<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
<title>Scorpion Software Corporate Weblog</title>
<link>http://www.scorpionsoft.com/blog/</link>
<description>The Security Company for Small Business</description>
<copyright>Copyright 2008</copyright>
<lastBuildDate>Sat, 30 Aug 2008 14:39:22 -0800</lastBuildDate>
<generator>http://www.movabletype.org/?v=3.2</generator>
<docs>http://blogs.law.harvard.edu/tech/rss</docs> 
<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2000-01-01T12:00+00:00</sy:updateBase>

<item>
<title>Come check out some of the new stuff with AuthAnvil at Loadfest 2008!</title>
<description><![CDATA[<p>September is just around the corner, making it a perfect time for you to get the inside scoop on new technologies like Windows Server 2008 and Hyper-V, Small Business Server, SharePoint Server, Response Point and other leading Microsoft technologies at Loadfest 2008!</p>

<p>Loadfest 2008 is a free event for IT Professionals, IT Directors, System Engineers and Microsoft Partners who are looking to connect with their peers whilst gaining valuable hands-on experience with some of the latest & greatest products from Microsoft.</p>

<p>To register, navigate to the following URL: <a href="https://www.clicktoattend.com/invitation.aspx?code=130019">https://www.clicktoattend.com/invitation.aspx?code=130019</a></p>

<p>Join leading Microsoft Partners and employees as they share their experiences with these new technologies! In addition having an opportunity to network with your peers, you'll be able to attend special breakout sessions, see some great demos, and have a chance to win prizes! Don't miss out on this awesome experience to gain an advantage on these Microsoft solutions! Join us at Loadfest 2008 on September 27th!</p>

<p><strong>Notable Speakers and Presentations</strong><br />
Rodney Buike from Microsoft is making the trip out from Toronto to show IT Professionals in Calgary when is coming with relation to Microsoft technologies. Get the technical brief on Small Business Server 2008, especially now that it is been released. Also, Rodney will show us Hyper-V and Windows Server 2008. Get 3 hours of technical training on SBS and Windows Server. Play with these great products and ask technical questions to the people that can answer the questions you have.</p>

<p>Are you curious about Response Point? Come and see Microsoft's latest small business telephone system! Jeff Loucks is a Microsoft MVP with Response Point and he will be delivering a technical demonstration on Response Point during Loadfest 2008.</p>

<p>Lunch is being sponsored by us. We will having a technical lunch and learn and will show you the technical side of AuthAnvil and how to deploy a higher level of security for your networks and clients. I will also be available to address any questions and talk technical about AuthAnvil one on one if you need the time.</p>

<p>Popcorn Technologies will be giving a demo on MOSS (SharePoint Server) and how to fit MOSS into your environments.</p>

<p><strong>Agenda</strong><br />
In addition to some hands-on experience, you'll also see some great presentations. Here's a quick list of some of the sessions that you'll see during the day:</p>

<p>8:30 AM - Meet & Greet<br />
9:00 AM - Windows Small Business Server 2008 Technical Demo<br />
10:40 AM - Microsoft Office SharePoint Server<br />
12:00 PM - AuthAnvil Luncheon<br />
1:00 PM - Windows 2008 Server and Hyper-V<br />
2:40 PM - Response Point</p>

<p><strong>Where?</strong><br />
Popcorn Technologies (6016 3rd Street SW, Calgary, AB)<br />
Windows Live Maps: <a href="http://tinyurl.com/653zvv">http://tinyurl.com/653zvv</a></p>

<p><strong>When?</strong><br />
September 27th from 8:30 AM to 5 PM (Mountain)</p>

<p>Hope to see some of  you there!!<br />
</p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/08/come_check_out.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/08/come_check_out.html</guid>
<category>Events</category>
<pubDate>Sat, 30 Aug 2008 14:39:22 -0800</pubDate>
<content:encoded><![CDATA[<p>September is just around the corner, making it a perfect time for you to get the inside scoop on new technologies like Windows Server 2008 and Hyper-V, Small Business Server, SharePoint Server, Response Point and other leading Microsoft technologies at Loadfest 2008!</p>

