Showing posts with label IT security. Show all posts
Showing posts with label IT security. Show all posts

Thursday, February 14, 2008

Managed security boom hits 20% CAGR

THE managed security services market in Australia will expand at a compound annual growth rate of 20 per cent until at least 2013, according to new research from analyst group Frost & Sullivan.

The Asia Pacific Managed Security Services 2006-2013 found revenues in the Australian market were $240 million in 2006 and were forecast to grow to $880 million by the end of 2013.

While the managed security services (MSS) market was still in its early stages of growth in the region, Frost & Sullivan analyst Arun Chandrasekaran said the MSS model had started to gain wide acceptance, particularly in advanced countries like Australia, Japan, Singapore and Hong Kong.

The potentially enormous market in India had also showed promising growth on the back of ongoing liberalisation in the telecommunications sector.

“Additionally, there is a growing realisation that information security investments should no longer be viewed as IT investments but more strategically in the business risk context,” Mr Chandrasekaran said.

“Engaging with a strong MSSP allows organisations to share risk management and gain access to skilled resources for risk mitigation,” he said.

Mr. Chandrasekaran said globalisation and mobility, small and medium-sized businesses faced the same issues as larger enterprise – like fading security perimeters, complex converged networks and data security issues”.

“Hence the security requirements for SMB in Australia are not too different from the large enterprises. However, the awareness levels and willingness to pay still separate these two horizontal segments.”

For more Managed Service news, click here.



For more IT Security news, click here.

Wednesday, February 6, 2008

Google ramps email security services

SEARCH giant Google has unveiled a new suite of security tools for protecting email from spam and related problems, technology it acquired when it acquired internet firm Postini last year.

The so-called Powered by Postini security products deliver message filtering, encryption and archiving for business, and works with any mail system, including Notes, Exchange, and Novell Groupwise.

Pricing for the Powered by Postini services start at US$3 (A$3.35) per user per year, although a premium service that includes filtering, security and archiving costs US$25 per user per year.

“As threats rise in volume and complexity, and compliance requirements pile up, IT is struggling to find the resources to keep up,” said Google director of product management Scott Petry.

“Now, Google can take care of this for you. Organisations of all shapes and sizes can get access to Google's industry leading security and compliance technologies,” Mr Petry said.

The Powered by Postini security products are the latest addition to Google Apps platform, which includes email, word processing, spreadsheets and personal information managers.

These online applications have become the latest industry battleground for the hearts and minds – if not their dollars – of customers. The threat of internet-based apps is one of the keys behind Microsoft’s massive bid for Google’s online rival Yahoo!

For more IT Security news, click here.



For more Web Applications news, click here.

Thursday, January 24, 2008

Cyber criminals move beyond Windows

ORGANISED criminals involved in cyber attacks aimed at stealing IDs and money are moving beyond Windows, and are for the first time knocking loudly at the doors of Macintosh and Linus-based systems, experts warn.

Tech security and control firm Sophos has published in its Security Threat Report 2008 found Apple was a significant target of criminal hackers in 2007, and that the threat would expand in 2008.

While Malware for Macs has been seen before, the Sophos reports that malicious code seemed for the first time to have been written by financially-motivated hackers who saw an opportunity.

“No-one should underestimate the significance of financially-motivated malware arriving for Apple Macs at the end of 2007,” Sophos senior technology consultant Graham Cluley said.

“Although Macs have a long way to go in the popularity stakes before they overtake PCs, particularly in the workplace, their increased attractiveness to consumers has proven irresistible to some criminal cybergangs.,” Mr Cluley said.

The Sophos' Threat Report also reveals that the wider use of new mobile technologies and wi-fi enabled devices, like the iPhone and iPod Touch, may be opening up new vectors of attack for hackers.

Flaws have been found in the mobile email program and Safari browser installed on such devices. But while uptake remains limited cyber-criminals are unlikely to exploit these avenues on a major scale in the near future. However, as personal wi-fi devices grow in popularity, the risks will no doubt increase.

Sophos experts also said that the low cost ultra-mobile PCs, such as the popular Linux-based ASUS EEE laptop, will gain the attention of the cyber underworld as sales continue to grow.

“The ultra-mobile ASUS EEE laptop, like many others, comes pre-installed with Unix, making it automatically immune to the vast majority of spyware and malware attacks,” Mr Cluley said.

For more IT Security news, click here.

Monday, January 21, 2008

Yahoo saddles up OpenID 2.0

INTERNET giant Yahoo! has announced its support for the OpenID 2.0 digital identity framework for all of its 248 million active registered users worldwide.

The OpenID service means that a Yahoo can use their Yahoo ID to register with any other site using OpenID 2.0, eliminating the need to create many separate IDs and log-ins for different web sites.

The initial OpenID service will be available for public beta on January 30. Web sites that accept OpenID 2.0 will be able to add a simple “Sign-in with Your Yahoo! ID” button to their login pages that will make it even easier for their users.

“A Yahoo ID is one of the most recognisable and useful accounts to have on the internet and with our support of OpenID, it will become even more powerful,” said Yahoo executive vice-president for platforms and infrastructure Ash Patel.

“Supporting OpenID gives our users the freedom to leverage their Yahoo! ID both on and off the Yahoo! network, reducing the number of usernames and passwords they need to remember and offering a single, trusted partner for managing their online identity,” Mr Patel said.

OpenID is an open, decentralised, free framework for user-centric digital identity, which eliminates the need for multiple usernames across different websites. OpenID is still in the adoption phase, but is becoming more popular as large organisations like AOL, Microsoft, Sun, Novell and others begin to accept and provide OpenIDs.

Today it is estimated that there are over 120 million OpenID-enabled URLs with nine thousand sites supporting OpenID logins.

“Today’s announcement by Yahoo supporting OpenID is the realisation of three years of hard work from this extremely passionate community of developers,” said Scott Kveton, chairman of the OpenID board of directors. “I have never met a more committed set of people focused on doing “the right thing” all the time.”

For more IT Security news, click here.



For more Digital Content news, click here.

Friday, January 18, 2008

Microsoft finds Excel security hole

SOME older versions of the ubiquitous Microsoft Excel spreadsheet can be exploited by hackers to take control of people’s computers, Microsoft has warned in an official security bulletin.

The company said it had only very recently become aware of the issue and said at this stage the risk to users was “limited” because the malicious code was not in wide circulation.

“At this time, we are aware only of targeted attacks that attempt to use this vulnerability,” the company said in a scheduled Security Advisory said.

The company has not decided whether to issue a patch for the vulnerability.

“Microsoft is investigating the public reports and customer impact. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.”

Meanwhile, Microsoft has continued to fill its most senior executive ranks with new blood from outside of the company announcing the appointment of a senior Disney executive as Microsoft chief information officer.

Tony Scott, who was a senior vice-president and CIO at Disney, will take charge of the Microsoft 4,000-person global information technology organisation that manages critical technology systems supporting the company’s worldwide sales, marketing and services efforts, as well as enterprise systems and applications for all corporate processes.

Mr Scott will officially assume the new role at Microsoft in February and report to Microsoft chief operating officer Kevin Turner.

For more IT Security news, click here.

Friday, January 11, 2008

Web 2.0 hacks on the increase

SOCIAL engineering and Web 2.0 attacks are fast becoming the most serious security threats on the internet, according to global security experts Grisoft, makers of the AVG security products.

“In 2008, Internet users are likely to see more sophisticated attacks as organised cybercriminals step up their efforts to steal digital assets from social networking site users,” Grisoft chief research officer Roger Thompson.

“Social networks are particularly vulnerable because they rely heavily on hyperlinked content, information sharing and the trust of their participants,” Mr Thompson said.

“From the attacks on Facebook and the Major League Baseball Web site to the Alicia Keys’ sites, it’s clear over the past year that incidence of online threats is accelerating.”

Viruses made up about 15 per cent of the threat landscape in 2007, consistent with Grisoft predictions at the end of 2006. But it was phishing scams, backdoor worms, trojans, keyloggers, spyware, adware and other web-based exploits that comprised the majority of threats, the company said.

Mr Thompson said web exploits and web-based social engineering attacks will be among the biggest security threats to users this year.

“Viruses will continue to be a threat, but we’ll also see an explosion of exploits through social engineering and Web 2.0 attacks in 2008,” he said.

For more IT Security news, click here.



For more Managed Service news, click here.

Monday, December 10, 2007

Malware incidents double in 2007

EUROPEAN tech security specialist F-Secure has reported it has detected as many malware signatures during 2007 as it had in the entire preceding 20 years.

And the company is predicting a miserable 2008, with malware volumes continuing to increase as criminals successfully create a network-based underground ecosystem, trading malware development tools, skills, capabilities and resources.

F-Secure says in its 2007 Data Security Wrap-Up that it has identified a total about 500,000 malware signatures in its cumulative database – compared to 250,000 a year ago. The number of examples of malware had doubled in just one year.

“We've never seen as many samples arrive to our labs,” F-Secure Corporation Chief Research Officer Mikko Hypponen said.

“We would be unable to handle such huge samples loads if we would not have built a high degree of automation into our malware analysis systems over the past years,” he said.

The company said that while no truly new malware technologies were seen the existing ones were refined and adapted for much greater effectiveness.

Financial transactions remain a favorite target for network crime. The amount of phishing sites continues to increase, but as bank customers have become more aware of this threat the criminals have started employing more sophisticated techniques.

For more IT Security news, click here.

Monday, November 26, 2007

Symantec launches SmartPhone protection

US-based tech security specialist has rolled out a suite of consumer mobile security products that provides anti-virus, firewall and anti-spam protection for Windows Mobile and Symbian OS phone operating systems.

Symantec’s Norton Smartphone Security aims to give mobile device users the same level of security that has become standard for laptops and other computing devices.

“Smartphones are expanding consumer freedom to communicate and access important information anytime, anywhere,” said Symantec Consumer Business Unit senior vice-president Rowan Trollope said.

“However, unsecure public WiFi or network connections can put users at risk. In addition, web and e-mail viruses can directly infect smartphones, enabling hackers to remotely control the device, access sensitive information or disable applications,” he said.

“Norton Smartphone Security runs discreetly in the background, providing the confidence and peace of mind to engage in everyday activities like e-mailing, Web browsing or banking online from these handheld devices.”

As more users transact using their mobile devices, the financial incentives for virus writers and mobile hackers increase, Symantec says.

In a U.S. survey of smartphone users conducted by Applied Research, 34 per cent of respondents said they access their bank accounts via their mobile device and 54 per cent of respondents said they access web sites that require a password.

For more IT Security news, click here.

Monday, November 19, 2007

Carriers’ security confidence grows

A NEW survey from IBM has revealed security concerns among telecommunication carriers had reduced dramatically in the past two years.

The results of the 2007 State of Security for Global Telecommunications Carriers survey mark a turning point in a competitive industry where the delivery of new services often has come at the expense of security considerations.

A key finding in this year's report reveals that only 36 per cent of survey respondents said security concerns were hindering their rollouts of Internet Protocol (IP) based service bundles including voice, video and data. That number is down sharply from 2006 when 55 per cent of carriers said security concerns were hindering delivery of new services.

“This survey shows what the market is already experiencing from recent mergers and acquisitions, including Verizon/Cybertrust and IBM/ISS: that security is a key ingredient for carriers as they move into next generation services and solutions,” said Current Analysis senior research director for telecom services Counse Broders.

“Clearly, those providers without a security solution in place risk losing their competitive edge.”

Security concerns still plague the telecom market especially in the area of next-generation, IP-based networks (NGNs).

NGNs represent a major evolution in telecommunications involving the convergence of voice, data and video onto one network.

The 2007 Global Telecommunications Carrier survey revealed that the wholesale migration to next-generation, IP-based architectures is imminent, with almost 85 per cent of respondents indicating that they will roll out this kind of architecture in the next five years.

However, fewer than half of respondents (46 per cent) said their companies had a strategy in place for mitigating security risks posed by NGNs.

For more Telecommunications news, click here.

Sunday, November 4, 2007

IBM boosts security investment

GLOBAL tech conglomerate IBM says it will spend a record US$1.5 billion (A$1.64 billion) next year developing and marketing products specifically for the security market.

The company last week introduced a swag of new security services, products and research breakthrough aimed at helping businesses more effectively manage operational and IT risk.

IBM said the IT security market was being transformed by the growth in more collaborative business models, by more sophisticated criminal attacks, and by increasingly complex infrastructure.

IBM says today’s wide array of security technologies, implemented tactically in silos, are not sufficient to deal with the new risk reality. IBM's approach is to strategically manage risk end-to end across all five domains of information technology security - Information Security; Threat and Vulnerability; Application Security; Identity and Access Management and Physical Security.

“For many enterprises, security is broken,” said IBM Internet Security Systems general manager Tom Noonan.

“The nature of evolving threats is such that installing point solutions to 'keep the bad guys out' is no longer a viable way to secure a business,” Mr Noonan said.

“We advocate new approaches to reduce complexities, adapt to new business imperatives and enable business value versus just threat protection. The path to a more secure world begins with a risk management strategy that limits the impact of threats, improves business resilience and creates an enterprise free of fear.”

IBM's Internet Security Systems (ISS) unit, acquired just over a year ago, is helping lead the way, teaming with IBM Research and integrating with IBM's Software and Systems businesses to deliver the world's most advanced risk management capabilities.

For more IT Security news, click here.

Thursday, September 13, 2007

Google tightens cookie controls

DOMINANT search provider Google has announced plans to tighten its privacy policies, reducing the life-span of ‘cookies’ it users to track which sites users’ visit.

Google global privacy counsel Peter Fleischer said the company would now program its cookies to expire after two years for a user that does not return to the Google search site.

The announcement is seen as a pre-emptive move as privacy advocates in the US continue to push Federal regulators for more stringent controls over the way online companies deal with personal information.

The company already promised recently that it would “anonymise” search server logs – including IP addresses and cookie ID numbers – after 18 months.

“We are committed to an ongoing process to improve our privacy practices, and have recently taken a closer look at the question of cookie privacy,” Mr Fleischer said.

A cookie is a small file that gets stored on the users’ computer when they visit a search site. The cookie reminds the search engine of the preferences the user sought the last time they visited the site. All search engines and most web sites use cookies.

The preferences let Google and other search engines remember basics, such as the user wanting search results delivered in English language, or that they only want ten results per page.

“After listening to feedback from our users and from privacy advocates, we've concluded that it would be a good thing for privacy to significantly shorten the lifetime of our cookies — as long as we could find a way to do so without artificially forcing users to re-enter their basic preferences at arbitrary points in time,” Mr Fleischer said.

“And this is why we’re announcing a new cookie policy.”

For more Web Applications news, click here.

Monday, August 27, 2007

Sharp rise in global malware threat: Sophos

NEW figures compiled by security vendor Sophos’ global network of monitoring stations has found a further sharp rise in web-based virus threats – with 80 per cent of the threats located on hacked legitimate sites.

Sophos uncovered an average of 29,700 new infected web pages every day.

The research for June puts the Iframe malware as by far the most prevalent web-based threat, making up 64 per cent of all threats during the month.

Earlier this month, an Iframe attack on multiple Italian web sites occurred, making headlines around the world. More than 10,000 web pages were infected, most of which were on legitimate but compromised web sites hosted in Italy.

Victim web sites included Italian city councils, employment services and tourism sites. Most of the affected pages appear to be hosted by one of the largest ISPs in Italy.

“The Italian Iframe attack should certainly act as a wake-up call to ISPs across the globe,” said Sophos senior security consultant Carole Theriault.

“Malicious code dumped on these web sites is just waiting to pounce on innocent surfers. Web sites should be as secure as Fort Knox, but at the moment, too many web pages are easy pickings for cybercriminals,” Ms Theriault said.

Nearly 60 per cent of malware-infected web pages in June were hosted in China, while 24 per cent were hosted in the US.

For more Business Software news, click here.

Tuesday, August 14, 2007

Pure Hacking sets up management change

PENETRATION testing specialist Pure Hacking has appointed a new chief executive, with founder Rob McAdam moving back to a business development role.

Former Hewlett-Packard Australia-New Zealand security specialist Timothy Dole takes over day to day management of the company.

Mr McAdam said the decision to appoint a CEO was aimed at driving growth and delivering on the existing strategy and vision for the organisation.

“Pure Hacking is a very successful and rapidly growing provider of specialist IT security services,” Mr McAdam said.

“We have achieved significant growth and with Timothy’s appointment the right senior leadership team is in place to achieve even better results in FY08,” he said.

Pure Hacking was founded in 2002 as a vendor-neutral, ethical hacking company.

So far the company has specialised entirely on penetration testing. While Pure Hacking does not name its clients, it says it has done work for some of the biggest companies in Australia, as well as for companies in 14 other countries.

Mr Dole said his big challenge would be to manage growth, to ensure the company is able to expand quickly both locally and overseas, but not at the expense of customer service quality.

He said Pure Hacking would soon announce a series of new specialist services outside of its traditional penetration testing services.

“It’s an exciting time, we have a solid growth strategy, the right management and an enthusiastic team sharing the same vision and passion,” Mr Dole said.


