HOME     MENU     SEARCH     NEWSLETTER    
THE ENTERPRISE SECURITY SUPERSITE. UPDATED 4 MINUTES AGO.
You are here: Home / Data Security / MS Buys Authenticator PhoneFactor
Microsoft Buys Multi-Factor Authenticator PhoneFactor
Microsoft Buys Multi-Factor Authenticator PhoneFactor
By Barry Levine / Enterprise Security Today Like this on Facebook Tweet this Link thison Linkedin Link this on Google Plus
PUBLISHED:
OCTOBER
04
2012


Microsoft has acquired multi-factor authentication provider PhoneFactor, the two companies announced Thursday. Terms were not disclosed.

Microsoft said in a statement that the acquisition will help to "enhance the security of almost any authentication scenario." PhoneFactor said it is the leading provider of phone-based, two-factor authentication solutions, and that its authentication is used in government, healthcare, enterprise, banking, and Web site applications.

Out-of-Band Methods

PhoneFactor, founded in 2001, is used by hundreds of organizations to secure logins and transactions. Its solutions already work with a variety of Microsoft products and services, such as Outlook Web Access or Internet Information Services, and it interoperates with Active Directory.

The company's authentication platform can be used either in a hosted or on-premise fashion, and it offers centralized user management, automated enrollment, user self-service and reporting. PhoneFactor said it would continue to provide support for its services, and that new customers would still be able to purchase PhoneFactor products directly from the company.

Multi-factor authentication systems have great potential, because they decrease the emphasis on coming up with a hard-to-guess password and require that the user have a physical device on hand. With such systems, users enter two or more supporting forms of identification to access a secure area or conduct a transaction.

PhoneFactor's phone-based multi-factor authentication methods use existing phones. It incorporates out-of-band methods, which means two separate channels are used to deliver the logon information, such as a phone call or a text message in conjunction with a typical user name and password combination. It also offers an OATH passcode option.

Third-Channel Option

With the company's system, for instance, a person enters a user name and password. Immediately, PhoneFactor calls the user, and the user simply answers the call and presses the # key. Instead of a phone call, PhoneFactor could send the user a text message with a logon- or transaction-specific passcode, which the user then enters.

Another alternative is that a notification is "pushed" to the PhoneFactor App on the user's smartphone or tablet, and the user clicks the "authenticate" button to complete.

PhoneFactor can also utilize a third factor, through a third channel, such as speaking a short passphrase during the authentication call. The spoken passphrase is then authenticated through a voiceprint.

The idea is that a hacker would need to know the user name and password, physically have the phone, and know the second- or third-channel confidential information. In the case of a voiceprint, of course, the hacker would be out of luck -- except in movies, when the victim's voice has been prerecorded.

The company's multi-factor authentication could also involve the generation of an OATH passcode, which is entered during login. An OATH passcode is generated by an open source algorithm, creating an unique passcode each time. The OATH option was added to PhoneFactor's portfolio in July, and can use either PhoneFactor's app or one from a third party to generate the passcode.

Tell Us What You Think
Comment:

Name:

Like Us on FacebookFollow Us on Twitter
TOP STORIES NOW
MAY INTEREST YOU
High Quality CRM Data: Prevent, detect and fix errors at the point of data entry for Dynamics CRM. Trillium Software helps you achieve an accurate, synchronized, single view of customers. It's time to trust your data. Take a product tour and read CRM Analyst opinions here.
MORE IN DATA SECURITY
Product Information and Resources for Technology You Can Use To Boost Your Business

NETWORK SECURITY SPOTLIGHT
Using Internet-connected devices without strong passwords is inherently risky, as illustrated by reports that a Russian Web site is showing live footage from thousands of people's webcams.

ENTERPRISE HARDWARE SPOTLIGHT
Doctor Who had K-9, the robot dog that accompanied him on adventures through space. Now, Mountain View has K5, a 5-foot-tall, 300-pound robot security guard patrolling in the Bay Area.

MOBILE TECHNOLOGY SPOTLIGHT
To better its customer service, Comcast is pulling out at least some of the stops. The cable giant has launched an app so you can track the cable guy in real time. It's designed to ease customer frustration.

© Copyright 2014 NewsFactor Network, Inc. All rights reserved. Member of Accuserve Ad Network.