Re: Re[3]: RSA SecurID SID800 Token vulnerable by design

2006-09-11 Thread Brian Eaton
On 9/11/06, 3APA3A [EMAIL PROTECTED] wrote: BE Two-factor auth cannot be said to make accessing the network from a BE compromised PC safe. That does not make two-factor auth useless. BE With plain passwords, once the attacker has the password, they can BE access the network at will. With

Re[3]: RSA SecurID SID800 Token vulnerable by design

2006-09-11 Thread 3APA3A
Dear Brian Eaton, --Saturday, September 9, 2006, 6:12:31 PM, you wrote to [EMAIL PROTECTED]: BE For web SSO in particular, accessing the token once is nearly as good BE as accessing it constantly. The token will be used for the initial BE authentication, but normally a cookie will be used for