For more IT Security news, click here.

Tuesday, July 3, 2007

Sophos creates follow-the-sun security blog

IT security specialist Sophos has unveiled a 24-hour, follow-the-sun blog designed to provide breaking news and commentary on emerging security threats.

The SophosLabs blog is written by security researchers at SophosLabs, with regular contributions from the companies researchers based in Sydney, Oxford, Boston and Vancouver.

The blog will be updated several times each day to cover the latest technical information and stories of interest.

The Sophos network of malware and spam analysis centres in each location means the blog covers global timezones.

Australian contributors will include Sean McDonald, SophosLabs Manager, JPAC, and the team at Sophos's North Sydney threat analysis, research and development centre.

“In today's world of rapidly evolving security threats, organisations need swift access to information about what's out there, what's interesting and what's causing a problem," said Mark Harris, director of SophosLabs in the UK.

“The new blog provides Sophos customers, business partners and the general public with updates on interesting new malware and spam techniques, insight into web-based threats, and even examples of when hackers get it very, very wrong,” Mr Harris said.

For more Web Applications news, click here.

Norton update crashes PCs in China

MILLIONS of personal computers and servers in China have been crashed by a faulty update to Symantec’s popular Norton anti-virus software, China’s state-run Xinghua News Agency has reported.

Xinghua said more than 1000 customers in the southern Chinese city of Guangzhou has reported the problem by lunchtime last Friday.

It said an automated update of the Chinese version of Norton Anti-Virus issued last Friday caused computers running Windows XP to crash to a blue screen of death. The computers returned to the blue screen even after a reboot.

Symantec confirmed the incident had resulted from an inappropriate handling of an automatic upgrade of the AntiVirus security software. It is thought the update accidentally prompted computers to kill two essential system files.

Xinghua said it was estimated that several million users ran the Windows XP operating system with Norton Anti-Virus in China.

The state-owned English language China Daily newspaper said Chinese companies were already seeking compensation.

For more IT Security news, click here.

Huawei inks joint-venture with Symantec

CHINESE networking giant Huawei has signed a groundbreaking joint-venture with US security specialists Symantec to develop and distribute security and storage appliances for corporate customers.

The joint-venture’s storage and security appliance products will also target phone companies and service providers.

“The joint venture will help carriers and enterprises effectively address these challenges by offering security and storage appliances that are easy to implement and maximize value to customers,” the companies said.

The yet-unnamed joint-venture is subject to government approvals, though Huawei and Symantec hope it will be operational by the end of the year.

The joint-venture will be headquartered in the Chinese city of Chengdu. It will be 51 per cent owned by Huawei and 49 per cent by Symantec.

“Network security will definitely form the foundation as telecom networks migrate toward an All IP environment,” Huawei chief executive officer Ren ZhengFei

“The partnership will enable us not only to provide leading network security solutions to carriers, but also to deliver professional security and storage solutions to enterprises, helping our customers build a safer and more efficient network.”

Huawei will contribute its telecommunications storage and security businesses including its integrated supply chain and integrated product development management practices.

Additionally, the new company will have access to Huawei’s intellectual property (IP) licenses, research and development capabilities, manufacturing expertise and engineering talent, which includes more than 750 employees.

The joint venture’s services and support infrastructure will draw upon Huawei's successful model for customer service and technical support, including worldwide technical support and call centre operations.

Symantec will contribute some of its leading enterprise storage and security software licenses, working capital, and its management expertise into the new company. Symantec will also contribute US$150 million toward the joint venture’s growth and expansion.

For more IT Security news, click here.

Tuesday, April 24, 2007

Hacker cracks Mac OS security

A HACKER has won a US$10,000 (A$12,000) prize at the CanSecWest security conference in Vancouver after managing to break into a Macintosh computer running OS X.

Conference organisers said they had set up the contest to highlight potential risks of the Mac systems.

The competition had originally been planned as a challenge just for CanSecWest attendees through its onsite wireless network. But when 3Com subsidiary TippingPoint stumped up the cash prize they decided to put the two target machines online and open the context to everyone.

Few details of the hack have been released, and the hacker/prize-winner has not been named, although it is understood they are not at the conference.

“One OSX box has been owned! At this point all we can say is there is an exploitable flaw in Safari which can be triggered within a malicious web page,” according to the CanSecWest web site.

