<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Authentication on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/authentication/</link>
    <description>Recent content in Authentication on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 27 Jan 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/authentication/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Part I: Bluetooth Auracast from a Security Researcher’s Perspective</title>
      <link>https://insinuator.net/2025/01/part-i-bluetooth-auracast-from-a-security-researchers-perspective/</link>
      <pubDate>Mon, 27 Jan 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/01/part-i-bluetooth-auracast-from-a-security-researchers-perspective/</guid>
      <description>&lt;p&gt;Auracast, the new Bluetooth LE Broadcast Audio feature has gained some publicity&#xA;in the past months. The Bluetooth SIG has introduced the LE Audio feature-set to&#xA;the Bluetooth 5.2 Specification in 2019 and vendors are only now starting to&#xA;implement it. Auracast facilitates broadcasting audio over Bluetooth LE to a&#xA;potentially unlimited number of devices. It does not require pairing or&#xA;interaction between the sender and the receivers.&lt;/p&gt;&#xA;&lt;p&gt;We also presented this topic&#xA;&lt;a href=&#34;https://media.ccc.de/v/38c3-auracast-breaking-broadcast-le-audio-before-it-hits-the-shelves&#34;&gt;at 38c3&lt;/a&gt;.&#xA;This blog post will contain similar contents albeit with some more details.&lt;/p&gt;</description>
    </item>
    <item>
      <title>White Paper on Multi-Factor Authentication in Microsoft Windows Environments</title>
      <link>https://insinuator.net/2018/01/white-paper-on-multi-factor-authentication-in-microsoft-windows-environments/</link>
      <pubDate>Mon, 29 Jan 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/01/white-paper-on-multi-factor-authentication-in-microsoft-windows-environments/</guid>
      <description>&lt;p&gt;A new ERNW whitepaper was just published. I wrote this whitepaper in the course of my bachelor thesis and it examines multi-factor authentication in Microsoft Windows environments:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Credential theft and the subsequent reuse of stolen credentials are a significant problem in today’s information security. To counter the associated risks, a planned approach is required as part of a comprehensive security architecture program. This includes the implementation of multi-factor authentication as an important building block. This whitepaper covers the relevant steps of implementing a multi-factor authentication system in an enterprise environment and closes with a security evaluation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Newsletter 42: Dangers of Disabled Pre-Boot Authentication in  Corporate Environments</title>
      <link>https://insinuator.net/2013/12/ernw-newsletter-42-dangers-of-disabled-pre-boot-authentication-in-corporate-environments/</link>
      <pubDate>Mon, 16 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/ernw-newsletter-42-dangers-of-disabled-pre-boot-authentication-in-corporate-environments/</guid>
      <description>&lt;p&gt;It’s been a long time… we just published an &lt;a href=&#34;https://www.ernw.de/category/newsletter/index.html&#34;&gt;ERNW Newsletter&lt;/a&gt;. Here’s the abstract:&lt;/p&gt;&#xA;&lt;p&gt;In order to protect sensitive data on corporate laptops, most companies are using full disk encryption solutions. While native encryption products like Microsoft Bitlocker, Apple FileVault and open source solutions like TrueCrypt were already heavily scrutinized by security researchers, many popular commercial third party products are to some point still black boxes.&lt;/p&gt;&#xA;&lt;p&gt;In this paper, we discuss Check Point Full Disk Encryption (FDE) with active “Windows Integrated Logon”. Checkpoint FDE is a software package that is part of Check Point Endpoint Security and offers full disk encryption on Microsoft  Windows and Mac OS X systems. The “Windows Integrated Logon” feature reduces total cost of ownership by disabling pre-boot authentication. Check Point themselves warn about security risk associated with using this feature.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Certificate Based Device Authentication with iOS Devices</title>
      <link>https://insinuator.net/2011/10/certificate-based-device-authentication-with-ios-devices/</link>
      <pubDate>Wed, 05 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/certificate-based-device-authentication-with-ios-devices/</guid>
      <description>&lt;p&gt;We recently performed a Proof-of-Concept (PoC) implementation of certificate based auth with iPads in some large environment. So far the focus has been mainly on WLAN access; VPN and EAS authentication are going to follow in the next step.&lt;/p&gt;&#xA;&lt;p&gt;As we figure that the topic might be of interest for some of you, we’ve extracted a certain, not-too-customer-specific part of the deliverable and converted it into an &lt;a href=&#34;http://www.ernw.de/content/e15/e26/e1662/download1664/ERNW_Newsletter_36_Cert_for_iOS_en_ger.pdf&#34;&gt;ERNW newsletter&lt;/a&gt;. Special thanks go to Rene Graf for leading the project! 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Series on “Outdated Threat Models” – Part 1</title>
      <link>https://insinuator.net/2009/10/series-on-outdated-threat-models-part-1/</link>
      <pubDate>Sun, 25 Oct 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/10/series-on-outdated-threat-models-part-1/</guid>
      <description>&lt;p&gt;Yesterday I took a long run (actually I did the full distance &lt;a href=&#34;http://www.albmarathon.de&#34;&gt;here&lt;/a&gt;) and usually such exercises are good opportunities to “reflect on the world in general and the infosec dimension of it in particular”… at least as long as your blood sugar is still on a level to support somewhat reasonable brain activity 😉&lt;/p&gt;&#xA;&lt;p&gt;Anyhow, one of the outcomes of the number of strange mental stages I went through was the idea of a series of blogposts on architectural or technological approaches that are widely regarded as “good security practice” but may – when looked at with a bit more of scrutiny – turn out to be based on what I’d call “outdated threat models”.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
