Home > Security Tips > Web Security Advisor > ASP.NET authentication: Three new options for Web services
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

ASP.NET authentication: Three new options for Web services


Mike Chapple, CISSP
03.11.2004
Rating: -2.33- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Web developers migrating to ASP.NET are about to find themselves faced with new authentication options available for use in Web services. These tools offer greatly enhanced functionality over prior authentication mechanisms and allow you to seamlessly integrate the appropriate level of security into your applications.

Let's take a brief look at each of the three authentication modes supported by ASP.NET.


MORE INFORMATION ON SECURING WEB SERVICES:

  • Passport Authentication allows users of Microsoft's Passport service to use their existing .NET Passport credentials to authenticate to your site. This technique is mainly used by extremely large-scale Web sites, such as Microsoft's own MSN network, the USA Today Web site and e-Bay.

    So which authentication mechanism is right for you? It depends upon your needs. If you're building a public Web application that will see large-scale use, you'll probab



    ly find Forms Authentication the most flexible and appropriate technique. Windows Authentication offers a viable alternative when users already possess a domain account. This makes it an ideal choice for intranet applications and minimizes the number of times users must provide their authentication credentials during a single session. Microsoft's Passport is a great idea in theory, but it's unlikely that you'll find it useful enough to justify the $10,000 annual licensing fee charged by Microsoft.

    About the author
    Mike Chapple, CISSP, currently serves as Chief Information Officer of the Brand Institute, a Miami-based marketing consultancy. He previously worked as an information security researcher for the U.S. National Security Agency. His publishing credits include the TICSA Training Guide from Que Publishing, the CISSP Study Guide from Sybex and the upcoming SANS GSEC Prep Guide from John Wiley. He's also the About.com Guide to Databases.


    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Web Security Advisor,   Web Authentication and Access Control,   Enterprise Identity and Access Management,   Application and Platform Security,   Web Security Tools and Best Practices,   Web Services Security and SOA Security,   Web Application Security,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Web Security Advisor
    DNS rebinding defenses still necessary, thanks to Web 2.0
    New defenses for automated SQL injection attacks
    PCI compliance and Web applications: Code review or firewalls?
    Worst practices: Bad security incidents to avoid
    Web scanning and reporting best practices
    Social networking Web site threats manageable with good enterprise policy
    Enterprise security in 2008: Building trust into the application development process
    PCI DSS Section 6: A plan for tackling application security
    Making the case for Web application vulnerability scanners
    Preparing for uniform resource identifier (URI) exploits

    Web Authentication and Access Control
    Changing times for identity management
    How to use single sign-on for Web access control to prevent malware
    IBM USB banking device stops keyloggers, malware
    Can mutual authentication beat phishing or man-in-the-middle attacks?
    Could someone place a rootkit on an internal network through a router?
    Sun launches open source OpenSSO for identity management
    Should a new user have to confirm an email address to gain access?
    Shared Identity Providers Could Soothe Password Chaos
    Users can no longer reach any Microsoft login site. Any ideas?
    Vista WIL: How to take control of data integrity levels

    Web Services Security and SOA Security
    Cryptographers say cloud computing can be secured
    Information security book excerpts and reviews
    Will cloud computing and virtualization save the day?
    MySpace, Facebook ignoring basic principles of security
    Kaminsky: DNS flaw capable of attacks on many fronts
    Kaminsky on DNS rebinding attacks, hacking techniques
    Which operating system can best secure an FTP site?
    IBM's Watchfire halts network research, focuses on Web apps
    How does identity propagation work?
    Citrix adds Web security with acquisition

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    access log  (SearchSecurity.com)
    anonymous Web surfing  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    identity chaos  (SearchSecurity.com)
    knowledge-based authentication  (SearchSecurity.com)
    multifactor authentication (MFA)  (SearchSecurity.com)
    walled garden  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Research Solutions for Network Security, Access Control and Security Threats
    More Security Resources for Resellers, VARs and OEMs
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts