When A Password Is Not A Password

Kenneth P. Weiss · 1990

Single-factor password technology is not appropriate in today’s networked environment. Powerful workstations, file servers, and remotely accessible mainfraimes require new high tech computer security solutions. Often, the technologies available and the reasons for them are not well understood. This presentation focuses on the less obvious vulnerabilities of information systems and the philosophy and technology behind two-factor identification, authentication, and access control systems; and how they can be technically overlaid for implementation in existing environments. The theoretical issues associated with using ignition keys stored in tokens versus transmitting them in both clear text and encrypted form are discussed.

Read the paper · More papers on PaperTik