<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.loghound.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6404704753143794967</id><updated>2012-05-08T18:13:54.932-07:00</updated><category term='mobile'/><category term='HSBC'/><category term='mobile money'/><category term='technology'/><category term='mobile telephony'/><category term='trust'/><category term='obscurity'/><category term='reputation'/><category term='NFC'/><category term='digital footprint'/><category term='seduction'/><category term='privacy'/><category term='hacking'/><category term='paytoo'/><category term='Anonymous'/><category term='RSA'/><category term='2FA'/><category term='#liveensure'/><category term='Epsilon'/><category term='Banks'/><category term='political change'/><category term='SWIFT'/><category term='internet'/><category term='banked'/><category term='Secure Key'/><category term='#innotribe'/><category term='online gaming'/><category term='LANIER'/><category term='TARP'/><category term='IBM'/><category term='hack'/><category term='ID theft'/><category term='one time password'/><category term='TV'/><category term='remittances'/><category term='cyber'/><category term='cyber crime'/><category term='SAAS security'/><category term='internet security'/><category term='authentication'/><category term='online security'/><category term='security'/><category term='Man in the middle'/><category term='lulzsec'/><category term='data privacy'/><category term='two factor authentication'/><category term='bailout'/><category term='parenting'/><category term='Internet future'/><category term='Federal Reserve'/><category term='Google'/><category term='KELLY'/><category term='OpenID'/><category term='device fingerprinting'/><category term='rsac'/><category term='Western Union'/><category term='cloud security'/><category term='telephony'/><category term='payments'/><category term='device ID'/><category term='Wall Street'/><category term='connectivity'/><category term='china'/><category term='Internet of things'/><category term='social media'/><category term='unbanked'/><category term='virtualisation'/><category term='palmtree technology'/><category term='password'/><category term='identity theft'/><title type='text'>Ross Macdonald</title><subtitle type='html'>Musings on the Web, the World and Wonderland...</subtitle><link rel='http://schemas.loghound.com/g/2005#feed' type='application/atom+xml' href='http://www.liveensure.com/blog.phpfeeds/posts/default'/><link rel='self' type='application/atom+xml' href='http:///www.liveensure.com/blog_files/rmfeed.php'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php'/><link rel='hub' href='http://www.liveensure.com/blog.php'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/6404704753143794967/posts/default?start-index=26&amp;max-results=25&amp;orderby=published'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>49</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-4861869386197450251</id><published>2012-03-18T11:13:00.001-07:00</published><updated>2012-03-18T11:20:09.419-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='trust'/><category scheme='http://www.blogger.com/atom/ns#' term='data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile telephony'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile'/><category scheme='http://www.blogger.com/atom/ns#' term='online security'/><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><category scheme='http://www.blogger.com/atom/ns#' term='technology'/><category scheme='http://www.blogger.com/atom/ns#' term='palmtree technology'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>TRUST</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;b&gt;Trust&lt;/b&gt;/trəst/ &amp;nbsp; : &amp;nbsp;&lt;i&gt;Firm belief in the reliability, truth, ability, or strength of someone or something.&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The foundations of the working of human society are built on trust. &amp;nbsp;This has been so since the beginning of recorded history. &amp;nbsp; As our communities evolved from hunter gatherer groups into agricultural chiefdoms, and ultimately modern states their operation, increasing complexity and success relied not only upon our cultural evolution as posited by Robert Wright in Non-Zero (&lt;a href="http://www.nonzero.org/"&gt;Non Zero&lt;/a&gt;) &amp;nbsp;but also upon trust. &amp;nbsp; Trust is integral to our ‘culture.’&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The birth of capitalism and the rapid economic and technological growth of the last five centuries began with the pooling of capital used by investors to underwrite a ships trading expedition called the ‘&lt;i&gt;contratto di commenda&lt;/i&gt;’ . &amp;nbsp;Such ventures could not have happened without the inherent trust that the investors had - that the expedition’s captain would return the profits to the investors.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Today we could not conduct our modern lives without trust. &amp;nbsp;We go about our day with confidence that our utilities will be delivered, that the bus or train we ride on will get us safely to our destination, &amp;nbsp;that the coffee shop we visit maintains acceptable levels of hygiene, &amp;nbsp;that our ISP and our email providers will keep our data confidential. &amp;nbsp; &amp;nbsp;Ah... now that brings up a point. &amp;nbsp; Can we indeed trust our Cloud providers to maintain our privacy and keep our data secure. &amp;nbsp; They may mean well - but can they really do it.? &amp;nbsp; If RSA – that 500 lb security behemoth cannot even keep its servers secure from hackers then who can ? (&lt;a href="http://www.wired.com/threatlevel/2011/03/rsa-hacked/"&gt;RSA hack&lt;/a&gt;) &amp;nbsp;So while we trust our providers to do the best they can – can they actually deliver ? &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;An interesting revelation for me at the recent Global Mobile Congress in Barcelona was the results of a particular piece of market research suggesting that users trust their mobile operators. &amp;nbsp;I guess that comes from many years of generally good, reliable service which has gradually gotten cheaper. &amp;nbsp; But now that data is overtaking voice as the biggest service on the networks - with it comes our mobile Web access and so I would suggest that our faith in MNO’s will start to erode. &amp;nbsp; &amp;nbsp;The migration of hackers and malware from fixed to mobile is happening at the same rate that mobile access is proliferating. (&lt;a href="http://www.guardian.co.uk/technology/2012/jan/30/android-malware-row"&gt;Mobile malware&lt;/a&gt;)&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;There is much FUD out there when it comes to security on the Net and with it an undermining of trust. &amp;nbsp; After all without real security who can you trust? &amp;nbsp; Does all of this mean that the trust evolved and developed over millennia is now in danger of being eroded completely. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;We in our modern connected societies have become ever more suspicious particularly of those in whom we should have ‘trust’ i.e. the State. &amp;nbsp;(&lt;a href="http://heatherbrooke.org/books/silent-state/"&gt;Silent State&lt;/a&gt;) &amp;nbsp;The State has become ever more intrusive into our daily lives and our privacy, &amp;nbsp;which we (maybe not the generation Y’ers) &amp;nbsp;hold dear, &amp;nbsp;is compromised. &amp;nbsp;The same holds true for the Internet age mega corporation – Google and Facebook. &amp;nbsp;Who proudly pronounce the death of privacy. &amp;nbsp; (&lt;a href="http://www.readwriteweb.com/archives/facebooks_zuckerberg_says_the_age_of_privacy_is_ov.php"&gt;Zuckerberg says privacy is dead &lt;/a&gt;)&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;But I digress. &amp;nbsp;Trust is the lubricant of the modern economic engine. &amp;nbsp;Not privacy. &amp;nbsp;If we are to maintain and increase economic growth we need to regain trust particularly when it comes to online transactions. &amp;nbsp; Simply because online is where much of our economic activity is going. &amp;nbsp; We need to find ways in which we can confidently engage online with trust. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;A Single Sign On (SSO) which simplifies the process of accessing so many of the services we use on a daily basis – particularly social media – does not constitute anything more than basic identification. &amp;nbsp;Confirmation of self reported credentials. &amp;nbsp;Neither the site, nor the user can be confident that the other party is legitimate. &amp;nbsp; &amp;nbsp;But SSO is great – because it works (most of the time) and it is easy to use.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Imagine if you could log on and authenticate the session as easily as using an SSO? &amp;nbsp; Imagine if both the site and the user could proceed with a session (transaction / communication/ engagement ) confident that the other party was 100% legitimate and that the communication was secure? &amp;nbsp;(&lt;a href="http://www.liveensure.com/"&gt;LiveEnsure&lt;/a&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;That would bring trust back to the Internet. &amp;nbsp;That would allow us to realize the full potential that the Internet has to offer. &amp;nbsp;That full potential being &amp;nbsp;- &amp;nbsp;much stronger economic growth at a time when the World is in desperate need of good news for its economy !&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-4861869386197450251?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=4861869386197450251' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=4861869386197450251' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=4861869386197450251'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=4861869386197450251'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=4861869386197450251' title='TRUST'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-8884925923678700099</id><published>2012-03-04T15:12:00.000-08:00</published><updated>2012-03-04T15:12:15.226-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='connectivity'/><category scheme='http://www.blogger.com/atom/ns#' term='telephony'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile telephony'/><category scheme='http://www.blogger.com/atom/ns#' term='technology'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet of things'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet future'/><title type='text'>Mobile World Congress - sensory overload</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;The mobile ecosystem is alive and well and flourishing and reflects its current status as the globally dominant (and growing) industry &amp;nbsp;that is becoming increasingly integrated into every aspect of our lives. &amp;nbsp; &amp;nbsp;The Barcelona extravaganza which is notable for two things. &amp;nbsp;Firstly its sheer size – upwards of 60 000 delegates dwarfing anything ever held in Cannes ( when I last visited the show) and secondly, &amp;nbsp;the absence of the largest company in the sector – Apple. &amp;nbsp; Never known to follow the crowd – Apple rightly or wrongly uses its own platform ( in San Francisco) &amp;nbsp;to make its announcements and thereby retains its mystique or displays its sheer arrogance – depending on your perspective. &lt;br /&gt;&lt;br /&gt;That Mobile will continue to permeate every aspect of modern life is beyond doubt. &amp;nbsp; The first phase of GSM where voice was the killer app has now been replaced by data and most particularly Internet access and mobile applications. &amp;nbsp;So Mobile expands beyond the MNO realm and extends into Broadband where WIFI connectivity has become a key strategy for MNO’s to relieve the burden on their networks. &amp;nbsp; We now live in a truly connected world with almost as many mobile connections as there are people on the planet which recently hit the 7bn mark. &amp;nbsp;In addition there are over 1bn Broadband connections and this is growing at over 30% per annum. &amp;nbsp; &amp;nbsp;The global mobile industry generates $1.5trillion in revenues and almost $200bn is invested in Capex every year. ( GSMA )&lt;br /&gt;&lt;br /&gt;The increased access to the Internet is vital to the expansion of knowledge and thereby our ability to solve the seemingly intractable problems facing humanity. &amp;nbsp;Watch this fascinating TED talk on how we can solve these problems with the spread of education, knowledge and ideas all accelerated by the Internet. &amp;nbsp;(&lt;a href="http://www.ted.com/talks/peter_diamandis_abundance_is_our_future.html"&gt;http://www.ted.com/talks/peter_diamandis_abundance_is_our_future.html&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Here’s to the next year of every increasing connectivity and &amp;nbsp;new ideas. &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-K8tSJwwG1nM/T1P2U9AB8KI/AAAAAAAAB38/Jfcex3dVLYo/s1600/IMG_3115.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="239" src="http://3.bp.blogspot.com/-K8tSJwwG1nM/T1P2U9AB8KI/AAAAAAAAB38/Jfcex3dVLYo/s320/IMG_3115.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;The Huawei horse&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-8884925923678700099?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8884925923678700099' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=8884925923678700099' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8884925923678700099'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8884925923678700099'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=8884925923678700099' title='Mobile World Congress - sensory overload'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-K8tSJwwG1nM/T1P2U9AB8KI/AAAAAAAAB38/Jfcex3dVLYo/s72-c/IMG_3115.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-6770865546306778298</id><published>2012-02-01T15:34:00.000-08:00</published><updated>2012-02-01T15:51:08.179-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSA'/><category scheme='http://www.blogger.com/atom/ns#' term='data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='Epsilon'/><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='device ID'/><category scheme='http://www.blogger.com/atom/ns#' term='two factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Time for a new Magic Quadrant</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;You have all heard of the Magic Quadrant. &amp;nbsp;An industry benchmark by which the, mostly, established players like to measure themselves against each other. &amp;nbsp; &amp;nbsp;To quote Wikipedia (that repository of all Internet wisdom ;-))&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;“&lt;i&gt;the Magic Quadrant aims to provide a qualitative analysis into a market and its direction, maturity and participants, thus possibly enabling a company to be a stronger competitor for that market.&lt;/i&gt;” &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The axes of the ‘Quadrant’ are ‘ability to execute’ and ‘completeness of vision’ and the methodology used to apply the ranking remains a closely guarded secret (or mystery depending on how you look at it.) &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The MQ applies to many niches in the tech sector. &amp;nbsp;I want to consider the &amp;nbsp;User Authentication MQ. &amp;nbsp;Notably because the space is getting much media attention these days. &amp;nbsp; Hackers !&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Wikipedia says that the aim of the analysis it is to &amp;nbsp;“ .&lt;i&gt;.enable a company to be a stronger competitor for that market &lt;/i&gt;“ . &amp;nbsp; So you would look at all the players and see ‘ which player you should aspire to be most like.’&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;However there is a small problem in the realm of User Authentication. &amp;nbsp; The companies highlighted in this category represent a very diverse spectrum of enabling technologies all aimed at authenticating users. &amp;nbsp; They range from the industry behemoths like RSA and Vasco to smaller, newer and exciting players like Phone Factor. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;So lets understand exactly what it is that these companies do. &amp;nbsp;They protect their staff, their data, their customers and business partners from the unwanted attentions of hackers who are constantly trying to gain access to their systems and their data. &amp;nbsp; So presumably in order to get into the Magic Quadrant you have to be top of your game? &amp;nbsp; These guys represent the elite of the Authentication industry. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The solutions that they sell (in an industry now worth about $2bn) all fall nicely into one of the following three broad categories:&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;•&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Device recognition –Java Script browser scraping and literal device info recognition&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;•&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Certificates, Cookies, Soft Tokens – downloaded to the device and re-referenced&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;•&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;OTP, Images/Challenges – dongles, PIN generators, SMS OOB&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Considering the industry is replete with all manner of technical wizardry why is it that our headlines continue to read like a hackers dream ( and a CIO’s nightmare). &amp;nbsp;Only last week Zappos was hacked. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;What it means is that these solutions are not working. &amp;nbsp;Yet these companies manage to continue convincing their customers that with ‘their’ solution they are safe! &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;I wonder what CNN moment it will take before businesses and Governments realize that they have been led a merry dance. &amp;nbsp;Another SONY? Epsilon? &amp;nbsp;Or possibly some large critical national infrastructure failing under an attack leading to a disaster like a train or airplane crash or power grid failure. &amp;nbsp; God forbid. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Lets hope sense prevails before we get there. &amp;nbsp;Get Live Ensure. &amp;nbsp;Many are starting to drink the Kool Aid and are seeing the light. &amp;nbsp;Join them.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Maybe it is time for a new MQ.?&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Link:&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;a href="http://www.gartner.com/technology/reprints.do?st=sb&amp;amp;id=1-18UHKYY&amp;amp;ct=120118"&gt;http://www.gartner.com/technology/reprints.do?st=sb&amp;amp;id=1-18UHKYY&amp;amp;ct=120118&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-6770865546306778298?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6770865546306778298' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=6770865546306778298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6770865546306778298'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6770865546306778298'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=6770865546306778298' title='Time for a new Magic Quadrant'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-3481224863183662187</id><published>2012-01-15T16:14:00.000-08:00</published><updated>2012-01-15T16:15:48.444-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bailout'/><category scheme='http://www.blogger.com/atom/ns#' term='Banks'/><category scheme='http://www.blogger.com/atom/ns#' term='Wall Street'/><category scheme='http://www.blogger.com/atom/ns#' term='Federal Reserve'/><category scheme='http://www.blogger.com/atom/ns#' term='TARP'/><title type='text'>The World in a weird place or ( The Truman Show)</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The world is in a very weird place.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;After having read some research (&lt;a href="http://divinecosmos.com/start-here/davids-blog/1023-financial-tyranny"&gt;http://divinecosmos.com/start-here/davids-blog/1023-financial-tyranny&lt;/a&gt;) about how we have all been hoodwinked by the US Fed to the tune of $26trn ( yes &amp;nbsp;- &amp;nbsp;that is trillion not billion ) I am beginning to wonder whether we aren’t all on the set of some giant Truman Show (without the great weather and white picket fences !)&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;So according to this research, &amp;nbsp;which I would have dismissed as some kind of latter day Zeitgeist conspiracy theory if I had not clicked through some of the links and seen an article written by a US Senator ( not that that should somehow give it legitimacy given the intimate role of members of the US Govt in this tragedy), &amp;nbsp;economic power globally rests in the hands of a very tightly knit group of corporations and institutions – mainly banks. &amp;nbsp; Hence the bailouts. &amp;nbsp; &amp;nbsp;Believe me TARP was a tip of the ice-berg. &amp;nbsp;That was like Sunday School collection money. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;So in brief the Federal Reserve ( a private company independent of the US Govt ) prints money and lends it to the US Treasury for use as currency and charges interest. &amp;nbsp;It also prints the money and then lends it to foreign banks. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Now I bet you didn’t know that.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;In fact since 2008 to the tune of $16 trillion. &amp;nbsp; To the likes of Barclays, Deutsche, RBS, UBS plus of course the usual suspects like Goldmans, &amp;nbsp;Citi, &amp;nbsp;BOA, Morgan Stanley &amp;nbsp;and &amp;nbsp;Merril Lynch who each received over $1trn. &amp;nbsp;In fact it is all well documented in an audit (&lt;a href="http://sanders.senate.gov/newsroom/news/?id=9e2a4ea8-6e73-4be2-a753-62060dcbb3c3"&gt;http://sanders.senate.gov/newsroom/news/?id=9e2a4ea8-6e73-4be2-a753-62060dcbb3c3&lt;/a&gt;) of the Fed conducted by the GAO ( General Accountability Office) which is the first time the Fed has ever been audited. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Bet you didn’t know that either !&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;“ &amp;nbsp;&lt;i&gt;The GAO audit also revealed that many of the people who serve as directors of the 12 Federal Reserve Banks come from the exact same financial institutions that the Fed is in charge of regulating.&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;i&gt;Further, the GAO found that at least 18 current and former Fed board members were affiliated with banks and companies that received emergency loans from the Federal Reserve during the financial crisis.&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;i&gt;In other words, the people "regulating" the banks were the exact same people who were being "regulated." Talk about the fox guarding the henhouse!...&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;i&gt;For example, the CEO of JP Morgan Chase served on the New York Fed's board of directors at the same time that his bank received more than $390 billion in financial assistance from the Fed….&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;i&gt;Getting this type of disclosure was not easy. Wall Street and the Federal Reserve fought it every step of the way. “&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;And you wonder why the Occupy movement is so popular?&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;So who is right ? &amp;nbsp; &amp;nbsp;The 99% who want the 1% to pay a fair tax rate. &amp;nbsp; Or the 1% who want to maintain their Uber wealth by keeping their tax rates low. &amp;nbsp; The problem is - &amp;nbsp;it is the 1% who control the economic power and hence the media and hence the politicians. &amp;nbsp; &amp;nbsp;Make your own deductions how this election is going to go. &amp;nbsp; That is of course unless the common man stands up and makes his voice heard and his vote count. &amp;nbsp;It happened in North Africa and the Middle East. &amp;nbsp; Maybe it will start happening in the most unlikely places. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The White House has woken up to SOPA. &amp;nbsp;Is it because Schmidt can muster more resources than Murdoch? &amp;nbsp;Or has sense finally hit home. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;So as I was saying the world is in a very weird place. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;They are even talking about war with Iran. &amp;nbsp; &amp;nbsp;Who are the new Cheneys, &amp;nbsp;Rumsfelds and Wolfowitz’s. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Better pray that they had no heirs.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Was that Jim Carrey I just saw…&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-3481224863183662187?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3481224863183662187' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=3481224863183662187' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3481224863183662187'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3481224863183662187'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=3481224863183662187' title='The World in a weird place or ( The Truman Show)'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-2382821481310154918</id><published>2012-01-01T14:22:00.000-08:00</published><updated>2012-01-01T14:22:32.266-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IBM'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='2FA'/><category scheme='http://www.blogger.com/atom/ns#' term='one time password'/><category scheme='http://www.blogger.com/atom/ns#' term='two factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='NFC'/><title type='text'>The End of Passwords</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Finally it seems … the penny has dropped. &amp;nbsp; Passwords are a poor substitute for real online security. &amp;nbsp; There is more and more ‘chatter’ about it. &amp;nbsp; &amp;nbsp;Robin Henry writing in the Sunday Times on New Years Day talks of the end of ‘password hell’ invoking solutions in the pipeline from the Web Gods – Apple and Google. &amp;nbsp;The talk is of new biometric solutions such as facial and hand movement recognition. &amp;nbsp;Even IBM is talking this way. &amp;nbsp;(&lt;a href="http://www.forbes.com/sites/thestreet/2011/12/20/ibms-tech-predictions-for-the-next-5-years/"&gt;http://www.forbes.com/sites/thestreet/2011/12/20/ibms-tech-predictions-for-the-next-5-years/&lt;/a&gt;)&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;I agree with the notion that passwords are a dying breed but not that biometrics will become vogue. &amp;nbsp; They are fraught with problems of their own such as reliability, accuracy and the need for referencing of data-bases ( fail !) . &amp;nbsp; &amp;nbsp;Why are passwords defunct? &amp;nbsp; Basically they are difficult to remember and they are easy to steal. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The solutions needed are those that require no cognitive load for the user ( the most unreliable participant in this enterprise !) and which will leverage the emergent technologies like smart-phones and tablets. &amp;nbsp;These technologies enable mobile based solutions like SMS out of band and character recognition solutions as well as wireless solutions like NFC. &amp;nbsp; &amp;nbsp;In fact these technologies have created a challenge for the enterprise with these devices being brought into work by employees frustrated with working on antiquated PC’s.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;What is Nirvana ? &amp;nbsp; The user not having to remember anything apart from having his smart-phone on him. &amp;nbsp;Well it seems that people are more inclined to leave their keys or wallet at home than their smart-phone. &amp;nbsp;So all you will need is something that you already have and one which you wont leave at home. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The first step is to log in to the site with your email address (as the identifier). You then engage with a QR code that is delivered to the screen of the device you are logging in on ( even your smart-phone).. A line of sight interaction – you have to present your phone to scan the QR code on the screen. &amp;nbsp;There is no wireless interface a la NFC which is vulnerable to interception. &amp;nbsp;The phone delivers the scanned code back to the site, closing the loop ( triangulation) thereby proving your identity &amp;nbsp;and allowing you to transact. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Nirvana exists. &amp;nbsp;It is called Live Ensure. (&lt;a href="http://www.liveensure.com/"&gt;http://www.liveensure.com&lt;/a&gt;)&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Happy New Year.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-2382821481310154918?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=2382821481310154918' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=2382821481310154918' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=2382821481310154918'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=2382821481310154918'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=2382821481310154918' title='The End of Passwords'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-5538670848725897974</id><published>2011-12-05T07:12:00.001-08:00</published><updated>2011-12-07T05:25:34.226-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='SAAS security'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='one time password'/><category scheme='http://www.blogger.com/atom/ns#' term='two factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='hack'/><title type='text'>You need authentication</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: inherit;"&gt;I am constantly amazed at the lassez faire attitude that the majority of businesses, large and small, have about their online security.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: inherit;"&gt;Those that require their users / members to log on will provide a user name and password log in to verify their identity – and that’s it.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: inherit;"&gt;I suppose that if the large players like Amazon and iTunes can get away with it then the smaller guys think that’s all they need to. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: inherit;"&gt;The reality is that if the big boys get a hit – they have the firepower to deal with it.&amp;nbsp; But SME’s just need one bad hack and they are out of business.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: inherit;"&gt;2011 is going down as the year of the ‘Hack’ &lt;span class="Apple-style-span" style="font-family: inherit;"&gt;(&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.infosecurity-magazine.com/view/22481/year-of-the-hack-/?utm_source=twitterfeed&amp;amp;utm_medium=twitter"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;http://www.infosecurity-magazine.com/view/22481/year-of-the-hack-/?utm_source=twitterfeed&amp;amp;utm_medium=twitter)&amp;nbsp;&lt;/span&gt;&lt;/a&gt;with many high profile victims like SONY, RSA and Epsilon losing millions of their users personal information.&amp;nbsp; &amp;nbsp;&amp;nbsp;Despite this there seems to be the attitude that ‘ &lt;i style="mso-bidi-font-style: normal;"&gt;it cant happen to me’&lt;/i&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp; I have just read about the latest phishing scam targeting Amazon users (&amp;nbsp;&lt;a href="http://bit.ly/tXBENH"&gt;http://bit.ly/tXBENH&lt;/a&gt;&amp;nbsp;)&amp;nbsp;– warning you that your account is about to expire and that you need to re-register.&amp;nbsp; In the process handing over your precious information and opening up your Amazon account to the hacker.&amp;nbsp;&amp;nbsp;&amp;nbsp; There is also one going around for PayPal and Apple at the moment.&amp;nbsp;&amp;nbsp; Yet they persist with user name and password.&amp;nbsp;&amp;nbsp; Incredible.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: inherit;"&gt;&amp;nbsp;I suspect there is a bit of the “ &lt;i style="mso-bidi-font-style: normal;"&gt;it wont happen to me&lt;/i&gt; “&amp;nbsp; but also I believe that most SME owners think that they just can’t afford a proper solution because the image created by the industry is that you have to be a big corporate to have ‘proper’ security. &amp;nbsp;&amp;nbsp;It clearly is not true.&amp;nbsp;&amp;nbsp;&amp;nbsp; There are more and more solutions now targeting the ‘low’ end of the market.&amp;nbsp;&amp;nbsp;&amp;nbsp; While some are &amp;nbsp;‘samey’ to the big guys there are one or two which are really quite unique.&amp;nbsp;&amp;nbsp; What should you look for in such a solution ? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span lang="EN-US"&gt;It needs to be easy to get&lt;/span&gt;&lt;/i&gt;&lt;span lang="EN-US"&gt;.&amp;nbsp;&amp;nbsp; You shouldn’t have to call someone – have someone visit you – do some kind of an IT project.&amp;nbsp; It should be a SAAS service available on line and easy to integrate. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span lang="EN-US"&gt;It needs to be easy to use&lt;/span&gt;&lt;/i&gt;&lt;span lang="EN-US"&gt;.&amp;nbsp;&amp;nbsp; Your users should not have to get some ‘thing’&amp;nbsp; - be it a token ( physical or otherwise ),&amp;nbsp; a dongle,&amp;nbsp; a &amp;nbsp;card reader, a USB key or even a cookie or some kind of software download.&amp;nbsp;&amp;nbsp; Ideally your users should rely on something they already have like their smart-phone or their laptops as part of the solution.&amp;nbsp;&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span lang="EN-US"&gt;It should not cost a lot.&lt;/span&gt;&lt;/i&gt;&lt;span lang="EN-US"&gt; &amp;nbsp;Ideally some kind of ‘Pay as you Go’ solution which means that you don’t incur any unnecessary expenditure upfront in getting the product in place.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="font-family: inherit;"&gt;If you are going for something that is more complicated than that then you are making your life difficult.&amp;nbsp; Check out &lt;a href="http://www.liveensure.com/"&gt;http://www.liveensure.com&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-5538670848725897974?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=5538670848725897974' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=5538670848725897974' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=5538670848725897974'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=5538670848725897974'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=5538670848725897974' title='You need authentication'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-3653370662890576675</id><published>2011-11-05T15:34:00.000-07:00</published><updated>2011-12-06T08:56:37.469-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='connectivity'/><category scheme='http://www.blogger.com/atom/ns#' term='lulzsec'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile telephony'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile'/><category scheme='http://www.blogger.com/atom/ns#' term='online security'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet of things'/><category scheme='http://www.blogger.com/atom/ns#' term='Anonymous'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet future'/><title type='text'>The future is bright and it is mobile (in fact it is here !)</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;There are so many pundits out there who have finally jumped on this bandwagon.&amp;nbsp;&amp;nbsp; But lets be honest, &amp;nbsp;five and a half (or is it now closer to six)&amp;nbsp; billion people, &amp;nbsp;can’t be wrong – the mobile revolution is finishing its transition from what have been predominantly voice services to broad-band data services.&amp;nbsp; The devices that we used to just talk on are now full blown computers and we use them for everything – although we do actually still use them to talk on as well too!.&amp;nbsp; ( See my previous blog: &amp;nbsp;&lt;a href="http://www.liveensure.com/blog.php?id=3493622962031166405"&gt;http://www.liveensure.com/blog.php?id=3493622962031166405&lt;/a&gt;) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;There are so many exciting threads to this trend : the Internet revolution in Africa and other emerging markets,&amp;nbsp; the plethora of new services being created every day that add value to our everyday existence and the emergence of real competition in the mobile handset space.&amp;nbsp;&amp;nbsp; I applaud Microsoft ( and Nokia) for their exciting new partnership and a handset that will create a real challenge to the incumbent behemoths – Android and Apple&amp;nbsp; ( oh and six months ago I would have mentioned BB in the same breath – not anymore…)&amp;nbsp; Check out this video from MS providing their vision of the future - its pretty cool. (&lt;a href="http://www.youtube.com/watch?v=a6cNdhOKwi0"&gt;http://www.youtube.com/watch?v=a6cNdhOKwi0&lt;/a&gt;) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;That increased penetration of the Internet enhances economic performance, &amp;nbsp;is now empirically proven - &amp;nbsp;and so any and all technologies that achieve that end should be pursued with alacrity.&amp;nbsp; The strides in technology over the last decade when 3G first became de rigueur ( driven then mainly by the hardware fraternity keen to flog their wares ) have been immense and helped along irresistibly by the launch of the iPhone in 2007.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;What is perhaps even more daunting/ exciting&amp;nbsp; is the prospect of what will happen in the next ten years when network effects magnify the impact exponentially.&amp;nbsp; By 2020 it is forecast that there will be 50bn connected devices ( it is also called The Internet of Things).&amp;nbsp;&amp;nbsp; &amp;nbsp;These devices will form the basis of an&amp;nbsp;intelligent network fabric encircling us and interacting with us in so many ways – many as yet unimagined.&amp;nbsp; Enhancing our lives and optimizing our use of resources and thereby addressing the pressing challenges of poverty, global warming and water shortages.&amp;nbsp;&amp;nbsp; The interconnectedness of our societies and interdependencies created, &amp;nbsp;will further reduce the prospect of cross-border conflicts and therefore channel&amp;nbsp; taxpayers dollars away from arms towards health, education and infrastructure.&amp;nbsp;&amp;nbsp; It really is a future to be excited and positive about.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;I do believe that many of the limitations that the Internet has today which make so many people suspicious of ‘doing stuff ‘ online will be eliminated.&amp;nbsp; We will feel secure about transacting and it will be a seamless process to verify our transactions and our communications.&amp;nbsp;&amp;nbsp; Consumers will drive businesses who will in turn drive the policy makers to ensure that online security be addressed comprehensively.&amp;nbsp;&amp;nbsp; The recent London Cyber Conference represented the end of the old era of weak intergovernmental decision-making.&amp;nbsp;&amp;nbsp; The imperatives and the importance of tackling this problem will probably be brought home by some kind of a CNN moment (bigger than Stuxnet) and this will bring everyone to their senses.&amp;nbsp; The future Internet cannot operate insecurely and so sense will ultimately prevail.&amp;nbsp;&amp;nbsp; The efforts of Lulzsec and Anonymous have been well intentioned and should not be belittled despite some of their amateurish bravado.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;To get a sense of what this future really holds – take time to watch this video.&amp;nbsp; It is very, very exciting.&amp;nbsp; Here’s to the next 10 years.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: inherit;"&gt;(&lt;a href="http://www.youtube.com/watch?v=R7cuatm_bqw"&gt;http://www.youtube.com/watch?v=R7cuatm_bqw&lt;/a&gt;)&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-3653370662890576675?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3653370662890576675' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=3653370662890576675' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3653370662890576675'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3653370662890576675'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=3653370662890576675' title='The future is bright and it is mobile (in fact it is here !)'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-1244444118556301651</id><published>2011-10-20T15:01:00.000-07:00</published><updated>2011-10-20T15:06:57.741-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SAAS security'/><category scheme='http://www.blogger.com/atom/ns#' term='ID theft'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='2FA'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='device ID'/><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><category scheme='http://www.blogger.com/atom/ns#' term='one time password'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Authentication in ' context'</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;b&gt;con·text&lt;/b&gt;/ˈkäntekst/&lt;br /&gt;&lt;br /&gt;&lt;i&gt;The circumstances that form the setting for an event, statement, or idea, and in terms of which it can be fully understood and assessed.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;authenticate&lt;/b&gt; [ɔːˈθɛntɪˌkeɪt]&lt;br /&gt;vb (tr)&lt;br /&gt;&amp;nbsp;&lt;i&gt;to establish as genuine or valid&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;What does context have to do with authentication?&lt;br /&gt;&lt;br /&gt;When you log on to a web site and enter your user name and password so as to ‘authenticate’ yourself all you are presenting are self reported credentials to the site. &amp;nbsp;If you present the correct credentials then the site accepts you as - who you say you are. &amp;nbsp; It takes you at face value. &amp;nbsp;It identifies you. &amp;nbsp;Liken it to a knight of old arriving at castle and announcing himself. &amp;nbsp; When you log on to a web site and it asks you to log in with a user name and password – you are in effect – announcing yourself – identifying yourself. &amp;nbsp; &lt;br /&gt;&lt;br /&gt;What happens if someone steals your password? &amp;nbsp; Then they can log on as you – the site is none the wiser – the thief has presented the correct credentials. &amp;nbsp;The credentials &amp;nbsp;are by definition – static. &amp;nbsp; They remain valid whether you do so from one of many devices unless of course the site is using a device recognition credential – a cookie, &amp;nbsp;a Javascript based device identification or certificate solution. &amp;nbsp; &amp;nbsp;But again that credential is also static as it is re-used again and again no matter what the ‘context’. &lt;br /&gt;&lt;br /&gt;A hacker can harvest your credentials by one of many methods be they social engineering, key logging, Trojans, &amp;nbsp;Man in the Middle or Browser &amp;nbsp;attacks and so on. &amp;nbsp;The hacker can re-use those credentials in a different ‘context’ (e.g. from another device in another country) but still be regarded as ‘valid’ by the site.&lt;br /&gt;&lt;br /&gt;This is where most so called authentication solutions even two factor authentication solutions fail. &amp;nbsp; They ‘work’ &amp;nbsp;irrespective of the context. &amp;nbsp;Even when an OOB OTP is sent via SMS and the PIN is entered into the browser the same vulnerability exists. &amp;nbsp;A hacker can intercept the PIN and replay the session in real time posing as the ‘real’ person. &amp;nbsp;In other words the OOB pin can be used on a different browser or even session, device or IP address from which they were requested. &amp;nbsp; In other words – a different context. &lt;br /&gt;&lt;br /&gt;So why is context so important.? &amp;nbsp; Context is a function of three elements:&lt;br /&gt;&lt;br /&gt;•&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;u&gt;time&lt;/u&gt; (i.e. the moment of authentication – when it happens, the session &amp;nbsp;) ; &lt;br /&gt;&lt;br /&gt;•&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;u&gt;Method/mode&lt;/u&gt; is the context of origination and transmission – things that dial into the location of the source i.e. the device. &amp;nbsp; Hence the popularity of some device based solutions. &amp;nbsp;Most of which fail because they rely on persistent data ( cookies or Javascript or &amp;nbsp;downloaded software ) because they are easy to fool or copy. &lt;br /&gt;&lt;br /&gt;•&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;&lt;u&gt;Meaning&lt;/u&gt; is the literal value, or meaning of the credentials. &amp;nbsp;This is usually the total sum of the traditional login: &amp;nbsp;User name and password; &amp;nbsp; sometimes ‘beefed’ up perhaps with a time element (timeout) and source (ssl handle, cookie). &amp;nbsp; &amp;nbsp;This is the value of the token or OTP/OOB, the value of the challenge response, etc., i.e. the "thing you know". &amp;nbsp; The site controls the value, the user must know it, get it and repeat &amp;nbsp;it back. &amp;nbsp;( A shared secret ) which is usually the only unique element to the mix, as the other two are re-used, or known.&lt;br /&gt;&lt;br /&gt;The timing of the event is important because the session commences only when all of the key players/participants in the authentication puzzle come together in &lt;b&gt;context &lt;/b&gt;&amp;nbsp;for the act of ‘authentication’. &amp;nbsp; The key constituents are:&amp;nbsp;the user, &amp;nbsp;the device, &amp;nbsp;the site and &amp;nbsp;the session. &lt;br /&gt;&lt;br /&gt;Only when all of these parties (the correct /valid parties) come together i.e. in the right &lt;b&gt;context&lt;/b&gt; - can true authentication take place. &amp;nbsp;None of these elements or even values associated with them like U/P, cookies, &amp;nbsp;JVscript &amp;nbsp;fingerprint or certificate should be able to be used in isolation in another session. &amp;nbsp;In other words in another &lt;b&gt;context&lt;/b&gt; differentiated by time or device. &amp;nbsp;They all need to come together dynamically and uniquely for each session ( context) &amp;nbsp;to ensure integrity. &lt;br /&gt;&lt;br /&gt;So a proper authentication solution is one where all elements (and more) are combined into a single &lt;b&gt;context&lt;/b&gt; - whereby any of the elements in isolation, or out of &lt;b&gt;context&lt;/b&gt;, are meaningless. In addition any element inspected in isolation should not be the key to unlocking or accessing (or guessing) any of &amp;nbsp;the others. They should be dissociative.&lt;br /&gt;&lt;br /&gt;Finally none of the elements from this or any other &lt;b&gt;context&lt;/b&gt; are re-used, at least in their native form. &amp;nbsp; It's okay to re-use a password, or re-challenge the device , but it has to be different by nature of it's membership in the &lt;b&gt;context&lt;/b&gt;, and not meaningful outside of that (which is the source for most MITM, MITB, social engineering, phishing/ pharming, etc).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-1244444118556301651?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1244444118556301651' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=1244444118556301651' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1244444118556301651'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1244444118556301651'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=1244444118556301651' title='Authentication in &apos; context&apos;'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-3493622962031166405</id><published>2011-10-03T15:18:00.000-07:00</published><updated>2011-10-03T15:18:37.598-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='unbanked'/><category scheme='http://www.blogger.com/atom/ns#' term='remittances'/><category scheme='http://www.blogger.com/atom/ns#' term='telephony'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile telephony'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile'/><category scheme='http://www.blogger.com/atom/ns#' term='online security'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile money'/><category scheme='http://www.blogger.com/atom/ns#' term='paytoo'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='payments'/><category scheme='http://www.blogger.com/atom/ns#' term='online gaming'/><title type='text'>HUMAN EVOLUTION AND THE MOBILE</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;We in the southern part of the UK have started to see our Indian summer start to slowly fade as we get into this first week of October. &amp;nbsp; &amp;nbsp;It has been a wonderful but disorientating week with temperatures in the high 20’s (80’s F) – and clear blue skies - I could have sworn this was Jo’burg in Summer. &amp;nbsp; All that was missing was the swimming pools !&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Well I know that parts of the mid-West have also had some great weather. &amp;nbsp;Indeed in the good ol’ &amp;nbsp;US of A October has become known as &amp;nbsp;National Cyber Security Awareness month. &amp;nbsp; &amp;nbsp;Who would have thought ten years ago that a whole month would be ‘honoured’ with such a strange moniker. &amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Well I guess 10 years ago no one would have predicted that we would have become so utterly dependent on the Web – our every waking and in some instances sleeping moments have some Web connection. &amp;nbsp; &amp;nbsp;E-mail, social-media, &amp;nbsp;telephony, &amp;nbsp;shopping, business, entertainment, gaming &amp;nbsp;– just about anything you can think of - we can now do on the ‘Net. &amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;And it is has all now migrated to the mobile. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;We don’t move without our smart-phones attached to us like newly evolved limbs –extensions of our arms and hands like permanent deformations. &amp;nbsp; Each mutation reflecting our individual taste –our particular phase of evolution. &amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Some of us are Apple boys – coveting the very latest offerings from the Cupertino emporium with breathless anticipation ( like tomorrow Tues 4th – iPhone5 day ) - while those Droids amongst us turn their noses up at such blatant snobbery. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;They, the heroes of the ‘’working man’ of open source - embrace the democratic &amp;nbsp;power that Android brings to the masses. &amp;nbsp; (Compatibility, hardware issues and viruses aside) &amp;nbsp; &amp;nbsp; Then there are the die-hards – the traditionalists - those who haven’t evolved as much. &amp;nbsp; They still ‘carry’ themselves like our predecessors of the last decade with ‘ancient’ devices made by Nokia, RIM and Microsoft. &amp;nbsp; &amp;nbsp;Some of them pride themselves on using their phones only for calls and text messages. &amp;nbsp; &amp;nbsp; There are those who swear by their Blackberry buttons desperate to hang on to this dying function which is destined to wither away like a non-functioning limb. &amp;nbsp; ( I predict that two case studies in business schools in 2012/3 will be the demise of RIM and Groupon and how these success stories faltered and failed) &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;What this mobile revolution is doing is making the Internet more accessible as WIFI/WiMax and LTE become more ubiquitous and as we embrace these devices to do that most important of human activities – payments. &amp;nbsp; I predict that some aspirants will fall by the wayside but that a few smart technologies will come to define this next evolutionary period. &amp;nbsp; Those who can make payments simple and secure and usable will go a long way to solving the biggest challenge of the 'new mobile era'. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Perhaps these newly evolved limbs will be defined not only by their form factor and the services we consume but also how we pay for them. &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-3493622962031166405?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3493622962031166405' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=3493622962031166405' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3493622962031166405'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3493622962031166405'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=3493622962031166405' title='HUMAN EVOLUTION AND THE MOBILE'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-7588843131194772551</id><published>2011-09-19T10:36:00.000-07:00</published><updated>2011-09-19T13:44:44.923-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Epsilon'/><category scheme='http://www.blogger.com/atom/ns#' term='SAAS security'/><category scheme='http://www.blogger.com/atom/ns#' term='online security'/><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><category scheme='http://www.blogger.com/atom/ns#' term='2FA'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber crime'/><category scheme='http://www.blogger.com/atom/ns#' term='two factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>SIX MONTHS ON AND EPSILON STILL DONT SECURE THEIR USERS</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;In April this year, &amp;nbsp;Epsilon Data Management LLC &amp;nbsp;(one of the world's largest providers of marketing-email services) , a division of Alliance Data Systems Corp issued a statement,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;"&lt;i&gt;&lt;b&gt;On March 30th, an incident was detected where a subset of Epsilon clients' customer data were exposed by an unauthorized entry into Epsilon's email system. The information that was obtained was limited to email addresses and/or customer names only&lt;/b&gt;&lt;/i&gt;."&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;                 &lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span lang="EN-US"&gt;(&lt;a href="http://www.fastcompany.com/1744738/the-epsilon-breach-should-you-be-angry-worried-or-bored"&gt;http://www.fastcompany.com/1744738/the-epsilon-breach-should-you-be-angry-worried-or-bored&lt;/a&gt;)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;When it's all said and done, the Epsilon hack may be the &lt;b&gt;largest name and email address breach in the history of the Internet.&lt;/b&gt; &amp;nbsp;Epsilon handles more than 40 billion emails annually and more than 2,200 global brands. If you are thinking you are safe because you opted-out of marketing emails, think again&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;(&lt;/span&gt;&lt;a href="http://blogs.computerworld.com/18079/epsilon_breach_hack_of_the_century"&gt;http://blogs.computerworld.com/18079/epsilon_breach_hack_of_the_century&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Epsilon required their customers to log on to their systems using a user name and password with which to ‘authenticate’ themselves. &amp;nbsp;This was clearly inadequate as a hacker managed to breach their system and obtain a treasure trove of customer information. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;What this meant was that the customers of Epsilons customers i.e. the big &amp;nbsp;brands, &amp;nbsp;were ( and still are ) exposed to spear phishing attacks. &amp;nbsp;They can be targeted by the hackers with e-mails that will look like they legitimately come from those global brands which include the likes of :&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;i&gt;Best Buy, Capital One, JPMorgan, Citibank, Kroger, Barclays Bank of Delware, Visa, American Express, US Bank, TiVo Inc. and Walgreen Co, Robert Half, Kraft, Home Shopping Network, QFC, Marriott Rewards, Ritz-Carlton Rewards, LL Bean Visa Card, Brookstone, Dillons, the College Board, McKinsey &amp;amp; Company, New York &amp;amp; Company, Disney Vacations, Staples, TIAA-CREF, Verizon, Borders, Smith Brands, Abe Books and Lacoste…etc.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;                 &lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span lang="EN-US"&gt;(&lt;a href="http://www.itpro.co.uk/632566/the-fallout-from-the-epsilon-breach"&gt;http://www.itpro.co.uk/632566/the-fallout-from-the-epsilon-breach&lt;/a&gt;)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Currently ( 6 months later ) Epsilon announced ( from their website ):&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;“ &lt;i&gt;Further, Epsilon has enhanced user security by implementing two-factor authentication. Two-factor authentication is a security process that requires two means of identification to gain system access, adding significant additional protections beyond conventional strong password requirements. Two-factor authentication, currently in place for employees, will be extended to all clients in Q3 2011. &lt;/i&gt;“&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;                 &lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span lang="EN-US"&gt;(&lt;a href="http://www.epsilon.com/News%20&amp;amp;%20Events/Press%20Releases%202011/Epsilon_Unveils_Innovative_Security_Enhancements_to_Global_Email_Marketing_Platform%20/p1118-l3"&gt;http://www.epsilon.com/News%20&amp;amp;%20Events/Press%20Releases%202011/Epsilon_Unveils_Innovative_Security_Enhancements_to_Global_Email_Marketing_Platform%20/p1118-l3&lt;/a&gt;)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;At the time of writing &amp;nbsp;(19 Sep 2011) Epsilon clients are still only using a username and password to log-in.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;(&lt;a href="https://portals.epsilon.com/c_links.nsf/names.nsf?Login"&gt;https://portals.epsilon.com/c_links.nsf/names.nsf?Login&lt;/a&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Makes you wonder - doesn't it ? &amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-7588843131194772551?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=7588843131194772551' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=7588843131194772551' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=7588843131194772551'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=7588843131194772551'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=7588843131194772551' title='SIX MONTHS ON AND EPSILON STILL DONT SECURE THEIR USERS'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-6746721024765617119</id><published>2011-09-08T04:33:00.000-07:00</published><updated>2011-09-08T06:30:52.475-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ID theft'/><category scheme='http://www.blogger.com/atom/ns#' term='Man in the middle'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='Secure Key'/><category scheme='http://www.blogger.com/atom/ns#' term='one time password'/><category scheme='http://www.blogger.com/atom/ns#' term='HSBC'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>HSBC EMBRACES OLD TECHNOLOGY IN ITS BATTLE AGAINST HACKERS</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&amp;nbsp;If you live in the UK and are somehow involved in the business world and exposed to media you could not help but have noticed the extensive advertising campaign that HSBC has been running on its new (sic) ‘security device’ for online banking - Secure Key.&amp;nbsp;&amp;nbsp; &amp;nbsp;( I was tempted to refer to them as&amp;nbsp; ‘ large UK bank’&amp;nbsp; - but it is so obvious who it is – no point in pretending. )&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;A lot of money has been thrown at this campaign – I would guess millions.&amp;nbsp; (&lt;a href="http://www.youtube.com/watch?v=Jx0Z5CiQMIw"&gt;http://www.youtube.com/watch?v=Jx0Z5CiQMIw&lt;/a&gt;) &amp;nbsp;&amp;nbsp;Full page spreads in large circulation newspapers cost big bucks not to mention prime time TV slots.&amp;nbsp;&amp;nbsp; So here you have the worlds largest retail bank splashing millions on advertising and even more on a ‘cool’ little device that looks like a mini-calculator &amp;nbsp;- but basically a technology that has been around for about a decade.&amp;nbsp; &amp;nbsp;This will be rolled out to 4m retail customers worldwide at a reported cost of up to £50 per pop! (&lt;a href="http://www.bankingtech.com/bankingtech/article.do?articleid=20000201121"&gt;http://www.bankingtech.com/bankingtech/article.do?articleid=20000201121&lt;/a&gt;)&amp;nbsp; You do the math!&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;This same technology has been used by HSBC itself and many other banks for most of the noughties.&amp;nbsp;&amp;nbsp; But all to no avail.&amp;nbsp; Has online banking fraud stopped ?&amp;nbsp; No.&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;So why pursue a strategy- that has been proven to be wrong.&amp;nbsp; As they say – a sign of madness is doing the same thing over again and expecting a different result. &amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Technically the product is flawed.&amp;nbsp;&amp;nbsp; And it is cumbersome.&amp;nbsp; Watch this video to see just how cumbersome !!&amp;nbsp; (&lt;a href="http://www.youtube.com/watch?v=iOOWiQS5pUQ&amp;amp;feature=related"&gt;http://www.youtube.com/watch?v=iOOWiQS5pUQ&amp;amp;feature=related&lt;/a&gt;) &amp;nbsp;and also &amp;nbsp;(customers don’t want another ‘thing’ to carry around and potentially lose) , but &amp;nbsp;- most importantly it is vulnerable to being hacked by a Man-in-the-Middle or Man-in-the-Browser attack.&amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;After identifying yourself with a user name and password you are then asked to enter the One Time Password (OTP) back into the browser.&amp;nbsp;&amp;nbsp; The browser being the vehicle that you are trying to secure and establish trust over. &amp;nbsp;&amp;nbsp;But here you are entering your ‘million dollar’ PIN into an insecure browser. &amp;nbsp;&amp;nbsp;This is security by obscurity at its finest.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Also – as to be expected many customers don’t like it – forums have been set up where rants (and some raves ) are shared (&lt;a href="http://forums.moneysavingexpert.com/showthread.php?t=3296224"&gt;http://forums.moneysavingexpert.com/showthread.php?t=3296224&lt;/a&gt;) &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I have not even mentioned the carbon footprint of manufacturing these devices and then shipping them to 4m customers around the world. This number will grow by about 20 % per year as people lose them and they need to be replaced.&amp;nbsp; So who foots the bill ?&amp;nbsp;&amp;nbsp; YOU and me - &amp;nbsp;the bank's customer foots the bill.&amp;nbsp;&amp;nbsp; How?&amp;nbsp; In increased bank charges.&amp;nbsp;&amp;nbsp; And when you do get hacked – and many will – the bank has to make good the loss – again at the cost of YOU the customer.&amp;nbsp; Even higher bank charges. &amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Surely there are solutions out there that can be delivered over the web as a SAAS solution – obviating (in this case ) the multi-million pound investment in tokens and postage and packaging.&amp;nbsp;&amp;nbsp; Surely there are solutions that offer a higher level of security and ones that are much easier to use and ones which are cheaper.&lt;/span&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Of course there is.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;Live Ensure ( &lt;a href="http://www.liveensure.com/"&gt;http://www.liveensure.com&lt;/a&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;).&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;Maybe if you know someone at HSBC you should tell them about it.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-6746721024765617119?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6746721024765617119' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=6746721024765617119' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6746721024765617119'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6746721024765617119'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=6746721024765617119' title='HSBC EMBRACES OLD TECHNOLOGY IN ITS BATTLE AGAINST HACKERS'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-1343626290751210911</id><published>2011-08-11T08:57:00.000-07:00</published><updated>2011-08-11T09:07:11.445-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ID theft'/><category scheme='http://www.blogger.com/atom/ns#' term='2FA'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='#liveensure'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber crime'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='two factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hack'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>SECURITY SANS FRONTIERS</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;In many countries around the World, access to the Internet is seen as a basic right, and so it should be. &amp;nbsp; &amp;nbsp;Those countries which have done&amp;nbsp;so to date&amp;nbsp;include : &amp;nbsp;Estonia, France, &amp;nbsp;Spain, &amp;nbsp;Greece &amp;nbsp;and Finland, &amp;nbsp;which was actually the first to do so in June 2010. &amp;nbsp;(&lt;a href="http://www.publicserviceeurope.com/article/642/internet-access-should-be-a-human-right)"&gt;http://www.publicserviceeurope.com/article/642/internet-access-should-be-a-human-right)&lt;/a&gt; &amp;nbsp;I&lt;br /&gt;&lt;br /&gt;In fact the United Nations recently declared Internet access as a human right. (&lt;a href="http://www.itproportal.com/2011/06/04/un-declares-internet-access-as-a-human-right/"&gt;http://www.itproportal.com/2011/06/04/un-declares-internet-access-as-a-human-right/&lt;/a&gt;) &lt;br /&gt;&lt;br /&gt;Obviously the next challenge is to build the infrastructure and provide the means of access. &amp;nbsp; &amp;nbsp;But that is the subject of a separate discussion. &lt;br /&gt;&lt;br /&gt;So the “World” &amp;nbsp;has woken up to the importance of closing the digital divide and has also realized the importance of the Internet, and access to it, &amp;nbsp;to the functioning of society. &amp;nbsp; Amongst the many momentous events of the last twelve months which have included epochal scenes such as the Arab Spring, the new Financial crisis ( Greece / Euro) and most recently the London riots - what has also made headlines globally has been the spate of cyber attacks and hacking which have damaged (and embarrassed) some very large corporations like Sony and RSA and large Governmental and NGO’s like the CIA and the NATO. &amp;nbsp; &amp;nbsp;This has been coupled with the emergence of online activism dubbed ‘hacktivism’ &amp;nbsp;(the online equivalent of protesting in Tahrir square) – lead by the likes of Anonymous and Lulzsec. &amp;nbsp; These high profile events and the associated media coverage has raised the issue of online safety, security (and privacy) and exposed just how vulnerable users of the Internet ( i.e. all of us ) are, &amp;nbsp; to becoming victims of cybercrime ranging from phishing, &amp;nbsp;pharming, ID theft and, &amp;nbsp;in the case of businesses, DDoS. &lt;br /&gt;&lt;br /&gt;So it is all very well giving people access to the Internet. &amp;nbsp;Once they have access they need to be safe. &amp;nbsp; There is the risk that we create another ‘ digital divide’ . &amp;nbsp;This time the divide between those who can afford adequate online security and those who cannot. &amp;nbsp; We have called this the ‘security divide’. &amp;nbsp; There are those who are well informed about online security (most people reading this article would fall into that category) and those who haven’t a clue (the majority of people out there.) &amp;nbsp; &amp;nbsp;But there are also those who do understand the issues but cannot afford the prices being charged by most security vendors. &lt;br /&gt;&lt;br /&gt;In the spirit of trying to bridge the ‘ security divide’ we have embarked on a program of making LiveEnsureTM available, &amp;nbsp;to those organizations (who themselves have become soft targets for hackers ) like charities, &amp;nbsp;not-for-profits, &amp;nbsp;social enterprises and indeed small start-ups, &amp;nbsp;for free. &lt;br /&gt;&lt;br /&gt;We have called this initiative ‘ security sans frontiers’. &amp;nbsp; If your organization requires its users to log-in or if it takes donations online &amp;nbsp;(in other words if you need to protect your users by ensuring your site does not get hacked) and you think your organization qualifies then please sign up at &lt;a href="http://www.liveensure.com/"&gt;http://www.liveensure.com&lt;/a&gt; today. &amp;nbsp; Access to the Internet is and should be a basic human right but so too should &lt;b&gt;safe&lt;/b&gt; access to the Internet be. &lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-1343626290751210911?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1343626290751210911' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=1343626290751210911' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1343626290751210911'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1343626290751210911'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=1343626290751210911' title='SECURITY SANS FRONTIERS'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-8783740580244206445</id><published>2011-08-07T10:29:00.000-07:00</published><updated>2011-08-07T10:32:40.964-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ID theft'/><category scheme='http://www.blogger.com/atom/ns#' term='2FA'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='one time password'/><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='lulzsec'/><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><category scheme='http://www.blogger.com/atom/ns#' term='online security'/><category scheme='http://www.blogger.com/atom/ns#' term='SAAS security'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber crime'/><category scheme='http://www.blogger.com/atom/ns#' term='two factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>ANONYMOUS / LULZSEC /ANTI-SEC ARE DOING MORE GOOD THAN HARM !</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;I know,&amp;nbsp; &amp;nbsp;I know – I hear the howls of protest even before finishing this first sentence.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;“What about all the innocent lives exposed by the irresponsible publication of peoples names in positions of authority or in sensitive roles. ?”&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;But where does the fault lie ?&amp;nbsp; With those doing the breaking and entering? &amp;nbsp; Or those not providing adequate protection??&amp;nbsp; It is liked leaving your house locked without an alarm system, going on holiday, and coming back and finding it broken into.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;Don’t be surprised.&amp;nbsp; You have no one to blame but yourself.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;“ But these are criminals ! “&amp;nbsp; – I hear the sounds of self righteous chest thumping.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;Maybe, but what they have done – I hope – is scare the s**t out of anyone who has anything (data) that is accessible via the Web &amp;nbsp;- and into ensuring that their ‘security’ ( if any ) - is rapidly upgraded.&amp;nbsp; &amp;nbsp;&amp;nbsp;This ranges from personal users who have Gmail accounts to corporations and Governments who are custodians over much of your and my personal data.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;Who today has not heard of the hacking of SONY (and other gaming companies),&amp;nbsp; RSA,&amp;nbsp; IMF,&amp;nbsp; Citi-Group,&amp;nbsp; Lockheed Martin and myriad government agencies (particularly local police forces.)&amp;nbsp;&amp;nbsp; ??&amp;nbsp; (&lt;a href="http://www.cio.com/article/687364/AntiSec_Hackers_Dump_Data_After_Hacking_Police_Websites?source=rss_security"&gt;http://www.cio.com/article/687364/AntiSec_Hackers_Dump_Data_After_Hacking_Police_Websites?source=rss_security&lt;/a&gt;)&amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;There must be millions of tweets every day carrying a story or an angle of yet more hacks / breaches, &amp;nbsp;of yet more venerable institutions – by, invariably,&amp;nbsp; the Anonymous/Lulzsec/AntiSec ( ALA) contingent (or their pretenders). &amp;nbsp;&amp;nbsp;&amp;nbsp;Even the mainstream media is replete with such stories.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Perhaps the exposure has been a little excessive and we are starting to suffer from ‘hacker’ fatigue.&amp;nbsp;&amp;nbsp; It is becoming a little tiresome.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;Therein lies the danger.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;Is the good ( yes – I think on balance the awareness raising is good ) not going to be diminished through the excessive exposure, the desensitization ( boiling frog syndrome ) and the resultant complacency?&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;That is my main concern.&amp;nbsp;&amp;nbsp;&amp;nbsp; These ‘hacktivists’ &amp;nbsp;are not the best marketers in the world and they have the habit of rubbing everyone up the wrong way.&amp;nbsp; &amp;nbsp; But their cause has merit.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;Yes I believe that security practitioners and their clients should be raising their game or else run the risk of&amp;nbsp; : &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;a) being embarrassed (largely the damage that has been caused) by the ALA’s; or &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;b) of actually being hacked by some serious bad guys and thereby incurring considerable economic damage.&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;What the ALA’s have shown is that the millions spent on security by Governments and Corporations has been spent badly.&amp;nbsp;&amp;nbsp; The security solutions out there particularly the so-called two-factor authentication solutions whether token or dongle based (OTP),&amp;nbsp; java-script based, &amp;nbsp;SMS based or even just password based are fundamentally flawed and it is time for a new evolution of authentication solutions.&amp;nbsp;&amp;nbsp; If your website is ‘protected’ by a user name and password or SSO / Open ID&amp;nbsp; (or even one of the aforementioned) then you owe it to your customers and shareholders (citizens &amp;nbsp;- in the case of Government agencies) &amp;nbsp;to review your security. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-family: 'Helvetica Neue', Arial, Helvetica, sans-serif;"&gt;Lest you becoming the laughing stock of Lulzsec.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-8783740580244206445?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8783740580244206445' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=8783740580244206445' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8783740580244206445'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8783740580244206445'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=8783740580244206445' title='ANONYMOUS / LULZSEC /ANTI-SEC ARE DOING MORE GOOD THAN HARM !'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-4930118823573734606</id><published>2011-07-17T16:03:00.000-07:00</published><updated>2011-07-18T02:18:39.517-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>DOES YOUR WEBSITE HAVE A LOG IN ?</title><content type='html'>&lt;div class="MsoNormal"&gt;Well - you’re probably thinking - this is going to make a fun read !!&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Does my website have a log in ??&amp;nbsp; Well damn right it does ( you’re saying to yourself) – we can’t just let any old passer by onto our site!!&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I mean look at all these big cheeses being hacked like RSA , SONY and even the CIA !!&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;But if users have to log in - that means they need to register and they need to remember yet another user name and possibly - &amp;nbsp;but not necessarily - another password.&amp;nbsp;&amp;nbsp;&amp;nbsp; Well - that means that customers desert in droves !&amp;nbsp; Or does it? &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Are customers put off when they have to log in ?&amp;nbsp; Well I guess a lot has to do with whether the service you offer is valuable enough.&amp;nbsp;&amp;nbsp; Lets see – Twitter, Facebook and Gmail just to name a few at random – you would expect to see some kind of ‘identification ‘ process going on.&amp;nbsp; And indeed you do.&amp;nbsp; And now to make it all that much easier – SSO (Single Sign On) ,&amp;nbsp; OpenID and now BrowserID courtesy of Mozilla ( amongst others ) make our lives much easier when accessing these services.&amp;nbsp;&amp;nbsp; (&lt;a href="http://www.hexus.net/content/item.php?item=31189"&gt;http://www.hexus.net/content/item.php?item=31189&lt;/a&gt;) &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Does your service justify such a feature.? &amp;nbsp;&amp;nbsp;Do you hold personal data,&amp;nbsp; do you transact,&amp;nbsp; is yours a mobile app that is personalized ( eg Groupon/Living Social) &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;More and more websites, corporate applications, mobile applications and cloud applications require that users log in and identity themselves; &amp;nbsp;and if you are one of them &amp;nbsp;you should be thinking of all the ways you can to make it as easy as possible. Here’s why . &amp;nbsp;&amp;nbsp;(&lt;a href="http://www.netwitsthinktank.com/internet/nonprofit-engagement-why-website-logins-matter.htm"&gt;&lt;span id="goog_1865469508"&gt;&lt;/span&gt;http://www.netwitsthinktank.com/internet/nonprofit-engagement-why-website-logins-matter.htm)&lt;span id="goog_1865469509"&gt;&lt;/span&gt; &lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Going forward I believe that users will actually demand that websites provide more in the way of security.&amp;nbsp;&amp;nbsp; When we leave our personal credentials on websites like Amazon and Apple we expect that the information is kept secure. However recent experience with the likes of SONY and Epsilon have shown that hackers have found these defences to be woefully inadequate.&amp;nbsp; And now our information is easy game and identity theft is rampant.&amp;nbsp; &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Live Ensure is a security solution that wraps around any form of log-in whether protected with an additional authentication layer or not and provides ‘ Swiss Vault ‘ security against identity theft.&amp;nbsp;&amp;nbsp; Why not check it out – it may just save your business.&amp;nbsp; I am sure SONY wished they had !&amp;nbsp; ( &lt;a href="http://www.liveensure.com/"&gt;http://www.liveensure.com&lt;/a&gt; )&amp;nbsp;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-4930118823573734606?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=4930118823573734606' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=4930118823573734606' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=4930118823573734606'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=4930118823573734606'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=4930118823573734606' title='DOES YOUR WEBSITE HAVE A LOG IN ?'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-1810815420661242263</id><published>2011-06-27T10:17:00.000-07:00</published><updated>2011-06-30T13:39:38.184-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='lulzsec'/><category scheme='http://www.blogger.com/atom/ns#' term='online security'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='seduction'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>HACKING - A 50 DAY LOVE ( LULZ) FEST ( or safe sex for the masses)</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;So Lulz have ( supposedly ) fallen out of love with us after only 50 days !! &amp;nbsp; WOW - &amp;nbsp;that was a short and sharp, &amp;nbsp;whirlwind romance. &amp;nbsp; &amp;nbsp;One hell'uve steamy affair. &amp;nbsp; &amp;nbsp;One day SONY, &amp;nbsp;the next day the IMF, &amp;nbsp;the next CIA – &lt;b&gt;no one&lt;/b&gt; - was safe from her charms.&lt;br /&gt;&lt;br /&gt;This little slut(z) came into our lives for a bit of fun and has left us breathless and embarrassed with no-where to hide . &amp;nbsp;Why ? &amp;nbsp;Because she wanted to show that with a little bit of seduction –by showing a little cleavage / &amp;nbsp;a bit of leg – she was able to conquer all before her. &amp;nbsp; Like Helen of Troy – no one could resist her charms.&lt;br /&gt;&lt;br /&gt;She made us realize that we don’t actually know what &lt;b&gt;protection&lt;/b&gt; is all about. &amp;nbsp; The protection we are &amp;nbsp;supposed to use &amp;nbsp;– was either damaged / wrongly spec’d or else we just could not get it 'on' quick enough. &amp;nbsp; Sure - &amp;nbsp;she may have laid some of our secrets bare – and many were left red-faced with no-where to hide - but we actually got off lightly. &amp;nbsp; But that was her game plan. &amp;nbsp;Show us up for the hypocrites that we are. &amp;nbsp; We all espouse safe-sex – but when in it comes to the nitty-gritty – we just can’t wait for the action – we rush in without thinking of the consequences after those first heady gropes.&lt;br /&gt;&lt;br /&gt;I have received a number of phishing e-mails in the last few weeks – typical of those that nabbed the unsuspecting victims at the afore-mentioned institutions. &amp;nbsp; See 2 examples below. &lt;br /&gt;&lt;br /&gt;Notice the difference in quality and sophistication – the first &amp;nbsp;– a bit rough and ready –lots of lipstick &amp;nbsp;and make-up – in your face seduction. &amp;nbsp;Bad spelling. &amp;nbsp;Street corner stuff. &amp;nbsp;But appealing to the curious .... &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ffUTwGGJoC4/Tgi3rNuTBUI/AAAAAAAAB14/ZbFR-TqY5nY/s1600/Screen+shot+2011-06-27+at+17.34.07.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="312" src="http://2.bp.blogspot.com/-ffUTwGGJoC4/Tgi3rNuTBUI/AAAAAAAAB14/ZbFR-TqY5nY/s320/Screen+shot+2011-06-27+at+17.34.07.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;This one is much more low key and professional – attractive to a different kind of man. &amp;nbsp; A man who seeks discretion and subtlety in his ladies. &amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-FrfZjMUsw-o/Tgi3xgNiepI/AAAAAAAAB18/w3cQWeGHdWU/s1600/Screen+shot+2011-06-27+at+17.34.26.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="230" src="http://1.bp.blogspot.com/-FrfZjMUsw-o/Tgi3xgNiepI/AAAAAAAAB18/w3cQWeGHdWU/s320/Screen+shot+2011-06-27+at+17.34.26.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;But just as effective !&lt;br /&gt;&lt;br /&gt;What you should not do when faced with such temptation &amp;nbsp;– if you want to retain your dignity – is click on the document icon or the link respectively. &amp;nbsp; Why? &amp;nbsp;Because all manner of nasties will be unleashed onto your device exposing your most intimate parts &amp;nbsp;to the seductress - who actually just wants to steal your wallet/ID/Passport etc &amp;nbsp;while your trousers are down. !&lt;br /&gt;&lt;br /&gt;So is this Lulz fest really over. ? &amp;nbsp; I doubt it. &amp;nbsp;The pickings are just too rich and besides - what else is there for a Lulz to do ? &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-1810815420661242263?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1810815420661242263' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=1810815420661242263' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1810815420661242263'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1810815420661242263'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=1810815420661242263' title='HACKING - A 50 DAY LOVE ( LULZ) FEST ( or safe sex for the masses)'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-ffUTwGGJoC4/Tgi3rNuTBUI/AAAAAAAAB14/ZbFR-TqY5nY/s72-c/Screen+shot+2011-06-27+at+17.34.07.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-1763395501552358690</id><published>2011-05-28T09:19:00.000-07:00</published><updated>2011-06-02T03:11:41.203-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='banked'/><category scheme='http://www.blogger.com/atom/ns#' term='unbanked'/><category scheme='http://www.blogger.com/atom/ns#' term='remittances'/><category scheme='http://www.blogger.com/atom/ns#' term='telephony'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile'/><category scheme='http://www.blogger.com/atom/ns#' term='SWIFT'/><category scheme='http://www.blogger.com/atom/ns#' term='#innotribe'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile money'/><category scheme='http://www.blogger.com/atom/ns#' term='paytoo'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Western Union'/><category scheme='http://www.blogger.com/atom/ns#' term='payments'/><title type='text'>MOBILE MONEY - A SOLUTION READY TODAY</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;Google have just announced with some fanfare that they have created a mobile money eco-system. &amp;nbsp; Android users can now use their devices fitted with NFC chips to make payments at selected Points of Sale in the US. &amp;nbsp; This will only be launched on a limited scale some time in the Summer. &amp;nbsp;It is not actually ready yet. ( &lt;a href="http://googleblog.blogspot.com/2011/05/coming-soon-make-your-phone-your-wallet.html"&gt;http://googleblog.blogspot.com/2011/05/coming-soon-make-your-phone-your-wallet.html&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;There is no doubt that those of us in the ‘advanced’ West will value the utility of being able to swipe our phones (which have become extensions of our very beings) when we buy coffee &amp;nbsp;- the Starbucks app has been out for a while – (&lt;a href="http://www.starbucks.com/coffeehouse/mobile-apps"&gt;http://www.starbucks.com/coffeehouse/mobile-apps&lt;/a&gt;) or when we make our day to day purchases. &amp;nbsp; It will be &amp;nbsp;‘cool’ just as it is cool today to flash an NFC enabled credit card at an NFC enabled POS when making small value purchases. &lt;br /&gt;&lt;br /&gt;However I would argue that the utility, &amp;nbsp;of the full functionality of mobile money transactions, will only be fully appreciated by those living in less developed countries - where few have bank accounts and credit cards but many have mobile phones. &lt;br /&gt;&lt;br /&gt;I was delighted and surprised to hear that the SWIFT conference in Mumbai being held this week has its focus on the unbanked. &amp;nbsp;(&lt;a href="http://www.swift.com/events/2011/Innotribe_Mumbai/index.page"&gt;http://www.swift.com/events/2011/Innotribe_Mumbai/index.page&lt;/a&gt;) &amp;nbsp;SWIFT is the organization that provides a platform for banks &amp;nbsp;(inter-alia) to automate and standardize financial transactions including transfers – hence the SWIFT code for bank accounts. &amp;nbsp; So it is a big and brave step that they have taken into what must be, for them, uncharted territory.&lt;br /&gt;&lt;br /&gt;Having grown up in the mobile phone industry in the 90’s and been fortunate to have seen some pretty cool innovations in that space – what stood out for me at the time was the inability of mobile banking to take off (despite best efforts from us as a mobile operator and the maturity of the technology). &amp;nbsp; My observation was that the failure was primarily political – it was a turf war between banks and MNO’s. &amp;nbsp; Banks did not want the MNO’s to get too close to their business for fear of losing control of their customers. &lt;br /&gt;&lt;br /&gt;Well that was a long time ago and since then things have moved on. &amp;nbsp;Companies like Monitise (&lt;a href="http://www.monitise.com/"&gt;http://www.monitise.com/&lt;/a&gt;) have demonstrated that the banks have adapted and realize they need to be part of the new order. &amp;nbsp; However they serve a limited segment of the potential global market. &amp;nbsp;Their customers all have bank accounts and all that Monitise and other aspirants are doing, &amp;nbsp;is &amp;nbsp;creating a new channel. &lt;br /&gt;&lt;br /&gt;What about those &amp;nbsp;( more than) 3bn mobile phone users who don’t have bank accounts?? (Reliable statistics show that only 2bn of the more than 5bn mobile phone users globally are banked.) &amp;nbsp; &amp;nbsp; These are generally poorer people who live in emerging markets in Africa and Asia. &amp;nbsp; They live in a cash economy with very high transaction costs. &amp;nbsp; A large proportion of their income comes from remittances from the richer Western countries. &amp;nbsp; &amp;nbsp;The cost of these transactions are outrageous &amp;nbsp;although competition is forcing these prices down (Western Union – &lt;a href="http://www.westernunion.com/"&gt;http://www.westernunion.com&lt;/a&gt; ) &amp;nbsp;The inefficiency in this financial system is deleterious to an already weakened economic order. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The challenge thus, is to provide a financial ecosystem that can bridge the sophistication of the banked with the needs and wants of the unbanked. &amp;nbsp; Such a system should leverage existing networks and infrastructure so as to reduce costs of implementation and ultimately transactions costs. &amp;nbsp; By using the mobile phone as the instrument for storing value (e-wallet) and its networks for sending the money one can achieve many of these objectives. &amp;nbsp; &lt;br /&gt;&lt;br /&gt;How does one translate cash into ‘e-money ‘ and visa versa. &amp;nbsp;This is a function of the partner networks that can be leveraged – these are the so- called pay in and pay out points where the user can do just that, &amp;nbsp;put money in or take cash out. &amp;nbsp; Of course ideally this should be integrated with the ‘advanced’ banking systems so that bank accounts, credit cards and debit cards can also interact with the system. &lt;br /&gt;&lt;br /&gt;M-Pesa, &amp;nbsp; (&lt;a href="http://enterprise.vodafone.com/products_solutions/finance_solutions/m-pesa.jsp"&gt;http://enterprise.vodafone.com/products_solutions/finance_solutions/m-pesa.jsp&lt;/a&gt;) is a great success story out of Kenya which demonstrates the ingenuity of a people whose culture and needs are not burdened by vested interests. &amp;nbsp; However M-Pesa is relatively restricted in its reach and its scope of services. &lt;br /&gt;&lt;br /&gt;Surely the ideal solution is one which taps into the users requirement for low cost calls ( he has a mobile phone already and hence wants to keep costs down), &amp;nbsp;and also provides the ability for the user to make and receive payments, &amp;nbsp;transfer money, &amp;nbsp;pay bills and remit funds internationally - all off a single account (e-wallet). &amp;nbsp; &amp;nbsp;One that can be &amp;nbsp;linked to credit cards and bank accounts but is also linked to ubiquitous networks of pay in and pay out points. &amp;nbsp;And one that is also linked to a branded card that can be used to make payments, draw cash from ATM’s as well as make online payments.&lt;br /&gt;&lt;br /&gt;Well as it happens there is such a solution. &amp;nbsp; It is provided by a company called Paymotech and it goes by the name of Paytoo (&lt;a href="http://www.paytoo.com/"&gt;http://www.paytoo.com/&lt;/a&gt;). &amp;nbsp; Unlike Google which is still trialing its mobile payment service Paytoo is now live across the US and is accessible at thousands of &amp;nbsp;outlets. &amp;nbsp;Paytoo has also implemented its services in countries like Nepal where in partnership with the central bank &amp;nbsp;the Nepalese Diaspora can now remit funds to their families back home at an affordable rate. &amp;nbsp; There are numerous other relationships in place ( check out their website) &amp;nbsp;that demonstrate the efficiency and ingenuity &amp;nbsp;of the Paytoo system. &amp;nbsp; Paytoo have a Mastercard BIN which allows them to issue branded prepaid cards. &amp;nbsp;They are also a global MVNO leveraging the Vodafone network – allowing Paytoo users to use their mobile phones abroad without incurring roaming charges. &amp;nbsp; And there is much much more. &lt;br /&gt;&lt;br /&gt;Perhaps SWIFT need look no further than Paytoo for a solution.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-1763395501552358690?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1763395501552358690' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=1763395501552358690' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1763395501552358690'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=1763395501552358690'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=1763395501552358690' title='MOBILE MONEY - A SOLUTION READY TODAY'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-6191085241645177173</id><published>2011-05-05T08:17:00.000-07:00</published><updated>2011-05-05T08:18:23.497-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='online security'/><category scheme='http://www.blogger.com/atom/ns#' term='identity theft'/><category scheme='http://www.blogger.com/atom/ns#' term='reputation'/><category scheme='http://www.blogger.com/atom/ns#' term='OpenID'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber crime'/><category scheme='http://www.blogger.com/atom/ns#' term='two factor authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='hack'/><title type='text'>REPUTATION MORE VALUABLE THAN CASH  (ASK SONY)</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The recent attack (it seems by Anonymous) on SONY which compromised the personal details of almost 100m of their gaming customers has caused massive damage to the SONY brand.&amp;nbsp;&amp;nbsp; According to Interbrand in 2009 SONY’s brand value was $12bn.&amp;nbsp;&amp;nbsp; You can safely assume that it will have taken a hit in the order of billions of dollars.&amp;nbsp;&amp;nbsp;( This excludes any legal action and the resultant loss.)&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The same could be said of Epsilon and RSA who like SONY did not have a major financial breach but their good names have been severely compromised.&amp;nbsp; &amp;nbsp;The loss to brand value as well as enterprise value could be massive due to the loss of future business.&amp;nbsp;&amp;nbsp;&amp;nbsp; (There is a report circulating citing research done on RSA’s customers of whom more than half stated that they would not be renewing their contracts. )&amp;nbsp; &amp;nbsp;&amp;nbsp;If not obvious before, &amp;nbsp;then now, &amp;nbsp;executives charged with the stewardship of large valuable corporations must realize how fragile that value is when faced with the multitude of challenges;&amp;nbsp; &amp;nbsp;be they natural (tsunamis/earthquakes) or man-made (criminal / terrorism/fraud) or just good old competition.&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;In respect of cybercrimes such as phishing and pharming attacks which can lead to either direct financial loss (draining of bank accounts/ theft of credit card details) or reputational damage (per the above) I contend that the latter constitutes a far greater threat than the former.&amp;nbsp; ( There are those who would argue that the&amp;nbsp; value of an email address exceeds that of a credit card number in the parallel world of the cybercriminal.) &amp;nbsp;&amp;nbsp;In respect of individuals this would be in the form of ID theft where personal credentials are used to commit fraud thereby damaging (perhaps irreparably) that persons reputation.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We have seen from the above examples of just how, &amp;nbsp;a corporation's reputation can be impacted.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;A person or a corporation would much rather that money was stolen than their reputation was damaged; &amp;nbsp; as the latter is very difficult to rebuild and, if so, invariably takes a long time.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The need for strong authentication in situations where today simple ‘identification’ is used (such as applications using - user name and password / Single Sign On / OpenID) has become an urgent imperative.&amp;nbsp;&amp;nbsp; Even then those authentication solutions need to be affordable, usable and effective.&amp;nbsp;&amp;nbsp;&amp;nbsp; Multi-factor solutions such as OOB tokens, OTP keys and browser-based javascript fingerprinting have relied on the browser, user acumen and ‘security by obscurity’ to function.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I believe we will see a steady trend of individuals and corporations demanding better security in the form of two factor authentication&amp;nbsp; (as a minimum) from their business partners / suppliers and customers.&amp;nbsp;&amp;nbsp;&amp;nbsp; We have seen many large corporations fall from grace very quickly for many reasons (Arthur Andersen / Enron / WorldCom / Lehman Brothers / Bear Sterns ).&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;No corporation can afford to crash or be severely damaged, because they were hacked,&amp;nbsp; because they did not take their online security seriously.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-6191085241645177173?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6191085241645177173' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=6191085241645177173' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6191085241645177173'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6191085241645177173'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=6191085241645177173' title='REPUTATION MORE VALUABLE THAN CASH  (ASK SONY)'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-732653455282275089</id><published>2011-04-11T15:05:00.000-07:00</published><updated>2011-04-12T01:07:36.551-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='technology'/><category scheme='http://www.blogger.com/atom/ns#' term='KELLY'/><category scheme='http://www.blogger.com/atom/ns#' term='parenting'/><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><category scheme='http://www.blogger.com/atom/ns#' term='LANIER'/><category scheme='http://www.blogger.com/atom/ns#' term='online gaming'/><title type='text'>TECHNOLOGY AND OUR KIDS</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;I am increasingly struck by the broad range &amp;nbsp;of reactions to the&amp;nbsp; continuous flow of technology that never seems to stop bombarding us from all sides - sometimes seeming to overwhelm.&amp;nbsp;&amp;nbsp;&amp;nbsp; There are those who embrace it as though it is a new source of strength echoing Kevin Kellys view that we “evolve’ with technology and that it is a source of good. &lt;a href="http://www.readwriteweb.com/archives/what_technology_wants_kevin_kelly_theory_of_evolution.php"&gt;http://www.readwriteweb.com/archives/what_technology_wants_kevin_kelly_theory_of_evolution.php&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are others who believe that it is an insidious negative fog that is slowly strangling the creativity out of our youth as they while away their lives in front of TV’s ,&amp;nbsp; online playing interactive games or Tweeting and ‘connecting’ via social networks.&amp;nbsp;&amp;nbsp;&amp;nbsp; Jaron Lanier says that ‘ technology reduces our humanity’&amp;nbsp; - promoting the hive mentality over individual expression.&amp;nbsp;(&lt;a href="http://www.jaronlanier.com/"&gt;http://www.jaronlanier.com/&lt;/a&gt;)&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I have to say that, whenever I find my daughter watching a mindless sitcom (aimed at teenagers although she is only 8) I find myself firmly in the second camp.&amp;nbsp;&amp;nbsp; Her technological interaction also includes time online playing Moshi Monsters or Club Penguin.&amp;nbsp;&amp;nbsp; I find myself caught up in an incredible dilemma – I am a tech-fan &amp;nbsp;– I have spent most of my working career advocating and enacting the power of technology as a force for change and hopefully for good – mobile phones in Africa and the Middle East;&amp;nbsp; ICT in South Africa and online security globally.&amp;nbsp;&amp;nbsp; I am undoubtedly firmly in the Kelly camp – and yet I find it so difficult to reconcile this with the impact I see it having on my children.&amp;nbsp; My daughter in particular.&amp;nbsp;&amp;nbsp; The mindless absorption of ‘sitcom pornography’ ( which seems to be the only way to describe it ) is the technological equivalent of&amp;nbsp; ‘eating white bread’&amp;nbsp; as my colleague Christian Hessler so eloquently described it to me.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; You are going through the act of eating – it is filling but there are no 'nutrients'. &amp;nbsp;&amp;nbsp;&amp;nbsp;It is mindless, 'nutritionless', &amp;nbsp;a waste of time and is inculcating bad values and getting them into the wrong sort of habits.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Or am I being,&amp;nbsp; as my family like to mock me,&amp;nbsp; a grumpy ‘old’ man.&amp;nbsp;&amp;nbsp; Should I just accept that the world has changed and that our children, &amp;nbsp;as digital natives, &amp;nbsp;are&amp;nbsp; wired differently&amp;nbsp; and interact with the digital world seamlessly? &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Or is the right approach that of the ‘Tiger parent’&amp;nbsp; who does not&amp;nbsp; allow their kids any ‘free’ time and who structure activities 24 x 7?&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I guess I want a balance and I want my kids to spend more time outside playing in the garden and feeling the dirt under their fingernails.&amp;nbsp; Maybe I am just wishing for them the childhood I had growing up under sunny skies in South Africa and not the gray drab monotony that is London.&amp;nbsp;&amp;nbsp; I guess you can’t have everything.&amp;nbsp;&amp;nbsp;&amp;nbsp; I am just grateful they are happy, healthy and wonderful people.&amp;nbsp;&amp;nbsp; I guess I will continue to vacillate between being a tech fan and a Luddite.&amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-732653455282275089?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=732653455282275089' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=732653455282275089' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=732653455282275089'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=732653455282275089'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=732653455282275089' title='TECHNOLOGY AND OUR KIDS'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-410526584906527817</id><published>2011-03-27T14:41:00.000-07:00</published><updated>2011-03-27T14:41:38.385-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2FA'/><category scheme='http://www.blogger.com/atom/ns#' term='Man in the middle'/><category scheme='http://www.blogger.com/atom/ns#' term='cloud security'/><title type='text'>Why is Cloud Security such a big Challenge ?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: 'Helvetica Neue', Helvetica, Arial, default; font-size: 13px; line-height: 17px;"&gt;Cloud security is a big challenge because the big vendors have made us believe it is so.&amp;nbsp;In reality it is not a big challenge.&amp;nbsp;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;There are solutions out there that solve the problem.&amp;nbsp;Remember that&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;cloud security is really about securing the access points – the doors (and&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;windows if applicable) to your house (of data). The walls are obviously secure and impenetrable but if your front (or back door for that matter) is secured with nothing more than a ‘standard’ lock then any thief can quickly pick the lock and get in. For "standard lock" read – "user name and password."&amp;nbsp;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;And the reality is that most applications that are accessed via a standard user name and password ‘lock’ are hosted in the Cloud.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;So what is needed is something much stronger but which is easy to implement and easy to scale. It helps not to use a&amp;nbsp;&lt;span class="qlink_container" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a href="http://www.quora.com/Two-factor-Authentication" style="color: #19558d; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none;"&gt;two-factor authentication&lt;/a&gt;&lt;/span&gt;&amp;nbsp;(2FA)&amp;nbsp; solution that requires you to carry around a dongle – because it just cannot scale economically.&amp;nbsp;And because traditional 2FA solutions are easily hackable through&amp;nbsp;&lt;span class="qlink_container" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a href="http://www.quora.com/Man-in-the-Middle" style="color: #19558d; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none;"&gt;Man in the Middle&lt;/a&gt;&lt;/span&gt;/&lt;span class="qlink_container" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a href="http://www.quora.com/Web-Browsers" style="color: #19558d; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none;"&gt;Web Browser&lt;/a&gt;&lt;/span&gt;&amp;nbsp;attacks.&amp;nbsp;&amp;nbsp;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;So what is needed is a solution is one that is easy accessible and implementable, i.e. a&amp;nbsp;&lt;span class="qlink_container" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a href="http://www.quora.com/SaaS-2" style="color: #19558d; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: none;"&gt;SaaS&lt;/a&gt;&lt;/span&gt;&amp;nbsp;solution; one that is easy to scale (does not require the end user to carry around some kind of device like a dongle or USB key) and one that is strong (is immune to traditional hacks).&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;Check out this video:&amp;nbsp;&lt;a href="http://www.youtube.com/watch?v=L..."&gt;http://www.youtube.com/wa&lt;wbr style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/wbr&gt;tch?v=L...&lt;/a&gt;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;&lt;br style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" /&gt;And you will see that Cloud security is not such a big challenge&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-410526584906527817?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=410526584906527817' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=410526584906527817' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=410526584906527817'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=410526584906527817'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=410526584906527817' title='Why is Cloud Security such a big Challenge ?'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-3190837722603306897</id><published>2011-03-18T17:40:00.000-07:00</published><updated>2011-03-18T17:40:55.072-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cloud security'/><category scheme='http://www.blogger.com/atom/ns#' term='obscurity'/><title type='text'>WHAT IS SECURITY BY OBSCURITY AND WHY HAS RSA STUMBLED?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;The breach at RSA just goes to show that security by obscurity never works. &lt;br /&gt;&lt;br /&gt;And you are probably wondering just what is ‘security by obscurity’ ? &lt;br /&gt;&lt;br /&gt;Lets use a simple metaphor that is familiar to us all to help explain the concept. &lt;br /&gt;&lt;br /&gt;We have all at one time or another left a spare key under the doormat, just in case we are locked out of the house, or we leave it for someone else to use to get in. &amp;nbsp; Well, &amp;nbsp;simply put, that is - security through obscurity.&lt;br /&gt;&lt;br /&gt;The theoretical security vulnerability is that anybody could break into the house by unlocking the door using the spare key from under the mat. &amp;nbsp; &amp;nbsp;Add to that scenario the reality that any burglar worth his salt will check out the most obvious hiding places, and so we, the house owner, run a &amp;nbsp;greater risk of a burglary by hiding the key in this way, since the effort of finding the key is likely to be less effort to the burglar than breaking in by another means. We have in effect added a vulnerability &amp;nbsp;(the fact that the key is stored under the doormat) to the system, and one which is very easy to guess and exploit.&lt;br /&gt;&lt;br /&gt;In the case of computer code or RSA algorithms the assumption is that the algorithm cannot be broken – that the burglar wont find the key under the mat. &amp;nbsp;Alas we have just found out how fatally flawed that logic is. &amp;nbsp;And boy it could not have happened to more iconic an institution than RSA. &amp;nbsp; The very same RSA that invented the public and private key algorithm (based on factoring of primes) that has formed the foundation of Internet security for the last 25 years. &amp;nbsp; But at the end of the day it is still security by obscurity. &amp;nbsp;&lt;br /&gt;&lt;br /&gt;Enter Kerckhoff and his principle. &amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Auguste_Kerckhoffs"&gt;http://en.wikipedia.org/wiki/Auguste_Kerckhoffs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://artofinfosec.com/335/crypto-kerckhoffs-principle/"&gt;http://artofinfosec.com/335/crypto-kerckhoffs-principle/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;“ Assume your enemy has the details of your system “ &lt;br /&gt;&lt;br /&gt;If your security relies on some level of operational system "secrecy" to work, it is just a matter of when, not if, the system will be compromised. The problem with traditional shared secret tokens, &amp;nbsp;(not to mention cost, deployment and custody issues) &amp;nbsp; is that they do nothing to establish context of the mutual authentication i.e. the establishment of trust between the parties. &amp;nbsp; &amp;nbsp;They are merely additional layers of "secret passwords", regardless of how those factors are generated or delivered. &amp;nbsp; &amp;nbsp;&lt;a href="http://www.schneier.com/crypto-gram-0205.html"&gt;http://www.schneier.com/crypto-gram-0205.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The application most used by the RSA SecureID token, being the generation of a “One Time Password” &amp;nbsp;which is then entered into the browser; &amp;nbsp; is reliant upon the integrity of the browser, &amp;nbsp;the very vehicle &amp;nbsp;for which trust has not yet been established. &amp;nbsp; This constitutes a fatal flaw in the ‘design’ of the system. &lt;br /&gt;&lt;br /&gt;The primary issue involved in this breach is the wide applicability of the "secret" elements that were compromised. In a properly architected authentication system, any security failure should be at worst, a one-in-a-row event. &amp;nbsp;In this case – assuming the hackers indeed have succeeded in ‘stealing the password’ &amp;nbsp;( the seed to the key generator) &amp;nbsp;they can exploit the vulnerability of all of RSA’s customers. &amp;nbsp; Not just one or two. &lt;br /&gt;&lt;br /&gt;Being the ‘chosen’ security vendor to &amp;nbsp;“ &amp;nbsp;90% of the Fortune 500 “ &amp;nbsp;( &lt;a href="http://www.rsa.com/node.aspx?id=1002"&gt;per RSA’s website&lt;/a&gt;) &amp;nbsp;leads to hubris and hubris leads to complacency. &amp;nbsp;The World now operates at Internet speed. &amp;nbsp;Just ask the Tunisian and Egyptian ( and who knows more) Governments about that. &amp;nbsp; &amp;nbsp;No one can assume that their position is safe. &amp;nbsp;The rise of Hacktivism (&lt;a href="http://bit.ly/gcqhxe"&gt;http://bit.ly/gcqhxe&lt;/a&gt;)&amp;nbsp;means that security has now risen right up the agenda and for RSA to be seen to be stumbling at such a crucial time could prove to be very damaging. &amp;nbsp; &amp;nbsp;&lt;br /&gt;&lt;br /&gt;Fortunately there are nimble and agile upstarts like &lt;a href="http://www.liveensure.com/"&gt;http://www.liveensure.com&lt;/a&gt;&amp;nbsp;who are showing the industry that innovation is alive and well and that solutions (that work) are available and they are affordable too. &amp;nbsp;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Other references:&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;a href="http://slashdot.org/features/980720/0819202.shtml"&gt;http://slashdot.org/features/980720/0819202.shtml&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-3190837722603306897?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3190837722603306897' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=3190837722603306897' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3190837722603306897'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=3190837722603306897'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=3190837722603306897' title='WHAT IS SECURITY BY OBSCURITY AND WHY HAS RSA STUMBLED?'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-2126017746344844478</id><published>2011-03-16T02:47:00.000-07:00</published><updated>2011-03-16T02:47:06.937-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='data privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><title type='text'>PRIVACY IN THE FACEBOOK ERA</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;So how do you value your privacy in the Facebook age ? &amp;nbsp;I was reviewing some of my old blogs from last year and found this one I did in July last year. &amp;nbsp;It is even more relevant now than it was then. &amp;nbsp;So if you did not read it before then please check it out. &amp;nbsp; &amp;nbsp;Next blog will be on gaming - watch this space. &lt;br /&gt;&lt;br /&gt;Does it matter to you that the calls you make, the emails you send, your credit card transactions, the Internet sites you visit, the images of you travelling to work, your social networking posts are now stored at data centres in the Cloud and retrievable by myriad marketers, Government agencies and companies ? &amp;nbsp; &amp;nbsp;None of whom you ever entrusted with your information in the first place. Your digital footprint is a permanent record of your every move.&lt;br /&gt;&lt;br /&gt;Data is the pollution of the Information age. Everything we do generates data, and a secondary spin-off of Moores law is that every year it gets cheaper to store and process this data. So rather than sort through our e-mails and delete the ones we don’t need – we just keep them all – it is easier and cheaper to do so. The same thing happens with all of our data now.&lt;br /&gt;&lt;br /&gt;Most of ‘your’ data actually belongs to someone else. All of your G-mails, everything you post on Facebook, all of your Amazon transactions – this information belongs to those companies who then harness this information to maximize their advertising revenue and to optimize the selection of products they want you to buy. The data gathered usually has a primary purpose such as the airlines frequent flyer programs where your travel needs are customized (your seating requirements and meal choices ), while its secondary purpose is to target you with a holiday special to some exotic destination, once sold to a 3rd party marketing company.&lt;br /&gt;&lt;br /&gt;The data we generate has value – whether to a company seeking to sell us more product or to a Government agency who is trying to track a terrorist cell. The utility of this data depends on its accuracy – so what may be useful to a marketing company such as your age, salary band and postal code will be insufficient for a National Security Agency . Companies are able increasingly to use this data to control their customers. Think about iTunes and the iPhone and how Apple has managed to control the whole eco-system end to end from the device to the content to the retail process. This is not necessarily a bad thing – users are happy to have this managed for them especially as technology becomes increasingly sophisticated and complex.&lt;br /&gt;&lt;br /&gt;But what happens when you lose control of your data ? When your information is unwittingly exposed to the world. This is a failure of security. But do you care? This is where the issue of the new generation gap becomes relevant. The Internet generation gap. The younger generation seem to be far more relaxed about their information being made public. They are living their lives ‘in public.’ What they did last night at a party is posted onto Facebook either by themselves or their friends. For the whole world to see. This is ‘normal.’&lt;br /&gt;&lt;br /&gt;So what seperates these ‘digital natives ‘ (those who have grown up with the Internet, with cell-phones, in the digital age with ubiquitous connectivity) from those of us who grew up when vinyl was still de rigueur , who watched TV according to a schedule; Generation X’ers who grew up in the pre-celebrity era – when football stars were paid a living wage, when videos and CD’s were mainstream. Bruce Shneier believes this divide – this generation gap can be classified as the divide between those who ‘get ‘ Twitter’ and those who don’t. Age is not the measure; your level of acceptance and comfort with the nuances of social media, your fluency with social media, is.&lt;br /&gt;&lt;br /&gt;The social norms of the digital natives are created by their environment, the world they were born into. Privacy in the pre-Internet age arose from the inefficiencies of prevailing technologies – telephone calls and letters were difficult to track. Now this has changed and because of the massive processing power of Googles’ search engine and other technological innovations privacy has been significantly diminished. Anyone can Google you and find you on Facebook/Twitter/Googlemail and through your friends and friends of friends they can discover a lot about you. Ask any major HR department when they interview job candidates how they do their ‘checking’ on candidates. There is not even a measure of privacy through obscurity, because even the sheer volume of data out there, is no match for the processing power of search algorithms.&lt;br /&gt;&lt;br /&gt;In the past you categorized your friends into different groups with whom your socialized – family, school friends, work colleagues, clubs and so on. There was a natural compartmentalization between these ‘Groups’ - today it is difficult if not impossible to section off your friends into such groups. To control your privacy now you have to explicitly engage with the privacy policy on the social media site / email provider or whatever service you seek online. Many people will accept the default settings just so that they can get on with it – inadvertently leaving big holes in their privacy.&lt;br /&gt;&lt;br /&gt;However regulators and law makers are starting to get firmer and they will have to force providers to allow users to opt in rather than to blindly accept default privacy settings. This should prevent some of the recent privacy debacles like the introduction of Google Buzz and Facebooks’ recent efforts at changing its privacy policies which saw the wholesale disclosure of peoples private information including their emails.&lt;br /&gt;&lt;br /&gt;A good example of how the Regulators are starting to get to grips with these issues is the Code of Conduct recently published by the Information Commissioner in the UK – linked below. But remember that privacy and security do not equate. Security is about you controlling your information. It is up to your to take back control of your data and not to leave it to others. You need to start thinking more about security and how it can be used to protect your data.&lt;br /&gt;&lt;br /&gt;But more of that another time.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-2126017746344844478?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=2126017746344844478' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=2126017746344844478' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=2126017746344844478'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=2126017746344844478'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=2126017746344844478' title='PRIVACY IN THE FACEBOOK ERA'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-7595865076077267854</id><published>2011-03-07T01:34:00.000-08:00</published><updated>2012-02-08T13:44:49.744-08:00</updated><title type='text'>INTERNET GROWTH OVER THE NEXT FIVE YEARS</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;Who would have predicted that a social networking site called Facebook would pick up 600m users in 7 years? &amp;nbsp; Who would have imagined that mobile phones would become such a core part of our daily lives in both &amp;nbsp;rich and poor countries.?&lt;br /&gt;&lt;br /&gt;To try and make some sense of the statistics here are a few simple graphs based on information from a variety of sources that in general corroborate each other.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;GLOBAL POPULATION:&lt;/b&gt; &amp;nbsp;This is projected to grow from the current 6.8bn to about 7.2bn during the next five years. &amp;nbsp; The majority of growth to take place in EMERGING markets. &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh6.googleusercontent.com/-DFMBskX9xVE/TXSiWJcF51I/AAAAAAAAB1U/P5rKCKOgF0M/s1600/GLOBAL+POPULATION.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="https://lh6.googleusercontent.com/-DFMBskX9xVE/TXSiWJcF51I/AAAAAAAAB1U/P5rKCKOgF0M/s320/GLOBAL+POPULATION.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;MOBILE PHONE PENETRATION&lt;/b&gt;: &amp;nbsp;The huge growth experienced over the last 15 years is set to continue, &amp;nbsp;in EMERGING markets in particular ( while in mature markets where penetration is over 100% &amp;nbsp;- older generation phones are being replaced by Smart-phones). &amp;nbsp; &amp;nbsp;Current mobile phone users number in the order of 4.9bn people &amp;nbsp;( or 72% penetration of the global population ) and in five years from now there will be OVER 6.6bn users (or about a 91% penetration of the forecast global population).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh5.googleusercontent.com/-T6vi2NYnWJ0/TXSibcezlFI/AAAAAAAAB1c/eRfKV8WMzgk/s1600/MOBILE+VS+POP.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="196" src="https://lh5.googleusercontent.com/-T6vi2NYnWJ0/TXSibcezlFI/AAAAAAAAB1c/eRfKV8WMzgk/s320/MOBILE+VS+POP.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;INTERNET PENETRATION:&amp;nbsp;&lt;/b&gt;&amp;nbsp;&amp;nbsp;This is set to increase from the current 2bn users (both PC’s &amp;nbsp;and mobile) &amp;nbsp;to about 4.3bn internet users in about five years. &amp;nbsp; So the growth in Internet penetration will be dramatic. &amp;nbsp;Driven mainly by a rapid growth in MOBILE penetration and the ongoing rollout &amp;nbsp;of broadband into residential markets globally. &amp;nbsp;Mobile access to the Internet will increase from the current 840m to about 2.5bn users over the next five years. &amp;nbsp;This includes both Smart-phones as well as tablet devices. &amp;nbsp; In EMERGING markets where penetration is lowest we can expect the quickest take up. &amp;nbsp; I anticipate that Africa will experience an INTERNET revolution over the next ten years in the same way that it experienced a MOBILE revolution over the last fifteen years. &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh4.googleusercontent.com/-5sxBdbrzrB4/TXSibKgnXXI/AAAAAAAAB1Y/AyKHBxfM32c/s1600/INTERNET+VS+MOBILE+INT.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="https://lh4.googleusercontent.com/-5sxBdbrzrB4/TXSibKgnXXI/AAAAAAAAB1Y/AyKHBxfM32c/s320/INTERNET+VS+MOBILE+INT.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Finally &amp;nbsp;- &lt;b&gt;THE INTERNET OF THINGS&amp;nbsp;&lt;/b&gt;&lt;br /&gt;The number of devices are that are connected to the Internet is expected to pass 5 billion this year according to IMS research (this includes digital picture frames, cameras and e-book readers) and predictions are that by 2020 the number of connected ‘things’ will surpass 22 billion. &amp;nbsp; &amp;nbsp;So these devices will become an integral part of the Internet and will communicate with each other as well as with humans to varying degrees. &amp;nbsp;The INTERNET will connect 'things' in a woven fabric encircling the earth. &amp;nbsp; &amp;nbsp;&amp;nbsp;Check out this video from IBM . &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/sfEbMV295Kk/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/sfEbMV295Kk&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266" src="http://www.youtube.com/v/sfEbMV295Kk&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Enjoy.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-7595865076077267854?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=7595865076077267854' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=7595865076077267854' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=7595865076077267854'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=7595865076077267854'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=7595865076077267854' title='INTERNET GROWTH OVER THE NEXT FIVE YEARS'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh6.googleusercontent.com/-DFMBskX9xVE/TXSiWJcF51I/AAAAAAAAB1U/P5rKCKOgF0M/s72-c/GLOBAL+POPULATION.gif' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-6087730286595012586</id><published>2011-02-27T15:30:00.000-08:00</published><updated>2011-03-01T04:23:35.950-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mobile telephony'/><category scheme='http://www.blogger.com/atom/ns#' term='internet security'/><category scheme='http://www.blogger.com/atom/ns#' term='political change'/><category scheme='http://www.blogger.com/atom/ns#' term='social media'/><category scheme='http://www.blogger.com/atom/ns#' term='china'/><title type='text'>WILL SOCIAL MEDIA CHANGE CHINA ?