Feeds

SecurID takes backseat in Windows Vista

Death of passwords postponed

7 Elements of Radically Simple OS Migration

It was cheered, specifically by employees of RSA Security, as the means to provide secure login to PCs running Windows Vista, finally dispensing with passwords and helping lock down enterprise networks.

Two years later, though, Microsoft has abandoned plans to provide native support for RSA's SecureID token-based authentication system in the delayed operating system, despite having worked on integration with RSA.

A Microsoft spokesman told The Register that companies like RSA must now write so-called credential providers that talk to Windows Vista and allow their security tokens and authentication technologies to work with the operating system.

"Most customers told Microsoft they do not view one-time passwords as strategic and are looking long term to smart cards as their preferred strong authentication mechanism," the spokesman said.

Microsoft was speaking after RSA chief executive Art Coviello was reported to have revealed Microsoft had devised its own architecture for third parties to use rather than providing native support for SecurID.

The Microsoft/RSA SecureID alliance was announced at the RSA Conference in 2004 with enthusiastic backing from Microsoft. The vision was to provide users with two-factor authentication access to PCs and to finally replace static passwords - the death of which Gates has been predicting for some time.

Gates, then a relative newbie to RSA events, brandished an RSA key fob on stage at the 2004 show in San Francisco, California, to enthusiastic applause from RSA employees. Microsoft's head of security Mike Nash, meanwhile, said that SecurID would allow customers to "more positively identify users before giving them access to systems and corporate resources."

RSA and SecurID, though, appear to have lost their favored status. Instead, RSA must now join other security providers to develop credential providers, which plug into the Windows Vista LogonUI. Coviello blamed problems Microsoft has had delivering Windows Vista, saying native support for SecurID would appear in later editions of the operating system. ®

Best practices for enterprise data

More from The Register

next story
Microsoft's Euro cloud darkens: US FEDS can dig into foreign servers
They're not emails, they're business records, says court
Sysadmin Day 2014: Quick, there's still time to get the beers in
He walked over the broken glass, killed the thugs... and er... reconnected the cables*
VMware builds product executables on 50 Mac Minis
And goes to the Genius Bar for support
Multipath TCP speeds up the internet so much that security breaks
Black Hat research says proposed protocol will bork network probes, flummox firewalls
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
Microsoft says 'weird things' can happen during Windows Server 2003 migrations
Fix coming for bug that makes Kerberos croak when you run two domain controllers
Cisco says network virtualisation won't pay off everywhere
Another sign of strain in the Borg/VMware relationship?
prev story

Whitepapers

7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
A new approach to endpoint data protection
What is the best way to ensure comprehensive visibility, management, and control of information on both company-owned and employee-owned devices?