Late last week, I spoke with the folks at Positive Networks, who, as it turns out, are in the process of evolving from a hosted VPN business (which has in fact been sold off) to one selling a really cool authentication product. In a nutshell, their new offering uses a cell phone as the second factor in a two-factor authentication scheme. It’s called PhoneFactor, and it’s worth a look – in fact, one version of it is free.
There are a lot of options in this service, but in its simplest form it is indeed simple – log in to your network as usual, and PhoneFactor will then place a voice call to the handset/phone number you designate. You key in a “#” if the connection is valid, and that’s it. The second factor in this case is something you’re likely to have with you all the time, and it’s essentially free in this application. No hardware tokens or USB keys are required. And if someone’s trying to hack your account, you’ll know right away.
I could only think of two possible problems with this approach. First, you may be out of range or your handset might be off. PhoneFactor can be programmed with a backup/alternate number. Second, if your directory gets hacked, someone else might get the call. Again, no problem, unless they’ve also got your password. But that’s the beauty of two-factor authentication. Information thieves need to compromise two different elements, and that’s a lot harder than one.
Like I said, the entry-level version is free, so give it a try. This solution isn’t as flexible as fingerprint recognition (more on that shortly), but no hardware, other than the handset you already have, is required.