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;Surely this has got to be the obvious question in light of the tectonic shifts reshaping the Maghreb? &lt;br /&gt;&lt;br /&gt;Is the end game (of this social media phenomenon), &amp;nbsp;not the demise of the last autocratic regime of any substance ? &amp;nbsp; ( there are others that will go – but are they as important ? No. &amp;nbsp;)&lt;br /&gt;&lt;br /&gt;There are so many factors at play in the next scene of this incredible drama. &amp;nbsp; Saudi Arabia has made an offer to buy Facebook &amp;nbsp;for the ‘princely’ sum of $150bn and hence remove any threat it may pose to stirring unrest in the country. &amp;nbsp;(&amp;nbsp;&lt;a href="http://abna.ir/data.asp?lang=3&amp;amp;id=228583"&gt;http://abna.ir/data.asp?lang=3&amp;amp;id=228583&lt;/a&gt;) ( BIG JOKE !!!) &amp;nbsp;Seems like an expensive mistake by King Abdullah if Zuckerburg and Co are foolish enough to be bamboozled by Goldman Sachs into accepting the offer. &amp;nbsp; &amp;nbsp;If he thinks that FB is the only way that revolutions are coordinated then he is being badly advised. &lt;br /&gt;&lt;br /&gt;You only have to read Bernard Henri Levy’s excellent analysis of what transpired in Egypt leading up to the uprising to understand the extent of the ingenuity of a determined disenfranchised population to rid themselves of their ‘leaders’. &amp;nbsp;(&lt;a href="http://www.huffingtonpost.com/bernardhenri-levy/egypt-year-zero_b_828455.html"&gt;http://www.huffingtonpost.com/bernardhenri-levy/egypt-year-zero_b_828455.html&lt;/a&gt;)&lt;br /&gt;By combining the power of telephony with that of the Internet they created ‘speak2tweet’ to circumvent the Web police. &amp;nbsp; The rest as they say ‘ is History’. &lt;br /&gt;&lt;br /&gt;Surely the same could happen in China. &amp;nbsp; Although this applies to Iran and Saudi Arabia not to mention the myriad other Maghreb /ME countries where dissent is fomenting from Jordan to Yemen to Morocco and even Qatar -&amp;nbsp;&amp;nbsp;China is far more interesting. &lt;br /&gt;&lt;br /&gt;This would be the prize. &lt;br /&gt;&lt;br /&gt;In one fell swoop we would have almost 20% of humanity freed from the oppression of an autocratic undemocratic regime. &amp;nbsp; Who knows what would replace it but one would hope that it would be a system – not a liberal Western democracy – but some hybrid that allows for more personal freedoms and participation in the political process. &lt;br /&gt;&lt;br /&gt;China cannot maintain a 9 or 10% growth rate and thereby generate the wealth that takes people out of poverty on an indefinite basis. &amp;nbsp; The &amp;nbsp;environmental burden on the land and the air is not sustainable, &amp;nbsp;the clamour for higher wages gets ever louder and there have been many job losses in the cities because of the financial crisis. &amp;nbsp;During 2009/10 over 50m lost their jobs in the cities on the East coast and returned to the farms inland. &amp;nbsp; Thus there were 50m fewer providers and more mouths to feed with less food. &amp;nbsp; China will struggle to feed its population if it does not colonize sufficient land in Africa (particularly) to supplement its current sources. &amp;nbsp; &amp;nbsp;Hence the indecent haste with which it is currently doing deals across Africa, to not only tie up commodities to feed its industrial engine but also, &amp;nbsp;to secure arable land. (Only about 15% of China’s land is arable and it reduces as the population grows)&lt;br /&gt;&lt;br /&gt;So what are the authorities in China doing about this ? &amp;nbsp; In addition to becoming the &amp;nbsp;Worlds 21st Century Colonizing power &amp;nbsp;- China is making a huge investment in transport infrastructure inside China to ensure that food can be delivered efficiently. &amp;nbsp;Rail and air infrastructure in particular is the main focus. &amp;nbsp; There has also been a massive investment in shipping cargo capacity to ensure that they can move the goods (commodities including food) &amp;nbsp;back to China from their economic colonies. &amp;nbsp; The NPC (National Peoples Congress) is to be held on 5 March in Beijing and no doubt economic issues will be high on the agenda. &amp;nbsp;However I suspect that they will also discuss the events of the last few weeks and months in the Arab world and what it could mean for China. &lt;br /&gt;&lt;br /&gt;There was an anonymous call for protests in China but the police have so far pre-empted any action. (&lt;a href="http://www.guardian.co.uk/world/2011/feb/27/china-jasmine-revolution-beijing-police"&gt;http://www.guardian.co.uk/world/2011/feb/27/china-jasmine-revolution-beijing-police&lt;/a&gt;). This is no doubt a portent of things to come.&lt;br /&gt;&lt;br /&gt;The Telegraph reported that : &lt;br /&gt;"We invite every participant to stroll, watch or even just pretend to pass by," said a letter published on Boxun, a foreign-based website that is banned in China. "As long as you are present, the authoritarian government will be shaking with fear". It was the second weekend in a row that protests were planned.&lt;br /&gt;&lt;u&gt;(&lt;a href="http://www.telegraph.co.uk/news/worldnews/asia/china/8350709/Heavy-handed-reaction-to-Chinas-Jasmine-protests.html"&gt;http://www.telegraph.co.uk/news/worldnews/asia/china/8350709/Heavy-handed-reaction-to-Chinas-Jasmine-protests.html&lt;/a&gt;)&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;So will the power of social media come to bear on the World’s largest oppressive regime and how long will it take.? &amp;nbsp; &amp;nbsp;Will the economic growth of the last 30 years together with the massive connectivity of mobile phones and Internet become the double-edged sword that leads to the demise of the Chinese political machine that has managed the economic growth so well and so tightly. &lt;br /&gt;&lt;br /&gt;Watch this space. &amp;nbsp;This promises to be a bigger year than 1989 – in more ways than one.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-6087730286595012586?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6087730286595012586' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=6087730286595012586' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6087730286595012586'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6087730286595012586'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=6087730286595012586' title='WILL SOCIAL MEDIA CHANGE CHINA ?'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-8783769897480254156</id><published>2011-02-16T04:36:00.000-08:00</published><updated>2011-02-16T04:37:38.308-08:00</updated><title type='text'>MOBILE or M-COMMERCE COMES OF AGE ?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;What is mobile commerce you may well ask?&amp;nbsp;&amp;nbsp; Well mobile payments comprise two categories – 1) payments for digital (virtual) goods usually done online and 2) &amp;nbsp;payments for physical goods usually done at a POS.&amp;nbsp;&amp;nbsp; The latter usually being of larger transaction value.&amp;nbsp;&amp;nbsp; So&amp;nbsp; when will we use our mobiles (in any real number) to make these day to day payments and also use them for online banking ? &amp;nbsp;&amp;nbsp;&amp;nbsp;My view is that this will be driven by both; &amp;nbsp;1) the &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;adoption of &amp;nbsp;technologies&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt; like NFC by the handset manufacturers and the POS manufacturers and the merchants;&amp;nbsp; and 2) &amp;nbsp;the &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;acceptance by users of these new technologies&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp; I suspect that the latter will take longer&amp;nbsp; - as people are naturally cautious about adopting new &amp;nbsp;technologies particularly when money is involved. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The major &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;handset manufacturers have started building NFC chips into their handsets&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt; as the GSMA have finalized the specification for NFC on GSM phones.&amp;nbsp; &amp;nbsp;Apple recently ‘leaked’ the news that the iPhone 5 will be NFC enabled and all the big names – Samsung/Nokia/Motorola/Ericsson/ZTE have announced NFC phones for launch this year.&amp;nbsp;&amp;nbsp;Google are very optimistic about the prospects for mobile commerce. (&lt;u&gt;http://www.mobilemarketingwatch.com/google-ceo-says-nfc-mobile-payments-will-prove-profitable-13258/&lt;/u&gt;)&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;Users will take a bit longer to get used to scanning their phones (not Oyster cards) at the readers on the Underground or at retail checkouts.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;It is mainstream in Japan&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt; and will become the same in the rest of the World.&amp;nbsp;(&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;u&gt;http://www.nma.co.uk/news/japan-leads-global-mobile-commerce-market/3023422.article&lt;/u&gt;&lt;/span&gt;)&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;&amp;nbsp;The mobile device has become &amp;nbsp;(and will increasingly continue to become) the medium where we consume advertising now more focused and bespoke to our individual requirements.&amp;nbsp; &amp;nbsp;Gaming manufacturers recognise the power of the mobile platform for their products and with the increasing trend towards social gaming have become another very important commerce layer on the mobile.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;span lang="EN-US"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Security is an issue.&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp;&amp;nbsp; Hackers have recognized that the adoption of mobile commerce is growing rapidly and they have turned their attention to this platform for the spread of malware, ID theft and online fraud.&amp;nbsp;&amp;nbsp;&amp;nbsp; However this will be a much bigger challenge for them because of the diversity of platforms (unlike in the desk/laptop world where 75% of Operating Systems are Microsoft).&amp;nbsp;&amp;nbsp; &amp;nbsp;Anti-virus software will be less important than &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;appropriate authentication solutions&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt; which will enable trusted transactions to take place.&amp;nbsp;&amp;nbsp;&amp;nbsp; These solutions will of necessity need to be light weight and not require the user to interface with any additional physical devices like dongles/ card readers/ USB keys etc which proliferate in the desktop world. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Of course mobiles will be used for more than just banking – &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;remittances, money transfer and voucher redemptions will become mainstream&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;. &amp;nbsp;&amp;nbsp;Expect smart-phones to get even smarter and to form a greater and greater proportion of all phones as the old ones die out and are replaced.&amp;nbsp;&amp;nbsp; By 2014 50% of mobile phone users will be using their phones to make payments according to Juniper – so the trend is strong and it is here to stay.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="BingExtMinimized" id="BingExt" style="display: inline; left: 129px; opacity: 1; top: 319px;"&gt;&lt;div id="BingExtContent"&gt;&lt;div id="BingExtTranslation" style="display: none;"&gt;&lt;/div&gt;&lt;div id="BingExtMaps" style="display: none;"&gt;&lt;/div&gt;&lt;div id="BingExtFlightStatus" style="display: none;"&gt;&lt;/div&gt;&lt;div id="BingExtDefault" style="display: none;"&gt;&lt;div id="BingExtDefaultText"&gt;&lt;div class="BingExtContentSeparator"&gt;&lt;/div&gt;&lt;a class="BingExtSearchForLink" href="" id="BingExtDefault.search"&gt;Search for &lt;span class="BingExtSearchForLinkHighlighted"&gt;http://www.mobilemarketingwatch.com/google-ceo-says-nfc-mobi ...&lt;/span&gt;&lt;/a&gt; &lt;a class="BingExtSearchForLink" href="" id="BingExtDefault.map"&gt;Search for a map&lt;/a&gt; &lt;a class="BingExtSearchForLink" href="" id="BingExtDefault.translate"&gt;Translate&lt;/a&gt; &lt;div class="BingExtContentSeparator"&gt;&lt;/div&gt;&lt;div class="BingExtBottomSection"&gt; &lt;div class="BingExtAttribution BingExtHidden"&gt; &lt;div class="BingExtAttributionText"&gt;Source: Attribution goes here&lt;/div&gt;&lt;/div&gt;&lt;div class="BingExtFooter"&gt; &lt;div class="BingExtFooterLink"&gt;&lt;a href="" id="BingExtDefault.about"&gt;About Bing Highlights&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="BingExtHidden" id="BingExtAbout"&gt; &lt;div class="BingExtContentSeparator"&gt;&lt;/div&gt;&lt;div id="BingExtAboutText"&gt; &lt;div class="BingExtAboutTitle"&gt;&lt;div&gt;Bing Highlights&lt;/div&gt;&lt;div id="BingExtAboutClose"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="BingExtAboutVersion"&gt;Version 1.0.0 (12)&lt;/div&gt;&lt;div class="BingExtAboutCopyright"&gt;Copyright © 2010 Microsoft Corporation. All rights reserved.&lt;/div&gt;&lt;a class="BingExtAboutLink" href="" id="BingExtSupportLink"&gt;Support&lt;/a&gt;&lt;/div&gt;&lt;div class="BingExtBottomSection"&gt; &lt;div class="BingExtAttribution BingExtHidden"&gt; &lt;div class="BingExtAttributionText"&gt;Source: Attribution goes here&lt;/div&gt;&lt;/div&gt;&lt;div class="BingExtFooter"&gt; &lt;div class="BingExtFooterLink"&gt;&lt;a href="" id="BingExtDefault.about"&gt;About Bing Highlights&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="BingExtTopSection"&gt;&lt;div id="BingExtHeader"&gt;&lt;input class="BingExtHidden" id="BingExtButtonMapsRadio" name="BingExtButton" type="radio" /&gt;&lt;label class="BingExtButton" for="BingExtButtonMapsRadio" id="BingExtButtonMaps" style="display: none;" title="Maps"&gt;&lt;/label&gt;&lt;input class="BingExtHidden" id="BingExtButtonTranslateRadio" name="BingExtButton" type="radio" /&gt;&lt;label class="BingExtButton" for="BingExtButtonTranslateRadio" id="BingExtButtonTranslate" style="display: none;" title="Translations"&gt;&lt;/label&gt;&lt;input class="BingExtHidden" id="BingExtButtonFlightStatusRadio" name="BingExtButton" type="radio" /&gt;&lt;label class="BingExtButton" for="BingExtButtonFlightStatusRadio" id="BingExtButtonFlightStatus" style="display: none;" title="Flight Status"&gt;&lt;/label&gt;&lt;input class="BingExtHidden" id="BingExtButtonSearchRadio" name="BingExtButton" type="radio" /&gt;&lt;label class="BingExtButton" for="BingExtButtonSearchRadio" id="BingExtButtonSearch" style="display: block;" title="Search"&gt;&lt;/label&gt;&lt;div id="BingExtLogo" title="Bing"&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div id="BingExtSpinner" style="display: none;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-8783769897480254156?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8783769897480254156' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=8783769897480254156' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8783769897480254156'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=8783769897480254156'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=8783769897480254156' title='MOBILE or M-COMMERCE COMES OF AGE ?'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6404704753143794967.post-6703356471130138009</id><published>2011-02-15T03:00:00.000-08:00</published><updated>2011-02-15T03:00:28.182-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='2FA'/><category scheme='http://www.blogger.com/atom/ns#' term='rsac'/><title type='text'>WHAT IS GOING ON AT INTEL ?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;!--StartFragment--&gt;  &lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;So last year Intel splash out almost $8bn on (one of their largest ever acquisitions) on&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;McAfee &amp;nbsp;in their quest to keep abreast of the rapidly moving Internet security market.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;One of their motivations was : &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;“&lt;i style="mso-bidi-font-style: normal;"&gt;But Intel will take it one step further. The McAfee deal will see the integration of security into hardware, into the chips powering much of our computer-driven world. It also bolsters Intel's attempts to become more than a chip maker as it develops its own consumer devices and offering of IT services&lt;/i&gt;. “&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;(http://www.bbc.co.uk/news/business-11025866)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;And yet today they announce : &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;“&lt;i style="mso-bidi-font-style: normal;"&gt;Phishers are getting so good and so numerous that even the most technically adept of online bankers should think twice before typing in that password. Even if it's a legit site, databases can be infiltrated and passwords can be cracked. Time for something more, then. Intel is working on it, teaming up with Symantec and Vasco on what's being broadly termed Identity Protection Technology, or IPT.”&lt;/i&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;(&lt;a href="http://www.engadget.com/2011/02/15/intel-working-with-symantec-and-vasco-for-ipt-hardware-based-se/"&gt;http://www.engadget.com/2011/02/15/intel-working-with-symantec-and-vasco-for-ipt-hardware-based-se/&lt;/a&gt;) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;So you have to say:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Was the McAfee deal fatally flawed ?&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Has Intel become schizophrenic ?&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Is the security market potentially so lucrative that you become totally promiscuous and jump into bed with anyone who says yes ? &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Maybe the RSA conference is going to be where these strands all come together ??&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Who knows? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;To cap it all this week Intel Capital announced that they have invested in a small security company called SecureKey.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;We don’t know how much – but it would have been extremely modest relative to the McAfee deal.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;The point is that SecureKey is nothing more than a re-hash of old technology – key fobs / USB keys.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;It is also limited in its application to users of smart cards.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;So all of this stuff that you have to carry around with you for security. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;All very expensive, non-scalable and insecure.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Check it out for yourself.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;(&lt;a href="http://www.securekey.com/"&gt;http://www.securekey.com/&lt;/a&gt;) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;You have to say:&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;what are the boys at Intel thinking ?&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;Maybe there is another announcement coming at RSA which will help us all make sense of this – but I suspect not.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-ansi-language: EN-GB;"&gt;Watch this space.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;!--EndFragment--&gt;   &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6404704753143794967-6703356471130138009?l=rossmac2310.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6703356471130138009' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.liveensure.com/blog.php?id=6703356471130138009' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6703356471130138009'/><link rel='self' type='application/atom+xml' href='http://www.liveensure.com/blog.php?id=6703356471130138009'/><link rel='alternate' type='text/html' href='http://www.liveensure.com/blog.php?id=6703356471130138009' title='WHAT IS GOING ON AT INTEL ?'/><author><name>Ross</name><uri>http://www.blogger.com/profile/17688081930736649538</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.loghound.com/g/2005#thumbnail' width='16' height='32' src='http://1.bp.blogspot.com/_YZaxEOTl7NI/S8dJ-lIRG-I/AAAAAAAAByA/amwIutkaVa0/S220/P1050558.JPG'/></author><thr:total>0</thr:total></entry></feed>
