RE: How to authentificate an user via telephon?

From: Gary Turovsky (GTurovsky@tpgstaffing.com)
Date: 12/06/02

  • Next message: Mark Medici: "RE: How to authentificate an user via telephon?"
    Date: Fri, 6 Dec 2002 11:30:29 -0600
    From: "Gary Turovsky" <GTurovsky@tpgstaffing.com>
    To: "Chris Berry" <compjma@hotmail.com>, <security-basics@securityfocus.com>
    

    > I have to say that I think thats a very insecure
    > authentication method. Our
    > company deals heavily with finding people, and getting
    > information about
    > them, and I can say from experience here that getting
    > someone's SSN and
    > birthdate is a trivial task. You'd be much better off with
    > another system
    > such as the three authenticating questions someone propsed
    > earlier. I also
    > recommend PasswordSafe from www.counterpane.com its a free
    > product that
    > allows you to manage multiple passwords in a secure 448bit blowfish
    > encrypted storage. (that should help your users from forgetting their
    > passwords all the time)

    Except when they forget the passphrase for their encrypted passwords :)



    Relevant Pages

    • Re: Generating passwords
      ... > Passwords are still the most widely used authentication method. ... > They are not prone to false positives and false negatives like biometric ... > VMS and Unix team leader ...
      (comp.security.unix)
    • Re: Generating passwords
      ... >- passwords are obsolete: ... over an insecure link or they are being stored on the system in an insecure ... Passwords are still the most widely used authentication method. ... They are not prone to false positives and false negatives like biometric ...
      (comp.security.unix)
    • Reset/Change Password for Mail box using EPF
      ... in the POP3 server, and I am using the Encrypted Password File ... authentication method. ... How can the users change their mail-box passwords, ...
      (microsoft.public.inetserver.iis.smtp_nntp)
    • Re: What encryption to use on an ipaq.
      ... Now I have a new iPaq and want the same functionality. ... Encrypted storage of passwords and personal codes. ...
      (microsoft.public.pocketpc)