Screenshot of Smart Pack management GUI
A Windows console is used to manage the information held on the smart cards, with optional remote management if required

Review: Vasco Digipass Smart Pack password security software

Get smart with your passwords

Written by Alan Stevens

Larger Image

Passwords can be a real pain to manage. Make them too short and they’re easy to remember but, similarly, easy to crack. Too long or complicated and they’re easily forgotten.

Added to which, you have to remember lots of them – one to log on to your PC, another to get onto the intranet, yet another for email and so on.

Advertisement

Digipass Smart Pack neatly resolves this dilemma. By the simple expedient of storing all your passwords in one place – on a secure smart card – which, together with a Pin code, you use to gain access to everything. Your desktop, the Lan, applications, websites, the works.

There are three parts to the Smart Pack. A smart card reader, the smart cards designed to go with it and client software, which can be installed on any PC running Windows 2000 or XP Professional.

The card reader gets installed first, by plugging into a free USB port. If the PC is running XP then suitable drivers will be loaded automatically, otherwise it’s just a matter of directing the new hardware wizard to search for them. After which you need to install the client software by running the setup program provided, and re-boot.

At this point you can still log on to the PC in the normal way, although you’ll notice that the usual logon screen has been replaced with one from Vasco. Log on normally and you can initialise your smart card simply by placing it into the reader and specifying the secret Pin you want to use. The Pin and the card itself provide secure, two-factor authentication of your identity.

Of course, Windows knows nothing about Pin codes and smart cards. It still wants you to log on using a user name and password, so the next step is to store those credentials in the chip in a smart card, using the management console provided. You can also force Windows to only log on with a smart card and lock the PC, or log off, whenever the card is removed from the reader.

Next time you log on, just insert your card and type your Pin – the Vasco software does the rest. A couple of applets running in the taskbar will also learn how you log on to other applications and websites and store that information on the card too. So, as long as your card is in the reader, you won’t have to remember any passwords at all and each one can be as long and complicated as you like.

Terminal server logons can also be stored on the card and the reader used with thin client terminals running XP Embedded. Digital certificates too, can be stored and used either to authenticate yourself or encrypt and digitally sign emails and other documents.

Note, however, that you can’t use stored certificates for both purposes and the setup and management required is a lot more involved if you want to take advantage of these options.

Ordinary password management, by contrast, is remarkably straightforward, even re-setting Pin codes when users forget them. Remote management of the smart cards is yet another option on larger networks and if you’re at all concerned about security or just want to reduce the time spent resetting user passwords, the Digipass Smart Pack is a neat and relatively painless way of solving the problem.

Product overview

  • Price: £117.50 (£100 ex Vat) for an evaluation kit (software plus two smart cards and card readers)
  • Manufacturer: Vasco (01296 482 661)
  • Specifications: System requirements:

Best prices

Ratings

  • Overall rating: 4
  • Features: 3
  • Performance rating: n/a
  • Value for money: 4
  • Average user rating:
Rate this product

Verdict

Pros: Secure two-factor authentication; automatic learning of application and Web logons; thin client support; option to lock PC when card is removed; optional remote management of smart card data
Cons: Windows only; web logon only works with Internet Explorer
Overall: A relatively easy way to replace worn-out Windows and Web passwords with secure two-factor sign-ons

See also:

Review: Vasco Digipass Pack security software and USB tokens

Two-factor authentication for remote and local users   More...

image: Safeboot for USB

Review: McAfee Safeboot for USB security

Keep your data safe with these secure USB devices   More...

Advertisements

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation