<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>PistolStar's Authentication Blog</title>
	<atom:link href="http://blog.pistolstar.us/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://blog.pistolstar.us/blog</link>
	<description>Usability. Security. Auditing. Compliance.</description>
	<pubDate>Fri, 23 Mar 2012 13:25:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
	<language>en</language>
			<item>
		<title>Recent News: PortalGuard Presents Contextual Authentication at SecureWorld Expo in Boston</title>
		<link>http://blog.pistolstar.us/blog/?p=465</link>
		<comments>http://blog.pistolstar.us/blog/?p=465#comments</comments>
		<pubDate>Fri, 23 Mar 2012 13:25:00 +0000</pubDate>
		<dc:creator>Kimberly Johnson</dc:creator>
		
		<category><![CDATA[Authentication Trends]]></category>

		<category><![CDATA[General Information]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[secureworld expo]]></category>

		<category><![CDATA[appropriate authentication]]></category>

		<category><![CDATA[authentication experts]]></category>

		<category><![CDATA[contextual authentication]]></category>

		<category><![CDATA[gradual increase security]]></category>

		<category><![CDATA[Marketwire press release]]></category>

		<category><![CDATA[midpoint passwords two-factor]]></category>

		<category><![CDATA[SecureWorld Expo Boston]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=465</guid>
		<description><![CDATA[Just wanted to share PortalGuard&#8217;s recent press release regarding the presentation of contextual authentication, a midpoint between passwords and two-factor, at the SecureWorld Expo in Boston, March 28th - 29th.
The release discusses the opportunity attendees will have to talk with our authentication experts about how to apply the appropriate authentication method to each user, group [...]]]></description>
			<content:encoded><![CDATA[<p>Just wanted to share PortalGuard&#8217;s recent <a href="http://www.marketwire.com/press-release/portalguard-presents-contextual-authentication-midpoint-between-passwords-two-factor-1634543.htm" target="_blank">press release</a> regarding the presentation of contextual authentication, a midpoint between passwords and two-factor, at the <a href="http://secureworldexpo.com/event/index.php/2012-boston-home" target="_blank">SecureWorld Expo in Boston</a>, March 28th - 29th.</p>
<p>The release discusses the opportunity attendees will have to talk with our authentication experts about how to apply the <a href="http://www.portalguard.com" target="_blank">appropriate authentication method to each user, group or application</a>.</p>
<p>Read the <a href="http://www.marketwire.com/press-release/portalguard-presents-contextual-authentication-midpoint-between-passwords-two-factor-1634543.htm" target="_blank">press release now on MarketWire</a> to learn more about having the flexibility to take a gradual approach to increasing security.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=465</wfw:commentRss>
		</item>
		<item>
		<title>Authentication is Evolving with PortalGuard Now on SearchSecurity.com</title>
		<link>http://blog.pistolstar.us/blog/?p=456</link>
		<comments>http://blog.pistolstar.us/blog/?p=456#comments</comments>
		<pubDate>Fri, 16 Mar 2012 20:26:18 +0000</pubDate>
		<dc:creator>Chief Content Writer</dc:creator>
		
		<category><![CDATA[Authentication Security]]></category>

		<category><![CDATA[Authentication Trends]]></category>

		<category><![CDATA[General Information]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[application and platform security]]></category>

