[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Re: SSL VPNs and security
- To: Michal Zalewski <lcamtuf@xxxxxxxxxxxx>, bugtraq@xxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] Re: SSL VPNs and security
- From: <wnorth@xxxxxxxxxxx>
- Date: Thu, 08 Jun 2006 20:56:48 -0500 (CDT)
Very good information, we use F5 firepass products and I could see the same
issue inherinet in your statements. The benefits to the business, from a cost
perspective, are many, no need for tokens unless you are doing 2-factor auth,
which I encourage as it will check your personal PIN against your AD account to
ensure you are, who you say you are. Without 2-factor, it's a lost cause.
Thoughts?
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/