News (38)

Microsoft joins Kerberos single ID consortium

The MIT Kerberos Consortium, a security authentication and authorisation group, announced on Monday that Microsoft has joined its shindig. Read more »

Tokens no silver bullet for security: banks

Authentication tokens used for online transactions will not stop identity theft, banks have warned as they search for other measures to secure customer accounts. Read more »

Cyota gives RSA token-less authentication

RSA Security's proposed acquisition of privately held Cyota will allow the company to offer a relatively cheap two factor, non token-based authentication system for its banking customers. Read more »

RSA to test new Web authentication service

Looking for a way to get its security gadgets into the hands of average consumers, RSA Security plans to test a new Web authentication service. Read more »

Microsoft tries to stop Vista piracy monster

Microsoft has issued an update to Windows Vista that's intended to stop a piracy monster. Read more »

Microsoft to embed Live services in Windows

Microsoft's Live-branded online services don't end at the Web browser. They extend deep into Windows. Read more »

Microsoft launches biometric access peripherals

Microsoft has reacted to concerns over passwords with the launch of a keyboard which uses biometrics to log on users to Web sites but the software giant has admitted the products are for convenience and not security. Read more »

Google adds OAuth to gadget mashups

Google has adopted the OAuth web-authentication standard, an open standard for controlling privacy, for its gadget platform. Read more »

Facebook botnet risk revealed

Researchers have created a proof-of-concept application for Facebook that turned the machines of people who added the app to their Facebook page into elements of a botnet that in a demonstration launched denial-of-service attacks on a victim server. Read more »

US Homeland Security still infected with Trojans?

The man in charge of IT security for the US Homeland Security department may lose his job after the revelations that his department's IT systems have misconfigured firewalls, suspicious botnet activity, trojans and virus infections. Read more »

Features (107)

Authentication caching with nscd

Distributed authentication is increasingly popular as home networks add more computers and business networks continue to expand. Using a central authentication system such as LDAP or NIS with other technologies like Kerberos has become somewhat of a standard in large networks. Read more »

Passwords: poor excuse for security

Cut costs. Save money. Maintain the status quo. With that mantra in mind, many network managers figure they've got authentication covered. As long as there's a password policy in place, who needs to spend money on authentication tools? Read more »

How to build secure ASP.NET applications

ASP.NET provides several ways to protect your Web-based app from attack. Here's an overview of authentication, authorisation, and role-based security. Read more »

Keeping the door open...and shut

A Web server opens up your business to the outside world, so how do you keep out those parts of the world you don't like? Read more »

Secure connections to PostgreSQL

The PostgreSQL database server is arguably one of the best SQL servers available, but it's not as easy for beginners to get a handle on it as with other SQL databases, such as MySQL. Read more »

Master simple forms authentication in .NET

Using forms authentication, you can quickly build a simple, secure Web app. This walk-through shows you how to apply the strategy in your apps. Read more »

Integrate Passport into ASP.NET apps

If you are looking for a secure means to transfer sensitive information in an ASP.NET application, try integrating Microsoft's Passport service. Read more »

Cookieless data persistence is possible

Cookies are a common way to store retrievable user information, such as authentication data. But what if you need a non-cookie solution? Read more »

Control access to .NET Web services

Web services can present problems caused by unauthorised access. These validation methods can help you reduce the risk. Read more »

Maximising IIS logging

Multiple options for logging user access activity are available when you manage Microsoft IIS Web servers. Here are several logging options. Read more »

Blog (1)

One ID to rule them all

Lana Kovacevic [blogs:webanatomy] -- OpenID is an open-source mechanism enabling you to use a single online identity to log-in to different websites that support OpenID. Read more »

Log in


Sign up | Forgot your password?

What's on?