Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
MrMoo
Sep 14, 2000

Simple, that requires state and adds complexity to the code.

Adbot
ADBOT LOVES YOU

MrMoo
Sep 14, 2000

PBS posted:

Let me explain a little further.

The goal is to log into X website, the website login page has two fields. One field is UserID, the other is Passcode.

The passcode itself is something you generate. You generate the passcode by entering your PIN into an RSA SecureID token client, either on a phone or computer.

So if your PIN is 123456, you input this into the SecureID token client and it will spit out something like 01923227.

Go back to the webpage, enter userid in userid field, enter 01923227 in the passcode field, hit login.

There is a pretty awful Cisco appliance that has a SSL portal that works like this.

MrMoo
Sep 14, 2000

DeaconBlues posted:

Is Norton/Symantec actually widely used in Linux land?

I would guess many email and web security gateways are affected, from Barracuda through to Untangle.

MrMoo
Sep 14, 2000

Mainland Chinese business strategy with outside nations appears to be: literally say anything that works to win the conversation and by the power of face ignore the consequences. It's quite uncanny.

MrMoo
Sep 14, 2000

Excuses but they at least did prepare a little bit:

https://www.yubico.com/2016/07/yubikey-route-usb-c/

Adbot
ADBOT LOVES YOU

MrMoo
Sep 14, 2000

Is there a list of vendors like https://drata.com for infosec compliance type stuff? There is a clear benefit to having a single portal manage all infosec poo poo, but one needs competition and ability to integrate bespoke stacks. Always fun when vendors don't list pricing.

All these trying to show their head with the OpenSSL 3.0.7 patch.

MrMoo fucked around with this message at 17:02 on Oct 26, 2022

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply