ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

RSA pushes usability in security

Peter Judge ZDNet.co.uk

Published: 09 Oct 2002 09:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

RSA Security is putting usability at the head of its product goals, as it hopes that future authentication products will be used more widely -- by administrators, not security specialists. The latest version of its Web authentication product, ClearTrust 5.0, is intended to be more usable, and more interoperable with other products than previous versions.

"There are 13 million security tokens out there, but there are tens of millions of passwords," said Art Coviello, chief executive of RSA Security, introducing the new version. "It's our job to eliminate them." Two-factor security based on tokens will have to replace the current single-factor method based on passwords, he said.

Single-factor security, most often exemplified by user IDs and passwords, is based on a very simple premise: what you know. In contrast, two-factor security isn't limited to what you know. It's also "what you have."

Introducing two-factor security into the workplace means making it easier to use than it has been previously, added Coviello.

John Worrall, marketing vice president of RSA, said usability had been high on the list of priorities during development of ClearTrust 5.0. With this version, said Worrall, "ClearTrust has gone through our usability lab for the first time."

There is an imperative to make such security products easy to use, he said. "In future the security market is not a niche. If the user interface is not good enough, it will slow down user acceptance." Previous RSA products have been aimed at expert security administrators.

RSA Security now has the same user interface on its ClearTrust and RSA mobile products (RSA mobile sends a one-time authentication code to the user's mobile phone) so administrators will find it easier to handle both. "There is a consistent methodology for the solution in both spaces," said Worrall, promising that future RSA products will have the same user interface.

ClearTrust 5.0 is the second version of the product to come from RSA, since the company bought ClearTrust's developer Securant in September 2001. Other new features include compliance with the Oasis group's markup language for security assertions, SAML, and better integration with RSA's other products, Keon digital certificate management and BSAFE encryption

RSA employs one usability specialist, but it has a usability lab where potential partners and users can try out pages built with different principles. "We want to map the user interface to the way things work," said Worrall.

Peter Judge reported from the RSA Conference in Paris.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
54 out of 81 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Business Process Administrators

Business Process Administrators Fixed Term Contract Head Office Bradford, West Yorkshire The HR systems team is responsible for producing and ...

Java Developer - User Interface - Swing

Huxley Associates reputable client requires a senior Java developer to join the user interface team for the continuing development of a consumer ...

Hyperion Administrators - Reading - 30,000-40,000

Hyperion Administrators are required to join a global data integration companies based in the UK. My client, based near Reading is looking for an ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation