17, March 2010

Making website log-in more secure - webmaster forum

 
Webdigity webmaster forums
[ Home | Help | Search | Forum's Shop | Archive | Login | Register | Webmaster Directory ]
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Making website log-in more secure
« previous next »
Pages: [1] Print

Author Topic: Making website log-in more secure  (Read 1010 times)
Atari ST fan
*
Posts: 7
46 credits
Members referred : 0


« on: Mar 26, 2009, 11:33:42 pm »

Hi all,

I want to make the log-in process to the secured area of our company website more secure by adding multi-factor authentication (we are currently just using username/pw) Does anyone know of a good system to use?

I have been trying to find a system myself online, but the only reasonable option I found is SafeTok (safetok.com). Does anybody have experience with this system?

I really like about SafeTok that it will be for free for us and our users since it's free to implement and the users do not need to buy expensive tokens for it but can just use any available USB stick or other consumer electronics item (mobile phone, ipod etc.) they already have. However, I wonder how our users will take the introduction of the system. Do you reckon that the users will find the system easy to use and the transition to the multi-factor authentication will go smoothly? Do you think the SafeTok system is a good option? What factors are most important to consider when implementing multi-factor authentication? If you have already integrated multi-factor authentication, what was most important to you and what did you find most troublesome? What system did you choose and why?
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5659
45587 credits
Members referred : 3



« Reply #1 on: Mar 27, 2009, 12:35:07 am »

I don't really find a reason to use such a thing for a website login. There are solutions like ssl which are 100% secure.

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Atari ST fan
*
Posts: 7
46 credits
Members referred : 0


« Reply #2 on: Mar 27, 2009, 12:39:48 am »

Yeah but only if the users are actually vigilant... SSL doesn't really prevent phishing... After all even a phishing website can use SSL...
And then there are key-loggers... And what if users are careless with their passwords? (i.e. write them on post-it notes that the leave on their desk, use them for other services with lower security,...)
« Last Edit: Mar 27, 2009, 12:48:23 am by Magic »
Global Moderator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 6690
34708 credits
Members referred : 374


It's time to use PHP5!


« Reply #3 on: Mar 27, 2009, 07:58:51 am »

Just block the IP address after x un-successful attempts or 5 wrong passwords for one user name.

check the authentication from Google, works great


Last blog : A new Wordpress theme for our blog
I am a metal monkey!
Administrator
Community Supporter ?
Jedai Sword Master
*****
Gender: Male
Posts: 5659
45587 credits
Members referred : 3



« Reply #4 on: Mar 27, 2009, 01:06:41 pm »

I suppose if someone can sniff an SSL connection (that requires public/private keys) then why it would be impossible to sniff such a device?

Trial and Error my two best teachers Cool
Join us @ facebook or twitter

Last blog : Butterfly Marketing 2.0
Atari ST fan
*
Posts: 7
46 credits
Members referred : 0


« Reply #5 on: Mar 27, 2009, 03:33:59 pm »

I think we are misunderstanding each other.

I am not worried at all about someone breaking SSL or brute-forcing the passwords out. What I am concerned about are social engineering & keylogger type of attacks.

For example:
  • The user having troubles remembering the password and writing it on a post-it note. His cleaning lady (or whoever) reading it and getting access to the account
  • Phishing - The user receiving an e-mail which seems to come from us, (but has been sent by an attacker) asking him to visit a link. The linked website looks like our webpage and asks the user to enter his username/password data for whatever reason (security checks, renewing account, whatever). If he does so, the data is submitted to an attacker who now has all data to log in
  • The user having a key-logger installed that captures the username & password entered when he visits our website and logs-in. The key-logger then submitting the data to the attacker who has all data required to log-in.
  • ...

The list of posisble attacks goes on and on.. It's really endless. SSL won't help against phishing, since it only ensures that the data is securely submitted - not that the user submits it to the right webpage. Actually, the phishing page could send the data to the attacker using SSL... Similarly limiting log-in attempts won't help since the attacker knows the correct log-in data.
Atari ST fan
*
Posts: 7
46 credits
Members referred : 0


« Reply #6 on: Mar 31, 2009, 01:57:44 am »

I just found a link to a page which tells the story of a guy who got phished.
flickr.com/photos/toasty/1276202472/
Think this should help to understand what kind of attacks I want to prevent.

« Last Edit: Mar 31, 2009, 02:02:31 am by Magic »
Spy Agent
***
Gender: Male
Posts: 113
70 credits
Members referred : 0


« Reply #7 on: Mar 31, 2009, 03:05:22 pm »

So do you want a system where users click on a combination of numbers to enter a secret 4 digit code? This number would be unique and the keylogger couldn't track it as its only using the mouse.
Trackback URI for this entry : http://www.webdigity.com/trackback.php?topic=8617
Tags : SafeTok fingerprint log-in web log-in online authentication secure log-in Bookmark this thread : Digg Del.icio.us Dzone more....

Pages: [1] Print 
Webdigity Webmaster Forums  >  Web Development  >  Security
Topic: Making website log-in more secure
« previous next »
Jump to:
User Area
Welcome, Guest. Please login or register.
Did you miss your activation email?
Mar 17, 2010, 02:28:17 am





Login with username, password and session length

Donate to our community, and get a permanent link back to your site!

Donate to our community, and get a permanent link back to your site!


Forum Statistics
Total Posts: 44.173
Total Topics: 8.616
Total Members: 8.211
Tutorials : 58
Resources : 929
Designs : 360
Latest Member: makebelieve

54 Guests, 5 Users online :

15 users online today:



Readers

Web Design Gallery · Whois Lookup · Pagerank · Tag Browsing · Lo-fi version · Syndication · Webmaster forum history · Advertise
Developed by HumanWorks © 2005 - 2010 Webdigity webmaster community · sublime directory
Webdigity Webmaster Forums | Powered by SMF 1.0.12. © 2001-2005, Lewis Media. All Rights Reserved.