Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


tonyhughes

Hawkes Bay
8476 posts

Uber Geek

Retired Mod
Trusted
Lifetime subscriber

#24100 15-Jul-2008 12:27
Send private message

This just smacks of the inability of some people to care about the users that have to use the system to create the revenue that feeds the company that pays the wages of the people that should really care more about the users.

Check this out - its a third party external system we use here at work (i.e. we have zero control over this process), all steps are required to use just one application, and the user gets booted after a few mins of inactivity:

1.    Log in to *******
2.    Visit the ******** web site: https:***************************
3.    Username: ***********
4.    Password: ********** followed by the display on your token. E.g. if your password is “*********” and your token reads “********” then enter “***************”.
5.    Once you see ********************, you will be asked to log in again.
6.    Username: ************
7.    Password: ************* (exactly as written including capitals) (different to first password, not choosable, and very complex for n00bs)
8.    Click the “**********” application icon
9.    Wait for the security warning to pop up, then click okay
10.    Wait for login to occur (~ 1 minute)
11.    Once ************ application opens you will be asked to login (again!!)
12.    Username: *************** (different username to first two)
13.    Password: ************** (different password again to each of the other two)







Create new topic
Dratsab
3946 posts

Uber Geek

Trusted
Lifetime subscriber

  #148060 15-Jul-2008 12:52
Send private message

Woohoo - that's a goody.  Looks like the system must be protecting the secrets upon which the survival of the entire western nation depends...



rscole86
4973 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  #148068 15-Jul-2008 13:06
Send private message

What is this token you use? Is it similar to a e-token like the aladin HASP keys?

Filterer
489 posts

Ultimate Geek


  #148070 15-Jul-2008 13:20
Send private message

I'd hazard a guess its a RSA SecurID token
http://en.wikipedia.org/wiki/SecurID




pɐǝɥ sıɥ uo ƃuıpuɐʇs



amanzi
Amanzi
1292 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #148151 15-Jul-2008 15:57
Send private message

Ha ha - that's nasty, but not totally uncommon. I'm going to hazard a guess and say that you're logging onto a Citrix Secure Gateway, then launching a remote desktop session to an application server, then launching a crusty, old legacy app that logs onto an Oracle DB server? About right?? :-)

Similar to an experience I had a Govt department recently - when signing on for the first time, you get three different sets of credentials that you have to manually sync together by changing all the passwords to match.

Jonski
265 posts

Ultimate Geek


#152360 29-Jul-2008 11:32
Send private message

What's the chance that people using this system have the login info stuck to the side of their monitor and leave their rsa tag in their top drawer?

I understand that some hospital systems are similarly diabolical.

Mind you, we've got the auditors in today, and one of them didn't know how to log in to their own network via vpn and rsa token. They were asking ME if I knew how to log in to THEIR systems.

I'm thinking of having a BOFH moment and randomly dropping their LAN port on the switch... or throttling it right back on half duplex. Bwahahaha!!

Cheers
Jon




I reject your reality and substitute my own!
- Adam Savage, Mythbuster

Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.