RSA: Microsoft to shelve token support in Vista

By Munir Kotadia, ZDNet Australia
Wednesday, May 03, 2006 10:22 AM
Microsoft has shelved plans to include built-in support for RSA Security's tokens in Windows Vista, even though the company has been testing out the authentication technology for almost two years.

In February 2004, Microsoft Chairman Bill Gates said that Windows would be able to support easy integration with RSA's popular SecurID tokens. That meant businesses would find it far easier to deploy a two-factor authentication system for logging on to networks and applications.

However, almost two years after the SecurID beta-testing program kicked off, RSA's chief executive, Art Coviello, disclosed that Windows Vista will not natively support the technology.

"Microsoft had said they would include the ability to support all kinds of One Time Password (OTP) and challenge-response type authentication in Vista. But they were unable to get it in with all the other issues they have had, so it is going to take longer," Coviello said in an interview on Tuesday morning in Sydney.

According to Coviello, sales of SecurID for Windows have "gone slowly" because Microsoft decided not to support the tokens natively in Windows. This meant that deploying a token-based system still required "some work," he said.

"It has gone slowly, and it has gone slowly for a number of reasons," Coviello said. "Microsoft has given us source code so we can replace the Microsoft logon screen. However, it is not yet native to the operating system. So it still requires some work at the desktop, which slows down the adoption rate."

Coviello expects Microsoft to add native support for SecurID in future updates to Vista, after which he hopes demand will increase significantly for two-factor authentication, where people present a second form of identification as well as their password.

"Admittedly, when Vista eventually includes support for onetime passcodes--as is expected in some future point release--people will be more aware generally," he said.

"Right now, we have a competitive advantage, and quite frankly, the adoption rate of our product, SecurID for Windows, is more about inertia in the market than about the technology," he said.

Although Microsoft has been slow to add support for SecurID and other password alternatives, Gates has frequently called on the industry to move away from passwords--including in a speech at this year's RSA Security show.

Vista is expected to include a password management system called InfoCards, which Gates announced at the RSA conference.

Microsoft said Tuesday that it had worked with several vendors and customers on whether to add native support in Vista for one-time passwords, via its Kerberos authentication protocol. RSA's SecurID token generates a different password for each attempt to log on to a service.

"Most customers told Microsoft they do not view one-time passwords as strategic and are looking long term to smart cards as their preferred strong authentication mechanism," a representative for the software maker said.

The Vista update will let third parties write credential providers to add their authentication tool to the operating system, the representative added.

CNET News.com staff contributed to this report.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

For the sake of accuracy: "via its Kerberos authentication protocol". That's PLAIN WRONG. Kerberos doesn't belong to microsoft. It could be their Kerberos authentication protocol implementation... at most.
Posted by Edmundo Carmona on Thursday, May 04 2006 12:35 AM


Tech Jobs Now!

Search for your ideal tech job:

Create your own yum repository

Open Source

Learn how to create your own yum repository with the createrepo tool. One thing it allows you to do is distribute specialized packages within an organization.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions



Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery

Could this be the most critical budget for India?

Blog thumbnail

For business journalists in India, budget time is excitement time. It's like sports journos covering the Olympics. As a newspaper correspondent, I too had my fill of budget-time excitement. But..... by Swati Prasad

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web