A Review of the Best News of the Week on Identity Mgt & Web Fraud

Best practices for passwords updated after original author regrets his advice (The Verge, Aug 14 2017)
A vast majority of the trusted tips and tricks we employ when crafting a custom password actually make us more vulnerable to hackers, according to the expert who popularized the tips back in 2003. The original WSJ article has the best headline: “The Man Who Wrote Those Password Rules Has a New Tip: N3v$r M1^d!”

Why NIST’s Bill Burr shouldn’t regret his 2003 password advice (Naked Security – Sophos, Aug 11 2017)
We’ve learned a lot about passwords since 2003 – not least that you need more than even the best-crafted password to keep data safe…

Dropbox introduces mobile prompts for two-step verification (Dropbox Blog, Aug 11 2017)
Mobile prompts are especially helpful as a backup when you don’t have cell signal, but do have Wi-Fi (for example, on a plane where you can’t receive security codes by text message)…


Sponsored by LogRhythm
SIEM Magic Quadrant
Gartner Positions LogRhythm in SIEM Leaders Quadrant for 5th Consecutive Year. Get the report


Dashlane’s 2017 Password Power Rankings: How Consumer & Enterprise Websites Handle User Security (Dashlane Blog, Aug 14 2017)
They examined the password policies of 40 popular consumer & enterprise websites and provide a quick view of which companies have 2FA, various password mechanisms, and logins that aren’t brute-forceable…

Centrify hits US$100M milestone in annual sales (Centrify Blog, Aug 15 2017)
Centrify hit a major milestone of more than $100M in sales in FY17, with sixty percent of those coming through the channel…

Figuring out multifactor authentication (FCW, Aug 15 2017)
With NIST now restricting the use of Short Message Service, what are the authentication options for federal agencies?

WatchGuard Technologies Acquires Datablink and Adds Advanced Authentication to SMB Security Portfolio (WatchGuard, Aug 15 2017)
This acquisition extends WatchGuard’s security portfolio beyond network and wireless security, enabling the company to deliver advanced authentication to small to midsize businesses (SMB) and distributed enterprises…

Cyber attacks on online retailers double in a year as hackers try to steal shoppers’ details (The Telegraph, Aug 16 2017)
The numbers of online shops hit by serious losses of customer data has doubled in the past year as hackers try to plunder retails sites for valuable personal details, a law firm has warned…