Archive for the ‘authentication’ Category

Translated version of the Japanese PhoneFactor article

Tuesday, May 22nd, 2007

Someone at my office had the bright idea of using Google to translate. Man, I work with some really bright people!

Translated article.

It’s neat.

Tuesday, May 22nd, 2007

Wow, what an amazing 24 hours! I’ve been doing everything from coding to PR to writing for the website to… well, you get the idea. PhoneFactor has caused quite a splash already at Interop, and we’ve been getting some really good press out of it.

One of my favorite quotes is this one, from an Infoworld article:

It’s neat. Instead of having users carry a smart token, Positive’s new PhoneFactor deal waits for an auth request (and not just using Positive’s VPN service; this works with any VPN platform). When it gets the request, it clicks back to a server managed by Positive that matches the user request with a supplied phone number. The phone number gets called and a keyed response is required to make sure you’re on your phone.

The most interesting coverage we got was actually from a Japanese site — interesting because I have no idea what it says! But, there’s a nice picture of Jason Sloderbeck and Chris Austin. Interop Las Vegas.

Jason and Chris at Interop

I’m tracking PhoneFactor publicity on my del.icio.us account here: http://del.icio.us/dispensa/PhoneFactor.

Anyway, I promise I’ll get this blog back to Windows soon, but at the moment, my head is full of PhoneFactor, so the blog is too!

UPDATE: Thanks to Karthik for pointing out my broken link.

PhoneFactor: Free two-factor authentication for everyone!

Monday, May 21st, 2007

After months of development and a couple of years of research and planning, I’m thrilled to announce that Positive Networks is readying its new two-factor authentication service, PhoneFactor, for launch this summer.

PhoneFactor is a phone-based two-factor authentication system. It works like this:

  1. A user enters her normal username and password and logs in
  2. Immediately, the system places a confirmation phone call to her pre-registered phone number
  3. The user answers and presses # to confirm the login

You’ll notice that there are a few distinct advantages to this system. Most obviously, users don’t have to carry around Yet Another Device. IT departments don’t have to manage Yet Another Device (mailing them out, RMAing them, doing token synch, yada yada yada). And because it’s just a phone call, it works on literally any TouchTone phone in the world - you don’t need a smartphone, a J2ME environment, or anything of the kind.

One of the biggest advantages of PhoneFactor, however, is that it’s free. From the first day it launches, Positive Networks will be making the PHoneFactor service available for free to everyone. More details are available at www.phonefactor.net, but the basic idea is that Positive is going to sign up to providing the standard PhoneFactor service for free, permanently. If you have a VPN product (including, of course, PositivePRO), or a public-facing web application, or a Citrix server, or virtually any other kind of networked application, you can add PhoneFactor two-factor authentication to it for free. Positive will even pick up the tab for the outbound phone calls, as long as they’re to domestic US phone numbers.

The PhoneFactor service is a legitimate free service, in the mode of GMail or Flickr. We plan on keeping it free permanently. It’s not crippleware, adware, shareware, or any other kind of badware. It’s not a trial, and it’s not time-limited. It’s simply a free service.

Now, we also have to pay to keep the lights on, so we’re planning on selling add-on modules to PhoneFactor that we think will deliver even more value than the standard service. We’re also going to provide our world-class administrative and end-user support services and our advanced integration service for a fee. More about the add-ons can be learned at www.phonefactor.net. It’s my honest belief that the standard PhoneFactor service will provide a lot of value to a great many organizations without the add-ons, and will probably be all that most organizations need. But, if you’re a Fortune 500 company considering an enterprise-wide deployment, some of these modules will probably be of great benefit to you.

You can probably tell I’m pretty excited about this. It’s not every day that you get to go out and solve a real problem with cool new software, and to top it all off, I get what every coder wants: the chance for my software to be widely used and appreciated.

The precise launch date isn’t fixed yet, but I expect to hear fireworks when we release it, if ya know what I mean. :-)

There is a ton of additional information over at www.phonefactor.net, including a particularly fine white paper by yours truly. You can also sign up for the mailing list to be notified when we release.

What I’ve been up to lately

Sunday, May 20th, 2007

I’ve been heads-down for the past six months focusing virtually all of my attention on two very special projects.

Tomorrow, Positive Networks will be announcing its newest service to the world: a two-factor authentication service for everyone. Readers of my blog will recognize by now that I’ve never been a fan of usernames and passwords, and I have long believed that the breaking point is near, when single-factor authentication simply won’t be practical any more.

I don’t want to jump the gun here, but I’m really excited about it - there are a couple of aspects of this service that are quite a bit different from what Positive has done in the past. Anyway, check back tomorrow for all of the details!

As for the second project, she’s been helping me code the first project for the last few weeks. If she keeps this up, I’ll have to add her to the credits. ;-)