“Of course all of the latest security patches have been applied. Technical details will be forthcoming as the winner works out the release. There is still one more Mac to go (the same flaw cannot be used again, but other Safari bugs are allowed),” it said.

“Just to review the rules, the first box required a flaw that allows the attacker to get a shell with user level privileges. The second box, still up for grabs, requires the same, plus the attacker needs to get root.”

Apple released a security patch late last Thursday (soon after the conference began) or 25 vulnerabilities which attendees thought might be more than a coincidence.

For more IT Security news, click here.

Friday, April 13, 2007

Microsoft patches ‘critical’ Windows security flaws

MICROSOFT has issued five software patches for security problems found in it Windows operating system, including a “critical” flaw in its new Windows Vista operating system.

The company also released a patch for another critical security flaw identified in its Microsoft Content Server platform, warning that the problem could allow hackers remote control of the system.

Five of the six bugs reported in the routine monthly Microsoft Security Bulletin for April were rated as critical, recommending that users update their software immediately.

The bulletin also rated the security hole identified in a Windows Vista messaging function as critical. The problem could lead to hackers taking over a machine, and users should be patched immediately.

“Critical” is the most serious of Microsoft’s four-level security rating system and is defined by the company as “a vulnerability whose exploitation could allow the propagation of an Internet worm without user action.”

Though the security patches were published part of Microsoft’s regular monthly release of fixes, the company last week broke the routine to issue an emergency fix for a problem found in Windows cursor animation files that was being widely exploited by hackers.

Microsoft has also reported that the cursor animation fix, which applied to all current Windows, including Vista, caused problems with some third-party software programs, in particular those related to audio files.

For more IT Security news, click here.

Thursday, April 5, 2007

Patch offered for Windows cursor bug

MICROSOFT is expected to issue a patch outside of its routine monthly security update following the hacker activity focused on an exploit that targets the cursor animation files used in Windows.

The company issued a statement saying its monitoring of attacks found that customer impact had been “limited”, but said it would make a patch available outside of its usual security routines.

Microsoft said it had completed testing on the patch earlier than expected.

The Windows Animated Cursor Handling vulnerability – also known as the ANI exploit – was identified late last week.

“In order for the attack to be carried out, the user must either visit a Web site that contains a web page that is used to exploit the vulnerability, or view a specially-craft email message or email attachment sent to them by the attacker,” Microsoft said in a statement.

Tech security specialist F-Secure said the majority of the attacks could be traced back to different Chinese hacker groups.

“We’ve seen a lot of activity relating to the ANI exploit during the weekend,” F-Secure’s chief research officer Mikko Hypponen said.

“This vulnerability is really tempting for the bad guys. It's easy to modify the exploit, and it can be launched via web or email fairly easily. We hope to see Microsoft release a patch for this exploit very soon.”

Most of the activity around the ANI exploit has been via dozens of malicious websites that attack the user if they visit the page with the most common versions of Internet Explorer. However, on Sunday the first worm using the ANI exploit to spread was found.

For more IT Security news, click here.

Wednesday, March 7, 2007

Australia Post secure online authentication

AUSTRALIA Post has signed the first customer for VIP Online Security, its managed security product that lets financial institutions implement one-time password (OTP) security tokens for internet banking.

After announcing a partnership with internet banking specialist Ultradata a month ago, Australia Post said the NSW Teachers Credit Union had signed on to VIP Online Security as part of its existing Ultradata core banking and net banking software system.

Australia Post Authentication Services manager Roger Lee said the VIP service would give an additional layer of protection to NSW teachers Credit Union account holders.

The service uses Verisign technology whereby account holders can be issued an electronic token that generates a one-time password each time the user wants to access their account. The OTP is used in addition to existing password protection on the site.

The VIP Online Security product is the latest in a series of managed security and authentication services Australia Post has specialised in. It has a strong history in providing services to financial institutions, including Bank@post, POSTBillPay, In-Person Proofing and verifying identity for bank accounts.

Leveraging a shared authentication network, the VIP Online Security lets online service providers accept the same authentication credentials as other participating members of VeriSign’s global VIP network.

NSW Teachers Credit Union chief executive Steve James said embracing security tokens was an important milestone for the credit union’s membership.

“As we don’t have a branch network, they rely very heavily on the internet to access their accounts,” Mr James said.

“Obviously, security in online banking is our prime consideration and Australia Post’s two-factor authentication will provide our members with peace of mind when transacting over the internet,” he said.

For more Managed Services news click here.