<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:s="http://www.techrepublic.com/search" xmlns:dc="http://purl.org/dc/elements/1.1/"  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
    <title><![CDATA[Discussion on Hacker or user? How to tell friend from foe ]]></title>
    <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-396043]]></link>
    <atom:link rel="hub" type="application/rss+xml" href="http://pubsubhubbub.appspot.com/" />
    <atom:link rel="self" type="application/rss+xml" href="http://www.techrepublic.com/forum/discussions/102-396043/rss" />

    <description><![CDATA[]]></description>
    <language>en-us</language>
    <lastBuildDate>2013-05-24T14:49:41-07:00</lastBuildDate>
             

    <item>
        <title><![CDATA[So if the Hacker hacks the SSO system.....]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-396043-3715194]]></link>
        <description><![CDATA[The article headline asks how to tell hacker vs. user but does not answer the question.  How does SSO do that?It would be good to mention when the author of the article works for one of the companies mentioned in the article.To simultaneously talk about remote access, web site authentication, cloud, and enterprise SSO in one breath is terribly confusing.  You don't use SSO for enterprise remote access (it's SSO by definition), you don't expose your SSO and AD to your web apps, and most enterprise security people are not likely to extend their authentication services out through their firewall to their business partners.Now if you're talking Cloud and SaaS, that's a whole different story. But in this case the whole app is 'outside the secruity perimeter' so putting the authentication out there is only logical.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-396043-3715194]]></guid>
        <dc:creator><![CDATA[robo_dev]]></dc:creator>
        <pubDate>Thu, 15 Nov 2012 09:55:34 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[OneLogIn - One more to put in the melting pot]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-396043-3715141]]></link>
        <description><![CDATA[To me SaaS represents one of the biggest challenges to IT in terms of general management and control. In the old days if a department wanted an app they came to IT who deployed it and monitored it and managed it. Now any department can buy any SaaS app and put any data they want up there without having the processes to provision and importantly deprovision users. Its the wild west out there. If I might be so bold - OneLogin is certainly worth looking at and adds to the level of security by including free 2FA.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-396043-3715141]]></guid>
        <dc:creator><![CDATA[readingman]]></dc:creator>
        <pubDate>Thu, 15 Nov 2012 06:20:11 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Identity isn't enough]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-396043-3712623]]></link>
        <description><![CDATA[Identity awareness can only help you so far, as long as se still use the dated model that any code running within a logged-on session acts as intended by the human user.UAC is a baby-step towards fixing that, but it's still a huge problem, especially where the connected device is outside IT management's control.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-396043-3712623]]></guid>
        <dc:creator><![CDATA[cquirke]]></dc:creator>
        <pubDate>Fri, 02 Nov 2012 20:37:41 -0700</pubDate>
    </item>
    </channel>
</rss>

