About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
PRODUCT REVIEWS GUIDE    REVIEWS    ANALYSES    SPECIAL REPORTS 
 

TEST CENTER

 
Token security

By Wayne Rash
September 6, 2002


THE CONCEPT BEHIND the NetSwift iGate is a good one: Provide an appliance with SSL acceleration and security that resides in front of your Web servers. That way, you can have secure communications to your network without burdening those servers with the processing overhead of SSL or the problems of setting up security on each server.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
Rainbow Technologies accomplishes this by providing iKeys, tokens that plug into a standard USB port on a computer. Once users insert the token and provide a PIN, their systems are authenticated and can reach a protected Web site or server via the appliance.

In theory, Rainbow Technologies' approach provides very strong protection. One of the basic practices of good security is that authentication must be proven by something you have (a token, for example) and something you know (perhaps a password). As long as these two facets are secure, your authentication is robust.

In practice, however, iGate's approach is not as secure as one might expect, although it's far better than user names and passwords. On the other hand, it's easy to administer and the cost isn't bad. And iGate isn't particularly difficult for an administrator or an end-user. Despite the good overall performance of the NetSwift iGate, we found cause for concern about Rainbow Technologies.

Unlocking the iGate

NetSwift iGate is a low-impact appliance. It's not hard to make this device part of your datacenter. Once it's in the rack, you need only attach a console cable to a terminal long enough to set the administrative IP address and the virtual IP address to be used by clients. Everything else is done via the appliance's management tools. One of the nice things about the iGate is that it requires no extra software on the Web server, so virtually any Web server will work.

Using the primary management tool requires an HTTPS connection to the appliance. This browser-based tool allows administrators to set up the operational aspects of the appliance. For example, they can choose whether to use SSL for connections from browsers; they can enable some load-balancing features; they can even select what you would like displayed on the appliance's front-panel LCD, such as IP address, and transaction rate.

User management is handled via an access control manager. This manager let administrators assign iKeys to users. The software also enables administrators to grant users access to protected Web servers using a name and password in case they can't use their iKey.

Client software needs to be installed on each workstation to support the iKey token. That installation takes place automatically when the CD is inserted into the workstation CD drive.

To access the Web server via iGate, users need only plug their iKeys into a USB port when prompted to do so. Users are then asked to enter their PIN. Once that's done, they're in.

The iKeys, incidentally, contain an LED that lets users know that the port is working. These token are provided with a keychain and key fob. Unfortunately, the token works only on Windows machines; Mac and Linux users are out of luck.

In general, once the NetSwift iGate is set up and the tokens are passed out to employees, there's not much to do except make changes, such as when a user is added, if his or her information changes, or if a user leaves the company. You can administer the process quickly and easily. Setting up a new user requires only that you insert his or her token into your USB port and define the user's name. When you've finished that, you upload changes to the appliance. It's that easy.

We did, however, have some concerns about the security of the appliance and about the company. First, the tokens accept only numerical PINs; users can't enter alphabetical or special characters. If someone wanted to use a pilfered token to break into your server, the numbers-only limitation would greatly simplify their task. Administrators can set the token to lock up after a predetermined number of failed access attempts.

Wait, isn't this a security company?

Another concern is the lack of security on the CD that comes with the iGate. The product we received contained a quarantined virus. This isn't a huge threat, but it means that Rainbow Technologies had a virus infection on the computers that created the CD, and one of them was caught. But it also means that other viruses or worms could exist on that disk that weren't caught. Clearly, Rainbow Technologies needs to clean up its operation and find a way to ensure the CD creation is safe from even the accidental introduction of malicious code.

Furthermore, Rainbow Technologies failed to include the front panel key when shipping the unit. According to a tech support engineer, this has happened with some frequency. Although this oversight does not pose a threat to your network, it delays the IT department in getting the iGate up and running.

Together, the virus and key problems suggest that there may be huge gaps in the quality assurance process. Although the iGate performed flawlessly once we got it unlocked, we never stopped wondering what else the company forgot to check.

When we got the iGate operating, it performed as the company said it would. It's easy to deploy, fairly easy to use (though the user interface could be more intuitive), and it provides the SSL support and the security companies need for their internal operations and their commerce sites. Unfortunately, Rainbow Technologies needs to address some serious security shortcomings before we can give iGate an unqualified thumbs up.




  BOTTOM LINE
Rainbow NetSwift iGate
BUSINESS CASE
This appliance provides security and acceleration to your commerce network through the use of USB based tokens and a simple administration process.

TECHNOLOGY CASE
iGate uses SSL acceleration and security keyed to USB tokens to provide a fast and secure communications.

PROS
+ Implementation is reasonably easy
+ Applicance boasts SSL acceleration
Security is token-based

CONS
- Tokens work only with Windows
- Access security should be stronger

COST
$9,995 for 50 tokens

PLATFORMS
Clients must run Windows to use USB tokens

COMPANY
Rainbow Technologies, Inc.; www.rainbow.com

Consider
Ease of use
Implementation
Innovation
Interoperability
Scalability
Security
Suitability
Support
Training
Value
Consider



RELATED ARTICLES

Test Center Research Report: Security
Sniffing for sneaks


RELATED SUBJECTS

Security


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no