		<category><![CDATA[appropriate authentication]]></category>

		<category><![CDATA[authentication platform]]></category>

		<category><![CDATA[authentication video]]></category>

		<category><![CDATA[authentication white paper]]></category>

		<category><![CDATA[enterprise identity access management]]></category>

		<category><![CDATA[flexible authentication]]></category>

		<category><![CDATA[real world security]]></category>

		<category><![CDATA[risk-based authentication]]></category>

		<category><![CDATA[searchsecurity.com]]></category>

		<category><![CDATA[white paper]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=456</guid>
		<description><![CDATA[ Now On 
Authentication is evolving. There&#8217;s a better way to authenticate. Be confident in who accesses your web applications.
You can now find this slogan on SearchSecurity.com, along with multiple media offerings from PortalGuard. PortalGuard is sponsoring both Security Topics, Application and Platform Security and Enterprise Identity and Access Management. Presenting a new flexible approach to authentication, the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.portalguard.com"><img class="alignnone size-thumbnail wp-image-458" title="outlook_portalguard-logo" src="http://blog.pistolstar.us/blog/wp-content/uploads/2012/03/outlook_portalguard-logo.jpg" alt="PortalGuard: Risk-based Authentication Platform" width="241" height="31" /></a> <em><strong>Now On </strong></em><a href="http://searchsecurity.techtarget.com/resources/Enterprise-Identity-and-Access-Management"><img class="size-medium wp-image-459 alignnone" title="searchsecurity_logo" src="http://blog.pistolstar.us/blog/wp-content/uploads/2012/03/searchsecurity_logo.jpg" alt="PortalGuard Now On SearchSecurity.com" width="138" height="30" /></a></p>
<p><strong>Authentication is evolving. There&#8217;s a better way to authenticate. Be confident in who accesses your web applications.</strong></p>
<p>You can now find this slogan on SearchSecurity.com, along with multiple media offerings from PortalGuard. PortalGuard is sponsoring both Security Topics, <a href="http://searchsecurity.techtarget.com/resources/Application-and-Platform-Security" target="_blank">Application and Platform Security</a> and <a href="http://searchsecurity.techtarget.com/resources/Enterprise-Identity-and-Access-Management" target="_blank">Enterprise Identity and Access Management</a>. Presenting a new flexible approach to authentication, the informative drop down video discusses how risk-based authentication is the next step in the evolution of authentication, and asks you, what&#8217;s your authentication situation?</p>
<p>Take a moment to check it out, and while you&#8217;re there request your copy of the exclusive whitepaper: &#8220;Real World Security with Risk-based Authentication&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=456</wfw:commentRss>
		</item>
		<item>
		<title>New White Paper on SearchSecurity.com</title>
		<link>http://blog.pistolstar.us/blog/?p=454</link>
		<comments>http://blog.pistolstar.us/blog/?p=454#comments</comments>
		<pubDate>Mon, 05 Dec 2011 15:33:21 +0000</pubDate>
		<dc:creator>Chief Content Writer</dc:creator>
		
		<category><![CDATA[Authentication Trends]]></category>

		<category><![CDATA[General Information]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[real world security]]></category>

		<category><![CDATA[risk-based authentication]]></category>

		<category><![CDATA[searchsecurity.com]]></category>

		<category><![CDATA[white paper]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=454</guid>
		<description><![CDATA[We recently released a new white paper, in conjunction with Osterman Research, titled &#8220;Real World Security with Risk-based Authentication&#8221;. This can be found here, on SearchSecurity.com.
The white paper address the challenge organizations face with being able to protect their  resources with appropriate authentication capabilities while at the  same time making access as easy [...]]]></description>
			<content:encoded><![CDATA[<p>We recently released a new <a href="http://searchsecurity.bitpipe.com/detail/RES/1318878280_482.html" target="_blank">white paper</a>, in conjunction with Osterman Research, titled <a href="http://searchsecurity.bitpipe.com/detail/RES/1318878280_482.html" target="_blank">&#8220;Real World Security with Risk-based Authentication&#8221;</a>. This can be found here, on <a href="http://searchsecurity.com" target="_blank">SearchSecurity.com</a>.</p>
<p>The <a href="http://searchsecurity.bitpipe.com/detail/RES/1318878280_482.html" target="_blank">white paper</a> address the challenge organizations face with being able to protect their  resources with appropriate authentication capabilities while at the  same time making access as easy as possible for users. In order to  achieve this, decision makers must focus on “real world security”,  namely, matching the level of authentication required to gain access to a  particular application with the risk associated with accessing it.</p>
<p>This <a href="http://searchsecurity.bitpipe.com/detail/RES/1318878280_482.html" target="_blank">white paper</a> examines the various methods of authentication in use today. View now to explore:</p>
<ul>
<li>Benefits of risk-based authentication</li>
<li>High-level recommendations about how to improve password management capabilities</li>
<li>A brief overview of PortalGuard</li>
<li>And more</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=454</wfw:commentRss>
		</item>
		<item>
		<title>PortalGuard Visits Hartford: DataConnectors Tech-Security Conference</title>
		<link>http://blog.pistolstar.us/blog/?p=449</link>
		<comments>http://blog.pistolstar.us/blog/?p=449#comments</comments>
		<pubDate>Wed, 29 Jun 2011 19:01:41 +0000</pubDate>
		<dc:creator>Chief Content Writer</dc:creator>
		
		<category><![CDATA[DataConnectors]]></category>

		<category><![CDATA[General Information]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[risk-based authentication]]></category>

		<category><![CDATA[trade shows]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=449</guid>
		<description><![CDATA[
If you are in the Hartford area, PortalGuard would like to encourage you to stop by the DataConnectors Hartford Tech-Security Conference, located in Cromwell CT.
The PortalGuard team will be there to discuss the PortalGuard Risk-based Authentication Platform as well as all supporting functionality. Feel free to stop by the table and ask authentication questions that [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.pistolstar.us/blog/wp-content/uploads/2011/06/hartford_2011.jpg"><img class="alignnone size-full wp-image-450" style="border: 0pt none;" title="hartford_2011" src="http://blog.pistolstar.us/blog/wp-content/uploads/2011/06/hartford_2011.jpg" alt="" width="500" height="61" /></a></p>
<p>If you are in the Hartford area, PortalGuard would like to encourage you to stop by the DataConnectors Hartford Tech-Security Conference, located in Cromwell CT.</p>
<p>The PortalGuard team will be there to discuss the PortalGuard Risk-based Authentication Platform as well as all supporting functionality. Feel free to stop by the table and ask authentication questions that may have been unanswered in the past, regarding:</p>
<p>- Self-service Password Reset: including Offline Recovery</p>
<p>- SSO: seamless access to web, desktop and mobile applications</p>
<p>- Password Compliance: add to your web applications - even SQL web apps</p>
<p>- Authentication Methods: configurable by user, group or application</p>
<p>Please <a href="http://www.dataconnectors.com/events/2011/07Hartford/agenda.asp" target="_blank">Click Here</a> for a the conference information and agenda. If you are looking for further conference information please contact Dawn Morrissey at 314-525-7140.</p>
<p>We hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=449</wfw:commentRss>
		</item>
		<item>
		<title>PortalGuard Declares Success at SecureWorld Expo 2011 - Philadelphia</title>
		<link>http://blog.pistolstar.us/blog/?p=442</link>
		<comments>http://blog.pistolstar.us/blog/?p=442#comments</comments>
		<pubDate>Thu, 19 May 2011 14:00:49 +0000</pubDate>
		<dc:creator>Chief Content Writer</dc:creator>
		
		<category><![CDATA[General Information]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[secureworld expo]]></category>

		<category><![CDATA[Dash for Prizes]]></category>

		<category><![CDATA[risk-based authentication]]></category>

		<category><![CDATA[static authentication]]></category>

		<category><![CDATA[trade show success]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=442</guid>
		<description><![CDATA[We have come back from last week&#8217;s SecureWorld Expo 2011 in Philadelphia with enthusiasm. PortalGuard, stationed at booth #109, was successful in discussing Risk-based Authentication with attendees and displaying the benefits of moving away from Static Authentication. Attendees stopping by the booth were posed with interesting technical questions and most were on a fact finding [...]]]></description>
			<content:encoded><![CDATA[<p>We have come back from last week&#8217;s SecureWorld Expo 2011 in Philadelphia with enthusiasm. PortalGuard, stationed at booth #109, was successful in discussing Risk-based Authentication with attendees and displaying the benefits of moving away from Static Authentication. Attendees stopping by the booth were posed with interesting technical questions and most were on a fact finding mission to establish the upcoming trends in enterprise authentication.</p>
<p>On Thursday, PortalGuard participated in the Dash for Prizes contest, which encouraged attendees to drop a business card at the booth to enter the drawing. In the end PortalGuard gave out a Cisco Flip Digital Camcorder as well as Amazon Gift Cards and snooze buttons.</p>
<p>Continuing to attend shows around the U.S., the next stop for PortalGuard will be in the fall. Please check <a title="PortalGuard - Usability &amp; Security" href="http://www.portalguard.com" target="_blank">www.PortalGuard.com</a> for upcoming events and news.</p>
<div id="attachment_443" class="wp-caption alignnone" style="width: 310px"><a href="http://blog.pistolstar.us/blog/wp-content/uploads/2011/05/sml_bckage.jpg"><img class="size-medium wp-image-443" title="SecureWorld Expo 2011 - Philly - Booth" src="http://blog.pistolstar.us/blog/wp-content/uploads/2011/05/sml_bckage-300x225.jpg" alt="Mark Cochran, VP of Global Sales, and Kimberly Johnson, Marketing Director, staff the booth" width="300" height="225" /></a><p class="wp-caption-text">Mark Cochran, VP of Global Sales, and Kimberly Johnson, Marketing Director, staff the booth</p></div>
<div id="attachment_444" class="wp-caption alignnone" style="width: 310px"><a href="http://blog.pistolstar.us/blog/wp-content/uploads/2011/05/sml_flip_winner.jpg"><img class="size-medium wp-image-444" title="Dash for Prizes - Flip Winner" src="http://blog.pistolstar.us/blog/wp-content/uploads/2011/05/sml_flip_winner-300x225.jpg" alt="Kimberly congratulates PortalGuard's first Dash for Prizes winner" width="300" height="225" /></a><p class="wp-caption-text">Kimberly congratulates PortalGuard&#39;s first Dash for Prizes winner</p></div>
<div id="attachment_445" class="wp-caption alignnone" style="width: 310px"><a href="http://blog.pistolstar.us/blog/wp-content/uploads/2011/05/sml_amazon_winner.jpg"><img class="size-medium wp-image-445" title="Dash for Prizes - Amazon Card Winner" src="http://blog.pistolstar.us/blog/wp-content/uploads/2011/05/sml_amazon_winner-300x225.jpg" alt="Kimberly congratulates PortalGuard's second Dash for Prizes winner" width="300" height="225" /></a><p class="wp-caption-text">Kimberly congratulates PortalGuard&#39;s second Dash for Prizes winner</p></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=442</wfw:commentRss>
		</item>
		<item>
		<title>PortalGuard Brings Risk-based Authentication to the SecureWorld Expo</title>
		<link>http://blog.pistolstar.us/blog/?p=438</link>
		<comments>http://blog.pistolstar.us/blog/?p=438#comments</comments>
		<pubDate>Thu, 05 May 2011 19:53:01 +0000</pubDate>
		<dc:creator>Chief Content Writer</dc:creator>
		
		<category><![CDATA[General Information]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[risk-based authentication]]></category>

		<category><![CDATA[secureworld expo]]></category>

		<category><![CDATA[tailored authentication]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=438</guid>
		<description><![CDATA[
Philadelphia 2011, May 11th &#38; 12th
Come stop by booth #109 to learn more about:
PortalGuard:
The PortalGuard software is a Risk-based Authentication Platform which is focused on enhancing usability, while maintaining a balance between security, auditing and compliance for your enterprise web, desktop and mobile applications. Developed and supported by authentication experts, PortalGuard is easy to deploy, [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.secureworldexpo.com/events/index.php?id=295" target="_blank"><img class="size-medium wp-image-437 aligncenter" title="show_banner" src="http://blog.pistolstar.us/blog/wp-content/uploads/2011/05/show_banner.jpg" border="0" alt="" width="190" height="43" /></a></p>
<p style="text-align: center;"><strong>Philadelphia 2011, May 11th &amp; 12th</strong></p>
<p>Come stop by booth #109 to learn more about:</p>
<p><strong>PortalGuard:</strong></p>
<p>The PortalGuard software is a Risk-based Authentication Platform which is focused on enhancing usability, while maintaining a balance between security, auditing and compliance for your enterprise web, desktop and mobile applications. Developed and supported by authentication experts, PortalGuard is easy to deploy, enterprise ready and Tailored for an exact fit to your requirements.</p>
<p><strong>Tailored Authentication:</strong></p>
<p>For a unique environment and/or situation, which requires specific functionality, our team would make the necessary adaptations to meet or exceed your security objectives, and provide a fully supported product.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=438</wfw:commentRss>
		</item>
		<item>
		<title>PortalGuard Attends Recent Industry Events</title>
		<link>http://blog.pistolstar.us/blog/?p=428</link>
		<comments>http://blog.pistolstar.us/blog/?p=428#comments</comments>
		<pubDate>Tue, 22 Mar 2011 21:32:52 +0000</pubDate>
		<dc:creator>Kimberly Johnson</dc:creator>
		
