authenticity

What the RSA breach means for you (FAQ)

RSA warned its customers yesterday that its network had been breached and data had been stolen that could affect customers using its popular SecurID token authentication technology. Although details are scarce, here's what we know so far.

What happened? Someone launched an "extremely sophisticated cyberattack" on RSA in the form of an Advanced Persistent Threat and data was stolen related to the SecurID technology, the company said in a statement on its Web site. APT attacks are often used for espionage, targeting source code and other information within a company or government agency. They typically involve knowledge … Read more

How to manage keychain clutter in OS X

The OS X keychain is a useful and secure way to save passwords, certificates, and other authentication information for applications, Web sites, and various other services. By default these are generally loaded into either the log-in keychain or the System kechain, depending on whether the service is user-oriented or a system setting such as Wi-Fi or VPN passwords.

Though the keychain is convenient, sometimes after extensive use it can become cluttered with numerous items. Generally this clutter does not harm anything, but sometimes it can result in odd problems such as the incorrect password being used for a service even … Read more

To fight spam, Google Apps adds e-mail signing

Google has made it possible for Google Apps customers to sign their outgoing e-mail using a technology called DomainKeys Identified Mail (DKIM) that makes it easier to ensure a sender is who he or she says he is.

Google has been using DKIM since 2008 to show Gmail users when incoming mail really is from PayPal and eBay--two major brand names often caught up in spoofed e-mails used in phishing attacks. Now the technology is available more broadly and for the e-mail Google Apps users send.

"Today...we're making it possible for all Google Apps customers to sign … Read more

Google makes it easier to authenticate e-mail

Google announced today that it is making it easy for organizations using Google Apps to authenticate outgoing mail so that recipients can rest assured that the messages are really from them and aren't spam.

Administrators of all editions of Google Apps can enable the DomainKeys Identified Mail technology for outgoing mail in the "Advanced Tools" tab of the control panel by checking several boxes. Gmail has supported e-mail signing standards since its inception in 2004, but implementation required more configuration and resources than that.

Functionally, this means fewer legitimate e-mail messages will be blocked by spam filters. … Read more

How to clear a network authentication hang in OS X

Generally when errors occur during authentication for network services such as file sharing or screen sharing in OS X the connection will either time out or immediately give a warning, but sometimes connections may hang when authenticating. When this happens the connection will not be established and the authentication window will remain on-screen as a floating window that will block other windows and show a continuous revolving activity indicator next to a "Connecting..." status message.

While the window usually has options for canceling the connection, the hang prevents these from being active and results in the only way … Read more

FaceTime not authenticating after hardware changes

If you choose to upgrade the hard drive on your system either for a faster drive or for one with more space, you may find Apple's new FaceTime videoconferencing application will no longer authenticate. When launched, the program will give an error stating "The server encountered an error processing registration. Please try again later."

This has been shown to happen when people have upgraded from magnetic hard drives to SSD drives, but may also happen with other hardware changes as well. The problem is because Apple uses a certificate system for authenticating your system with FaceTime, and … Read more

Mobile codes to boost Google account security

Google is making it harder for Gmail and other Google Apps accounts to get compromised by adding an optional feature that will send a security code to your smartphone for logging in.

The two-step verification feature will be available to Google Apps premier, education, and government customers on Monday, and to the hundreds of millions of individual Google users in coming months, as a built-in part of the free service, a Google product manager told CNET.

Until now, Google accounts have been protected only with passwords, which are susceptible to phishing and other social-engineering attacks.

The two-step verification feature will … Read more

Can VeriSign deal make Symantec the Web's identity broker?

With its acquisition of VeriSign's authentication business, Symantec is making a big play for a piece of the market for services that validate the identity of users and content on the Web.

The $1.28 billion cash deal--the third encryption-related purchase for Symantec in three weeks--would seem to be a natural extension of its desktop and server security offerings, several analysts said. But other observers question how well suited one of the leading antivirus providers really is to become the identity broker for the Internet.

"Where's the synergy?" wondered Avivah Litan, an analyst at Gartner, … Read more

Screen Sharing pausing and delaying on connection

When connecting to a computer using Apple's "Screen Sharing" feature, you may run into a problem where the system pauses and shows the spinning color wheel and does not connect. The problem happens immediately after authenticating the connection, and usually shows a black "Screen Sharing" window along with the color wheel.… Read more

Is your brand vulnerable?

Social media strategist Shannon Paul, who works with the NHL Detroit Red Wings, said many good things on a SXSW panel this Sunday, but the one thing that stuck with me most was her assertion that brands need to become more “human” in order to connect with their audiences. She wasn’t referring to personifying a brand through a human face (be it an average employee or a charismatic leader), but rather to exhibiting ‘branded’ behavior that is truly human. What does that mean? What is the most human trait of all human traits? Shannon Paul posits it’s vulnerability.… Read more