call center identity verification where the user entered from grid card). 
 
Potentially brilliant... any known holes? 
 
Mike </description>
		<content:encoded><![CDATA[<p>The appeal, of course, is that the organization doesn&#039;t have to provision a physical device or card.  And unlike SMS text and grid cards, the memorizing of a pattern eliminates the risk of interception (except for the call center identity verification where the user entered from grid card). </p>
<p>Potentially brilliant&#8230; any known holes? </p>
<p>Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jackson</title>
		<link>http://blogs.kuppingercole.com/kuppinger/2009/06/30/stronger-and-simpler-authentication/comment-page-1/#comment-111</link>
		<dc:creator>Jackson</dc:creator>
		<pubDate>Tue, 30 Jun 2009 16:40:53 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.kuppingercole.com/kuppinger/?p=189#comment-111</guid>
		<description>This is exactly why we OEM&#039;ed GrIDsure for our Defender product here at Quest Software.  </description>
		<content:encoded><![CDATA[<p>This is exactly why we OEM&#039;ed GrIDsure for our Defender product here at Quest Software.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