		<category><![CDATA[General Information]]></category>

		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=428</guid>
		<description><![CDATA[PortalGuard has been traveling the states attending leading industry events and educating attendees on self-service authentication, one-time passwords via a mobile device, multi-factor authentication and how to maintain usability for the end-user. With a focus on the enterprise PortalGuard offers a configurable, easy to deploy login system plug-in for the desktop, mobile or browser.
The next [...]]]></description>
			<content:encoded><![CDATA[<p>PortalGuard has been traveling the states attending leading industry events and educating attendees on self-service authentication, one-time passwords via a mobile device, multi-factor authentication and how to maintain usability for the end-user. With a focus on the enterprise PortalGuard offers a configurable, easy to deploy login system plug-in for the desktop, mobile or browser.</p>
<p><strong>The next stop for PortalGuard is:</strong></p>
<p><a href="http://www.misti.com/default.asp?page=65&amp;Return=70&amp;ProductID=5539&amp;LS=infosecworld" target="_blank"><img class="alignnone size-medium wp-image-431" title="infosec_2011_banner" src="http://blog.pistolstar.us/blog/wp-content/uploads/2011/03/infosec_2011_banner.jpg" border="0" alt="" width="208" height="58" /></a> Booth #614, Orlando FL, April 19th &amp; 20th<a href="http://blog.pistolstar.us/blog/wp-content/uploads/2011/03/infosec_2011_banner.jpg"><br />
</a></p>
<p><strong>Recently Attended Events:</strong></p>
<p><a href="http://www.portalguard.com/rsa11" target="_blank"><img class="alignnone size-medium wp-image-430" title="rsa2011-logo-stack-gray" src="http://blog.pistolstar.us/blog/wp-content/uploads/2011/03/rsa2011-logo-stack-gray-300x133.jpg" border="0" alt="" width="143" height="63" /></a> San Francisco CA, February 14th - 18th</p>
<p><a href="http://www.pistolstar.com/ls11" target="_blank"><img class="alignnone size-medium wp-image-429" title="ls11_logo_dots_000" src="http://blog.pistolstar.us/blog/wp-content/uploads/2011/03/ls11_logo_dots_000.jpg" border="0" alt="" width="201" height="58" /></a> Orlando FL , January 30th - February 3rd</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=428</wfw:commentRss>
		</item>
		<item>
		<title>What&#8217;s Your Password History?</title>
		<link>http://blog.pistolstar.us/blog/?p=413</link>
		<comments>http://blog.pistolstar.us/blog/?p=413#comments</comments>
		<pubDate>Wed, 20 Oct 2010 14:29:24 +0000</pubDate>
		<dc:creator>Chief Content Writer</dc:creator>
		
		<category><![CDATA[Authentication Security]]></category>

		<category><![CDATA[Authentication Trends]]></category>

		<category><![CDATA[Data Security]]></category>

		<category><![CDATA[IT Security]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[end-user frustration]]></category>

		<category><![CDATA[pass phrase]]></category>

		<category><![CDATA[password expiration policies]]></category>

		<category><![CDATA[password history]]></category>

		<category><![CDATA[password history policies]]></category>

		<category><![CDATA[password management]]></category>

		<category><![CDATA[password policies]]></category>

		<category><![CDATA[required level of data protection]]></category>

		<category><![CDATA[reset forgotten password]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[usability]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=413</guid>
		<description><![CDATA[What’s your password history? This is a question many end users are not able to answer causing increased frustration. Of course password history is extremely important as it prevents the user from reusing a password which could have potentially been compromised in the past.
One of the biggest challenges with implementing password history policies is being [...]]]></description>
			<content:encoded><![CDATA[<p>What’s your <a title="PortalGuard - Password History Feature" href="http://www.portalguard.com" target="_blank">password history</a>? This is a question many end users are not able to answer causing increased frustration. Of course password history is extremely important as it prevents the user from reusing a password which could have potentially been compromised in the past.</p>
<p>One of the biggest challenges with implementing password history policies is being able to maintain usability while increasing compliance and security. By limiting the user to only using passwords that are new to them each time, the user becomes frustrated every time they are required to reset their password. Unfortunately with limits being enforced, the frustrated user is more likely to write down passwords. <img class="size-medium wp-image-414 alignright" title="post-it" src="http://blog.pistolstar.us/blog/wp-content/uploads/2010/10/post-it.gif" alt="" width="192" height="125" /><img src="file:///C:/DOCUME%7E1/kjohnson/LOCALS%7E1/Temp/moz-screenshot.png" alt="" /><img src="file:///C:/DOCUME%7E1/kjohnson/LOCALS%7E1/Temp/moz-screenshot-1.png" alt="" />If you are thinking of implementing a password history policy it is better to <a title="PistolStar tailored authentication" href="http://www.pistolstar.com" target="_blank">tailor </a>it to your environment and only make it a requirement when it makes sense in relation to the required level of data protection.</p>
<p>Some key things to remember surrounding password history is that it has an inverse relationship to your <a title="Password Expiration Policies" href="http://www.portalguard.com/features/password-expiration-policy.html" target="_blank">password expiration policies</a>. So if you are expiring passwords frequently then you would need a higher password history limit. For example, if you expire passwords as frequently as every 30 days you would want a high password history limit, say around 50. This would not allow the reusing of any passwords for 1500 days. It is important to remember what is necessary for the type of data you are trying to protect.</p>
<p>The other concern is how to help your users create passwords and not get frustrated with having to remember brand new ones. Many times a user will create a password and continually use variations of the same password (ex.  password, password1, password2, password3, etc.). Something to take into consideration may be the limiting of similar passwords as it may be crucial to your security.</p>
<p>To help users with all of these issues the option you could give them is to <a title="PortalGuard - pass phrase functionality" href="http://www.portalguard.com" target="_blank">use a pass phrase</a>. Instead of a single “X” length of characters you could allow them to login with an entire sentence. This might be easier for some users to remember and therefore reset their pass phrase when needed.</p>
<p>Overall the goal is to decrease user frustrations while still implementing effective password history policies. Make sure to consider what level of data protection is required and what is necessary in terms of the limits you are setting for your end users.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=413</wfw:commentRss>
		</item>
		<item>
		<title>Stronger Passwords Weighing In</title>
		<link>http://blog.pistolstar.us/blog/?p=409</link>
		<comments>http://blog.pistolstar.us/blog/?p=409#comments</comments>
		<pubDate>Wed, 13 Oct 2010 02:56:30 +0000</pubDate>
		<dc:creator>Chief Content Writer</dc:creator>
		
		<category><![CDATA[Authentication Security]]></category>

		<category><![CDATA[Authentication Trends]]></category>

		<category><![CDATA[Data Security]]></category>

		<category><![CDATA[General Information]]></category>

		<category><![CDATA[IT Security]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[Security Attacks]]></category>

		<category><![CDATA[password security]]></category>

		<category><![CDATA[content security]]></category>

		<category><![CDATA[data protection]]></category>

		<category><![CDATA[employee security awareness]]></category>

		<category><![CDATA[password management]]></category>

		<category><![CDATA[password policies]]></category>

		<category><![CDATA[password strength]]></category>

		<category><![CDATA[password strength meter]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[usability]]></category>

		<category><![CDATA[weak passwords]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=409</guid>
		<description><![CDATA[One of the pains in an employee’s daily routines is the idea of password management. Especially being able to easily understand what the IT Security Staff means by using a “strong” password. In a recent CNN.com article they stressed the importance of implementing “super passwords” suggesting that passwords should all be a minimum of 12 [...]]]></description>
			<content:encoded><![CDATA[<p>One of the pains in an employee’s daily routines is the idea of <a title="Password Strength" href="http://www.portalguard.com/features/password-complexity-policy.html" target="_blank">password management</a>. Especially being able to easily understand what the IT Security Staff means by using a “strong” password. In a recent <a title="CNN.com Article" href="http://www.cnn.com/2010/TECH/innovation/08/20/super.passwords/index.html?hpt=Sbin" target="_blank">CNN.com</a> article they stressed the importance of implementing “super passwords” suggesting that passwords should all be a minimum of <a title="Password Strength" href="http://www.portalguard.com/features/password-complexity-policy.html" target="_blank">12 characters in length</a>. If these types of standards are going to become the norm, due to the varying types of attacks being performed, than the usability of passwords for the user will decrease.</p>
<p>By implementing a simple <a title="PortalGuard Home" href="http://portalguard.com" target="_blank">Password Strength Meter</a>, your employees can easily have visual feedback as to whether or not they are following password policies and avoiding weak passwords. This will also make password strengths easy to enforce for varying levels of required data protection.</p>
<p>With the <a title="PortalGuard Home" href="http://portalguard.com/" target="_blank">Password Strength Meter provided by PortalGuard</a> the user has a real time response to their choice of characters for their new password. With each character that is typed in the meter will show the user whether their password is becoming weaker or stronger. The administrators can implement this on every login page or only on those protecting critical data. The idea is that <a title="PortalGuard Home" href="http://portalguard.com/" target="_blank">Password Strength Meters</a> are going to aid the user in implementing stronger passwords while maintaining usability.</p>
<p><a title="CNN.com Article" href="http://www.cnn.com/2010/TECH/innovation/08/20/super.passwords/index.html?hpt=Sbin" target="_blank">CNN.com Super Passwords Article</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=409</wfw:commentRss>
		</item>
		<item>
		<title>HTTP Uh-oh! Look at the URL</title>
		<link>http://blog.pistolstar.us/blog/?p=400</link>
		<comments>http://blog.pistolstar.us/blog/?p=400#comments</comments>
		<pubDate>Tue, 28 Sep 2010 13:28:18 +0000</pubDate>
		<dc:creator>Chief Content Writer</dc:creator>
		
		<category><![CDATA[Authentication Security]]></category>

		<category><![CDATA[Authentication Trends]]></category>

		<category><![CDATA[General Information]]></category>

		<category><![CDATA[IT Security]]></category>

		<category><![CDATA[PortalGuard]]></category>

		<category><![CDATA[Security Attacks]]></category>

		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[authentication best practices]]></category>

		<category><![CDATA[employee security]]></category>

		<category><![CDATA[HTTPS]]></category>

		<category><![CDATA[security awareness]]></category>

		<category><![CDATA[security tips]]></category>

		<category><![CDATA[URL tips]]></category>

		<guid isPermaLink="false">http://blog.pistolstar.us/blog/?p=400</guid>
		<description><![CDATA[When it comes to security awareness it is key to provide your employees with quick tips to use throughout their daily routine to help them be more security aware. One of the first that is easy to implement and have employees get in the habit of is taking a look at the URL before they [...]]]></description>
			<content:encoded><![CDATA[<p>When it comes to security awareness it is key to provide your employees with quick tips to use throughout their daily routine to help them be more security aware. One of the first that is easy to implement and have employees get in the habit of is taking a look at the URL before they type in credentials.</p>
<p>Many times there are misleading URLs and false websites created for the sole purpose of tricking your end-users and stealing their credentials. To an untrained eye it is easy to be fooled.</p>
<p><a href="http://blog.pistolstar.us/blog/wp-content/uploads/2010/09/clip_image0021.jpg"><img class="alignnone size-medium wp-image-402" title="clip_image0021" src="http://blog.pistolstar.us/blog/wp-content/uploads/2010/09/clip_image0021-300x176.jpg" alt="" width="300" height="176" /></a>(Click Photo to Enlarge)</p>
<p>So the tip to give employees is to make sure to look for HTTPS in any URL where they are entering in credentials or accessing sensitive data. HTTP Secure (HTTPS) layers Hypertext Transfer Protocol on an encrypted SSL/TLS to ensure that information sent to the server is secure. This differs from the basic HTTP URLs which are not secure or encrypted and are subject to “man-in-the-middle” and “eavesdropping” attacks.</p>
<p>By users getting in the habit of looking for the more secure HTTPS you are more likely to prevent them from distributing valuable data over the network. This is a very strong method used best for financial transactions and internal portals.</p>
<p>Learn More:<br />
<a href="http://www.portalguard.com" target="_blank">PortalGuard – secure authentication</a><br />
<a href="http://en.wikipedia.org/wiki/HTTP_Secure" target="_blank">Wikipedia - explanation of HTTPS</a><br />
<a href="http://www.informatics.indiana.edu/markus/documents/security-education.pdf" target="_blank">Image Source: http://www.informatics.indiana.edu/markus/documents/security-education.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.pistolstar.us/blog/?feed=rss2&amp;p=400</wfw:commentRss>
		</item>
	</channel>
</rss>

