Web security product aims to foil hackers with continuous authentication

News
Jun 26, 20073 mins

2factor checks out, encrypts every data transmission in real time

A new Web application security product prevents hacker attacks with 256-bit secret keys that authenticate and encrypt each data transmission as it happens.

SecureWeb, a product from the vendor 2factor, responds to threats from hackers who interject themselves into a browser session after a user has logged on with a user name and password.

“Most login processes only authenticate you once,” says Glenn Veach, CTO of 2factor.

Say you log onto your bank’s Web site. Even after the bank’s security process authenticates you, a hacker still could interject another server into the session, one that shows a Web browser window with the same name as your bank’s. That would bring you to another site where you are prompted to give up private financial information, Veach says.

2factor executives say their product prevents such attacks by continuously generating short-lived 256-bit secret keys that authenticate both the server and Web browser without noticeably slowing the Web site. Because every data transmission is subjected to this process, the hacker is stymied — assuming he or she can’t access the 256-bit keys.

“I don’t know of anyone else who is doing that,” security analyst Eric Ogren of the Ogren Group says of 2factor’s approach to security. “It does help protect against some of those attacks that take effort to launch.”

SecureWeb starts at $1 per user, per month, with volume discounts available for resellers and large-volume users. If a bank were to offer SecureWeb, users who want extra security would be prompted to download a small program that appears as a desktop icon. Instead of launching a browser themselves, users would click on the desktop icon, which launches the browser and the bank Web site. Users would log on with their user names and passwords as they do today, and otherwise would notice no changes, according to 2factor.

“One thing we’ve heard from analysts is, you can have the world’s best security, but if nobody adopts it and nobody uses it, it’s not any good,” says David Burns, CEO of 2Factor.

SecureWeb, which facilitates secure communication between Web browsers and back-end servers, is based on 2factor software called Real Privacy Management (RPM), a customizable security system that can be deployed inside any software application, device or chip. Veach describes RPM as a developers kit that lets organizations integrate security with existing applications.

Pricing for RPM is the same as for SecureWeb.