<p>Loadfest 2008 is a free event for IT Professionals, IT Directors, System Engineers and Microsoft Partners who are looking to connect with their peers whilst gaining valuable hands-on experience with some of the latest & greatest products from Microsoft.</p>

<p>To register, navigate to the following URL: <a href="https://www.clicktoattend.com/invitation.aspx?code=130019">https://www.clicktoattend.com/invitation.aspx?code=130019</a></p>

<p>Join leading Microsoft Partners and employees as they share their experiences with these new technologies! In addition having an opportunity to network with your peers, you'll be able to attend special breakout sessions, see some great demos, and have a chance to win prizes! Don't miss out on this awesome experience to gain an advantage on these Microsoft solutions! Join us at Loadfest 2008 on September 27th!</p>

<p><strong>Notable Speakers and Presentations</strong><br />
Rodney Buike from Microsoft is making the trip out from Toronto to show IT Professionals in Calgary when is coming with relation to Microsoft technologies. Get the technical brief on Small Business Server 2008, especially now that it is been released. Also, Rodney will show us Hyper-V and Windows Server 2008. Get 3 hours of technical training on SBS and Windows Server. Play with these great products and ask technical questions to the people that can answer the questions you have.</p>

<p>Are you curious about Response Point? Come and see Microsoft's latest small business telephone system! Jeff Loucks is a Microsoft MVP with Response Point and he will be delivering a technical demonstration on Response Point during Loadfest 2008.</p>

<p>Lunch is being sponsored by us. We will having a technical lunch and learn and will show you the technical side of AuthAnvil and how to deploy a higher level of security for your networks and clients. I will also be available to address any questions and talk technical about AuthAnvil one on one if you need the time.</p>

<p>Popcorn Technologies will be giving a demo on MOSS (SharePoint Server) and how to fit MOSS into your environments.</p>

<p><strong>Agenda</strong><br />
In addition to some hands-on experience, you'll also see some great presentations. Here's a quick list of some of the sessions that you'll see during the day:</p>

<p>8:30 AM - Meet & Greet<br />
9:00 AM - Windows Small Business Server 2008 Technical Demo<br />
10:40 AM - Microsoft Office SharePoint Server<br />
12:00 PM - AuthAnvil Luncheon<br />
1:00 PM - Windows 2008 Server and Hyper-V<br />
2:40 PM - Response Point</p>

<p><strong>Where?</strong><br />
Popcorn Technologies (6016 3rd Street SW, Calgary, AB)<br />
Windows Live Maps: <a href="http://tinyurl.com/653zvv">http://tinyurl.com/653zvv</a></p>

<p><strong>When?</strong><br />
September 27th from 8:30 AM to 5 PM (Mountain)</p>

<p>Hope to see some of  you there!!<br />
</p>
]]></content:encoded>

</item>
<item>
<title>Scorpion Software will be closed for Labour Day</title>
<description><![CDATA[<p>On Monday, September 1st, all of Canada will be celebrating <a href="http://en.wikipedia.org/wiki/Labour_Day#Canada" target="_blank">Labour Day</a>. This is a national holiday celebrated across Canada on the first Monday of September of each year.</p>

<p>As a result, Scorpion Software will be closed Monday, with staff celebrating the holiday with their families. </p>

<p>To those celebrating, we hope you have a safe and enjoyable holiday!</p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/08/scorpion_softwa_13.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/08/scorpion_softwa_13.html</guid>
<category>Events</category>
<pubDate>Fri, 29 Aug 2008 12:11:58 -0800</pubDate>
<content:encoded><![CDATA[<p>On Monday, September 1st, all of Canada will be celebrating <a href="http://en.wikipedia.org/wiki/Labour_Day#Canada" target="_blank">Labour Day</a>. This is a national holiday celebrated across Canada on the first Monday of September of each year.</p>

<p>As a result, Scorpion Software will be closed Monday, with staff celebrating the holiday with their families. </p>

<p>To those celebrating, we hope you have a safe and enjoyable holiday!</p>
]]></content:encoded>

</item>
<item>
<title>Update available for the Windows Logon Agent</title>
<description><![CDATA[<p>Today we are re-releasing the v1.6 Windows Logon Agent update. It would be easy for us to simply update the file and be done with it, but I think it is only fair that we explain WHY we are re-releasing it.</p>

<p>At Scorpion Software we work hard to streamline the efficiencies when it comes to our development and test processes. Recently we introduced a new automated build and testing process that fully tests a suite of conditions we look for on a regular basis for our upcoming releases. In the midst of these changes, we introduced a problem in how our source control system functions and ended up merging an old unfixed source file into our release code. The result was that the fixes in our <a href="http://www.scorpionsoft.com/blog/archives/2008/03/new_version_of_1.html" target="_blank">March 3rd release</a> were lost in the latest v1.6 build. The code itself wasn't actually lost and was properly secured in our source control vault; we simply had to remove the stale file and reapply the fix with the good file. </p>

<p>In discussion with some of my peers at other software companies serving the SMB space, most of them said I should simply release the fix quietly and move on. I don't think that is fair to our clients. I think you should know when we make a mistake like this. And more importantly, I think you should know what we have done about it. Here is a list of the outcomes from this experience:</p>

<p><UL><LI>We have updated our stable build system to ensure it can no longer check out code except for its particular branch. Each major release will now include a complete file structure backup to match this to ensure we do not "break" old code.<br />
<LI>All critical bugs reported in the Defect Tracking System now must be accompanied with an automated functional test script. It is the responsibility of Customer Service to ensure that QA knows of the defect and that QA builds the appropriate test(s) for the developers before they are assigned the bug. If a test cannot be provided, a detailed manual test document must be included.<br />
<LI>No developer is allowed to check in code until it passes the automated test(s).<br />
<LI>Once the developer has checked in the code to fix a defect, the automated test will be merged into the automated test system that runs all daily tests, to ensure we do not reintroduce a bug. This in itself would have alerted us to our recent mistake, and prevented us from releasing it. <br />
<LI>Once a critical bug is fixed, it will be reviewed at the next team meeting to see if the <b>class of bug</b> may impact other parts of code. If so, the mandate at the company is to reduce those defects by following the above process over and over again until all code coverage is met.<br />
</UL>   </p>

<p>I'd like to thank our clients who have been patient with us as we investigated what happened here. The fix was actually done last week, but we have not released the fix until today so we could have time to completely understand how it occured, and ensure we properly addressed it.</p>

<p>You can download the latest version of the agent from our <a href="http://www.authanvil.com/upgradecenter/" target="_blank">Upgrade and Update Center</a> or through our <a href="http://www.authanvil.com/install/" target="_blank">Zero Media Install</a> website. </p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/08/update_availabl.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/08/update_availabl.html</guid>
<category>Product News</category>
<pubDate>Tue, 26 Aug 2008 08:30:02 -0800</pubDate>
<content:encoded><![CDATA[<p>Today we are re-releasing the v1.6 Windows Logon Agent update. It would be easy for us to simply update the file and be done with it, but I think it is only fair that we explain WHY we are re-releasing it.</p>

<p>At Scorpion Software we work hard to streamline the efficiencies when it comes to our development and test processes. Recently we introduced a new automated build and testing process that fully tests a suite of conditions we look for on a regular basis for our upcoming releases. In the midst of these changes, we introduced a problem in how our source control system functions and ended up merging an old unfixed source file into our release code. The result was that the fixes in our <a href="http://www.scorpionsoft.com/blog/archives/2008/03/new_version_of_1.html" target="_blank">March 3rd release</a> were lost in the latest v1.6 build. The code itself wasn't actually lost and was properly secured in our source control vault; we simply had to remove the stale file and reapply the fix with the good file. </p>

<p>In discussion with some of my peers at other software companies serving the SMB space, most of them said I should simply release the fix quietly and move on. I don't think that is fair to our clients. I think you should know when we make a mistake like this. And more importantly, I think you should know what we have done about it. Here is a list of the outcomes from this experience:</p>

<p><UL><LI>We have updated our stable build system to ensure it can no longer check out code except for its particular branch. Each major release will now include a complete file structure backup to match this to ensure we do not "break" old code.<br />
<LI>All critical bugs reported in the Defect Tracking System now must be accompanied with an automated functional test script. It is the responsibility of Customer Service to ensure that QA knows of the defect and that QA builds the appropriate test(s) for the developers before they are assigned the bug. If a test cannot be provided, a detailed manual test document must be included.<br />
<LI>No developer is allowed to check in code until it passes the automated test(s).<br />
<LI>Once the developer has checked in the code to fix a defect, the automated test will be merged into the automated test system that runs all daily tests, to ensure we do not reintroduce a bug. This in itself would have alerted us to our recent mistake, and prevented us from releasing it. <br />
<LI>Once a critical bug is fixed, it will be reviewed at the next team meeting to see if the <b>class of bug</b> may impact other parts of code. If so, the mandate at the company is to reduce those defects by following the above process over and over again until all code coverage is met.<br />
</UL>   </p>

<p>I'd like to thank our clients who have been patient with us as we investigated what happened here. The fix was actually done last week, but we have not released the fix until today so we could have time to completely understand how it occured, and ensure we properly addressed it.</p>

<p>You can download the latest version of the agent from our <a href="http://www.authanvil.com/upgradecenter/" target="_blank">Upgrade and Update Center</a> or through our <a href="http://www.authanvil.com/install/" target="_blank">Zero Media Install</a> website. </p>
]]></content:encoded>

</item>
<item>
<title>Using AuthAnvil to defend against the vile and villainy inside malware</title>
<description><![CDATA[<p>Recently I found a <a href="http://blog.sbsfaq.com/Lists/Posts/Post.aspx?ID=212">blog post</a> from one of our customers that had some interesting comments on their use of AuthAnvil. In the midst of having to battle a badly infected computer, Wayne Small provided his insights on how valuable AuthAnvil is to him.  Here is clipping of what he had to say...</p>

<blockquote>Ok - this is one bad ass piece of malware on this computer. The issue here is that I don't truly know what the malware on this computer will do now. It could contain a keylogger which is capturing every keystroke I type.  Hmm - this is a risk now as anything I do it may be logged.  The malware was also obviously preventing me from getting to the known sites to get the things I needed to fix this problem.  So I thought I'll connect back to my SBS server which is fully protected and I guessed that the malware would not know about my URLs etc.  The risk though was that the keylogger might capture my passwords!  Again this did not bother me as my servers are protected with two factor authentication by AuthAnvil.  I have a cool key token which generates one time password that means even if the keylogger captures my password it is totally useless.</blockquote> 

<p>Wayne brings up a good point. When working at servers and workstations that you cannot trust, you have to expect that your keystrokes may be monitored. Have you considered just how many places that may be in any given day? Think about it... how many times have you logged onto a trusted system from an untrusted host? How are you defending against this threat?</p>

<p>Wayne mentioned one part which I think is a great testimonial for AuthAnvil...</p>

<blockquote>AuthAnvil made it easy today for me to ensure that my password was protected while I was dealing with a spyware infected system.</blockquote>

<p>Thanks for the testimonial Wayne! If you meant it or not... we really appreciate it.</p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/08/using_authanvil.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/08/using_authanvil.html</guid>
<category>Customer Focus</category>
<pubDate>Sun, 03 Aug 2008 11:01:54 -0800</pubDate>
<content:encoded><![CDATA[<p>Recently I found a <a href="http://blog.sbsfaq.com/Lists/Posts/Post.aspx?ID=212">blog post</a> from one of our customers that had some interesting comments on their use of AuthAnvil. In the midst of having to battle a badly infected computer, Wayne Small provided his insights on how valuable AuthAnvil is to him.  Here is clipping of what he had to say...</p>

<blockquote>Ok - this is one bad ass piece of malware on this computer. The issue here is that I don't truly know what the malware on this computer will do now. It could contain a keylogger which is capturing every keystroke I type.  Hmm - this is a risk now as anything I do it may be logged.  The malware was also obviously preventing me from getting to the known sites to get the things I needed to fix this problem.  So I thought I'll connect back to my SBS server which is fully protected and I guessed that the malware would not know about my URLs etc.  The risk though was that the keylogger might capture my passwords!  Again this did not bother me as my servers are protected with two factor authentication by AuthAnvil.  I have a cool key token which generates one time password that means even if the keylogger captures my password it is totally useless.</blockquote> 

<p>Wayne brings up a good point. When working at servers and workstations that you cannot trust, you have to expect that your keystrokes may be monitored. Have you considered just how many places that may be in any given day? Think about it... how many times have you logged onto a trusted system from an untrusted host? How are you defending against this threat?</p>

<p>Wayne mentioned one part which I think is a great testimonial for AuthAnvil...</p>

<blockquote>AuthAnvil made it easy today for me to ensure that my password was protected while I was dealing with a spyware infected system.</blockquote>

<p>Thanks for the testimonial Wayne! If you meant it or not... we really appreciate it.</p>
]]></content:encoded>

</item>
<item>
<title>Scorpion Software will be closed for British Columbia Day</title>
<description><![CDATA[<p>On Monday, August 4th, all of British Columbia will be celebrating <a href="http://en.wikipedia.org/wiki/British_Columbia_Day">British Columbia Day</a>. This is a Civic Holiday (with different names) celebrated across Canada on the first Monday of August each year.</p>

<p>As a result, Scorpion Software will be closed Monday, with staff celebrating the holiday with their families. </p>

<p>To those celebrating, we hope you have a safe and enjoyable holiday!</p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/08/scorpion_softwa_12.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/08/scorpion_softwa_12.html</guid>
<category>Events</category>
<pubDate>Fri, 01 Aug 2008 14:23:58 -0800</pubDate>
<content:encoded><![CDATA[<p>On Monday, August 4th, all of British Columbia will be celebrating <a href="http://en.wikipedia.org/wiki/British_Columbia_Day">British Columbia Day</a>. This is a Civic Holiday (with different names) celebrated across Canada on the first Monday of August each year.</p>

<p>As a result, Scorpion Software will be closed Monday, with staff celebrating the holiday with their families. </p>

<p>To those celebrating, we hope you have a safe and enjoyable holiday!</p>
]]></content:encoded>

</item>
<item>
<title>Major update of the AuthAnvil Windows Logon Agent released</title>
<description><![CDATA[<p>For those customers who are deploying strong authentication with AuthAnvil to their Windows XP workstations and Windows Server 2003 servers, today we have released a new version of the AuthAnvil Windows Logon Agent which adds the following new features:</p>

<p><UL><LI>Provides for the ability to provide your own brand on the logon dialog for our AuthAnvil Certified Partners<br />
<LI>Allows for silent mode install for batch/remote installation<br />
<LI>Allows for Active Directory Software Deployment policies of the agent (via MSI) for our AuthAnvil Certified Partners<br />
<LI>Allows for configuration to require a password to uninstall the agent<br />
<LI>No longer requires the AuthAnvil DCOM Bridge!!<br />
</UL></p>

<p>The last item is the big one for us. The elimination of the AuthAnvil DCOM Bridge will prevent the most common support case we get at Scorpion Software, which is people inadvertantly installing the agent BEFORE installing the DCOM Bridge, even though the documentation is very clear on the proper order of things. By no longer needing the DCOM Bridge, we can also now more easily deploy the agent in an automated way for those clients who wish to do so.</p>

<p>You can download the latest version of the agent from our <a href="http://www.authanvil.com/upgradecenter/" target="_blank">Upgrade and Update Center</a> or through our <a href="http://www.authanvil.com/install/" target="_blank">Zero Media Install</a> website. </p>

<p>You can get the latest version of the AuthAnvil Windows Logon Agent Implementation Guide (which has a new Appendix describing the silent mode options now supported) <a href="https://secure.authanvil.com/ContentLibrary/default.aspx?file=AAWindowsLogon-Implementation-Guide-v3.pdf" target="_blank">here</a>. </p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/07/major_update_of.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/07/major_update_of.html</guid>
<category>Product News</category>
<pubDate>Thu, 31 Jul 2008 10:08:53 -0800</pubDate>
<content:encoded><![CDATA[<p>For those customers who are deploying strong authentication with AuthAnvil to their Windows XP workstations and Windows Server 2003 servers, today we have released a new version of the AuthAnvil Windows Logon Agent which adds the following new features:</p>

<p><UL><LI>Provides for the ability to provide your own brand on the logon dialog for our AuthAnvil Certified Partners<br />
<LI>Allows for silent mode install for batch/remote installation<br />
<LI>Allows for Active Directory Software Deployment policies of the agent (via MSI) for our AuthAnvil Certified Partners<br />
<LI>Allows for configuration to require a password to uninstall the agent<br />
<LI>No longer requires the AuthAnvil DCOM Bridge!!<br />
</UL></p>

<p>The last item is the big one for us. The elimination of the AuthAnvil DCOM Bridge will prevent the most common support case we get at Scorpion Software, which is people inadvertantly installing the agent BEFORE installing the DCOM Bridge, even though the documentation is very clear on the proper order of things. By no longer needing the DCOM Bridge, we can also now more easily deploy the agent in an automated way for those clients who wish to do so.</p>

<p>You can download the latest version of the agent from our <a href="http://www.authanvil.com/upgradecenter/" target="_blank">Upgrade and Update Center</a> or through our <a href="http://www.authanvil.com/install/" target="_blank">Zero Media Install</a> website. </p>

<p>You can get the latest version of the AuthAnvil Windows Logon Agent Implementation Guide (which has a new Appendix describing the silent mode options now supported) <a href="https://secure.authanvil.com/ContentLibrary/default.aspx?file=AAWindowsLogon-Implementation-Guide-v3.pdf" target="_blank">here</a>. </p>
]]></content:encoded>

</item>
<item>
<title>On-Demand Authentication for the SMB</title>
<description><![CDATA[<p>Last week Vlad Mazek, CEO of Own Web Now, <a href="http://www.ownwebnow.com/blog/2008/07/own-and-scorpion-software-team-up-for-an-affordable-password-protection/" target="_blank">announced</a> that they were now offering on-demand two-factor authentication services using our <a href="http://www.AuthAnvil.com" target="_blank">AuthAnvil</a> platform as the base.</p>

<p>This is an exciting opportunity for the SMB, as you can now get a resilient two-factor authentication solution pre-installed and running in a dedicated data farm anywhere in the world, for less than $20/month per user. No signup fees. No need to pay for tokens in advance. No need to setup and configure a server to run our software. It just "works", out of the box. From one user to thousands, you can now get the on-demand authentication you deserve.</p>

<p>With Own Web Now having multiple data centers in the US, and two new ones in London UK and Sydney Australia, you can expect to get the intercontinental redundancy you would expect from such a service. From the experts who know how to build such powerful cloud infrastructure. Using software built by the experts in strong authentication for small business.</p>

<p>And the greatest thing is, this new two-factor authentication system is being built in to all their services. So now you can have the option to get two-factor authentication in Outlook Web Access 2007 for Exchange, in Sharepoint 2007 and in their CRM and service management platforms. And there are new services we are currently building with them that we expect to release later this year that will extend that even further in the cloud.</p>

<p>Vlad invited me on his company's podcast where we discuss this new opportunity for the SMB. As Vlad pointed out on the company blog:</p>

<blockquote>We are extremely excited to offer this solution at just $20/user/month because it breaks the pricing barrier that kept this type of an offering from becoming mainstream in SMB. With more mobility, more cloud services, more people involved in IT systems management, two factor authentication is something to discuss with your prospects, clients, staff and bosses. Tune in and listen to us address many security pain points and how we believe this announcement solves them.</blockquote>

<p><a href="http://www.ownwebnow.com/media/own-partner-call-5.mp3" target="_blank">Click here to download the podcast, runtime 50 minutes.</a></p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/07/ondemand_authen.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/07/ondemand_authen.html</guid>
<category>Product News</category>
<pubDate>Mon, 21 Jul 2008 10:00:36 -0800</pubDate>
<content:encoded><![CDATA[<p>Last week Vlad Mazek, CEO of Own Web Now, <a href="http://www.ownwebnow.com/blog/2008/07/own-and-scorpion-software-team-up-for-an-affordable-password-protection/" target="_blank">announced</a> that they were now offering on-demand two-factor authentication services using our <a href="http://www.AuthAnvil.com" target="_blank">AuthAnvil</a> platform as the base.</p>

<p>This is an exciting opportunity for the SMB, as you can now get a resilient two-factor authentication solution pre-installed and running in a dedicated data farm anywhere in the world, for less than $20/month per user. No signup fees. No need to pay for tokens in advance. No need to setup and configure a server to run our software. It just "works", out of the box. From one user to thousands, you can now get the on-demand authentication you deserve.</p>

<p>With Own Web Now having multiple data centers in the US, and two new ones in London UK and Sydney Australia, you can expect to get the intercontinental redundancy you would expect from such a service. From the experts who know how to build such powerful cloud infrastructure. Using software built by the experts in strong authentication for small business.</p>

<p>And the greatest thing is, this new two-factor authentication system is being built in to all their services. So now you can have the option to get two-factor authentication in Outlook Web Access 2007 for Exchange, in Sharepoint 2007 and in their CRM and service management platforms. And there are new services we are currently building with them that we expect to release later this year that will extend that even further in the cloud.</p>

<p>Vlad invited me on his company's podcast where we discuss this new opportunity for the SMB. As Vlad pointed out on the company blog:</p>

<blockquote>We are extremely excited to offer this solution at just $20/user/month because it breaks the pricing barrier that kept this type of an offering from becoming mainstream in SMB. With more mobility, more cloud services, more people involved in IT systems management, two factor authentication is something to discuss with your prospects, clients, staff and bosses. Tune in and listen to us address many security pain points and how we believe this announcement solves them.</blockquote>

<p><a href="http://www.ownwebnow.com/media/own-partner-call-5.mp3" target="_blank">Click here to download the podcast, runtime 50 minutes.</a></p>
]]></content:encoded>
<enclosure url="http://www.ownwebnow.com/media/own-partner-call-5.mp3" length="47341698" type="audio/mpeg" />
</item>
<item>
<title>Whitepaper: The Five Failings of Password Security, and How you can Handle It</title>
<description><![CDATA[<p>Password security is one of the weakest forms of user authentication in the industry. Yet businesses continue to use passwords to protect their most important corporate data. These passwords are the keys you use to access your personal and corporate data anywhere in the world. It might be for accounts local on your computer, or could be your confidential customer data that may be hosted with a provider online. They are used everywhere, which has been a great advantage to business productivity and access, while at the same time also becoming a great liability. </p>

<p>Download our latest white paper to learn why passwords alone may be a large risk to your business, and show how two-factor authentication and identity assurance can help to protect your business against attacks to weak, shared or stolen passwords.</p>

<p>You can download it <a href="https://secure.authanvil.com/ContentLibrary/default.aspx?file=AAWP-TheFiveFailingsOfPasswordSecurity.pdf">here</a>.<br />
</p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/07/whitepaper_the.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/07/whitepaper_the.html</guid>
<category>In the Trenches</category>
<pubDate>Thu, 17 Jul 2008 13:09:10 -0800</pubDate>
<content:encoded><![CDATA[<p>Password security is one of the weakest forms of user authentication in the industry. Yet businesses continue to use passwords to protect their most important corporate data. These passwords are the keys you use to access your personal and corporate data anywhere in the world. It might be for accounts local on your computer, or could be your confidential customer data that may be hosted with a provider online. They are used everywhere, which has been a great advantage to business productivity and access, while at the same time also becoming a great liability. </p>

<p>Download our latest white paper to learn why passwords alone may be a large risk to your business, and show how two-factor authentication and identity assurance can help to protect your business against attacks to weak, shared or stolen passwords.</p>

<p>You can download it <a href="https://secure.authanvil.com/ContentLibrary/default.aspx?file=AAWP-TheFiveFailingsOfPasswordSecurity.pdf">here</a>.<br />
</p>
]]></content:encoded>

</item>
<item>
<title>Scorpion Software&apos;s office will be closed for Canada Day</title>
<description><![CDATA[<p>On Tuesday, July 1st, all of Canada will be celebrating <a href="http://en.wikipedia.org/wiki/Canada_Day" target="_blank">Canada Day</a>. This is a national statutory holiday celebrating the birthday of our great country. </p>

<p>As a result, Scorpion Software will be closed Tuesday, with staff celebrating the holiday with their families. </p>

<p>To those celebrating, we hope you have a safe and enjoyable holiday!</p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/06/scorpion_softwa_11.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/06/scorpion_softwa_11.html</guid>
<category></category>
<pubDate>Mon, 30 Jun 2008 10:33:51 -0800</pubDate>
<content:encoded><![CDATA[<p>On Tuesday, July 1st, all of Canada will be celebrating <a href="http://en.wikipedia.org/wiki/Canada_Day" target="_blank">Canada Day</a>. This is a national statutory holiday celebrating the birthday of our great country. </p>

<p>As a result, Scorpion Software will be closed Tuesday, with staff celebrating the holiday with their families. </p>

<p>To those celebrating, we hope you have a safe and enjoyable holiday!</p>
]]></content:encoded>

</item>
<item>
<title>Are you a fan of AuthAnvil?</title>
<description><![CDATA[<p>At Scorpion Software, we have amazing customers. The amount of positive feedback we get from happy clients amazes me at times. Sometimes, they are just one liners like:</p>

<blockquote>Why didn't I know about you years ago... AuthAnvil is awesome.</blockquote>

<p>or</p>

<blockquote>What a simple and elegant solution!</blockquote>

<p>You don't normally think of security solutions like two-factor authentication as simple and elegant. But our clients say time and time again about how easy it is to deploy and use. I just love this sort of feedback!</p>

<p>If there is one criticism I think I can make about Scorpion Software, it is the fact we haven't been doing a good job leveraging this. We do most of our business through word of mouth, but we haven't put the right effort to make sure OTHER people know about what is going on.</p>

<p>So we are going to do something about that. This summer you will see a shift as we start talking more with our customers and getting THEM to talk about their experience. How? We aren't entirely sure yet. It is a great experiment. We are going to try everything from blogs and case studies to customer testimonals and video interviews.</p>

<p>The first thing we are going to do is see how social networking applies to business. So starting today, I am announcing the <a href="http://www.facebook.com/pages/AuthAnvil/30294689928?ref=share" target="_blank">AuthAnvil Fan Page</a> on Facebook. In sync with our efforts with the <a href="http://apps.facebook.com/visabusiness/general/about_network" target="_blank">Visa Business Network</a> for Small Business on Facebook, it is a place for the AuthAnvil community to gather and share their experiences with our product. With the capacity to post videos, write notes and share pictures, I am hoping you will join us in letting the world at large know what AuthAnvil is about. How it helps you. And why you're a fan.</p>

<p>So are you a fan? If so, <a href="http://www.facebook.com/pages/AuthAnvil/30294689928?ref=share" target="_blank">become a fan</a> of AuthAnvil on Facebook! </p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/06/are_you_a_fan_o.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/06/are_you_a_fan_o.html</guid>
<category>Customer Focus</category>
<pubDate>Sun, 29 Jun 2008 13:15:39 -0800</pubDate>
<content:encoded><![CDATA[<p>At Scorpion Software, we have amazing customers. The amount of positive feedback we get from happy clients amazes me at times. Sometimes, they are just one liners like:</p>

<blockquote>Why didn't I know about you years ago... AuthAnvil is awesome.</blockquote>

<p>or</p>

<blockquote>What a simple and elegant solution!</blockquote>

<p>You don't normally think of security solutions like two-factor authentication as simple and elegant. But our clients say time and time again about how easy it is to deploy and use. I just love this sort of feedback!</p>

<p>If there is one criticism I think I can make about Scorpion Software, it is the fact we haven't been doing a good job leveraging this. We do most of our business through word of mouth, but we haven't put the right effort to make sure OTHER people know about what is going on.</p>

<p>So we are going to do something about that. This summer you will see a shift as we start talking more with our customers and getting THEM to talk about their experience. How? We aren't entirely sure yet. It is a great experiment. We are going to try everything from blogs and case studies to customer testimonals and video interviews.</p>

<p>The first thing we are going to do is see how social networking applies to business. So starting today, I am announcing the <a href="http://www.facebook.com/pages/AuthAnvil/30294689928?ref=share" target="_blank">AuthAnvil Fan Page</a> on Facebook. In sync with our efforts with the <a href="http://apps.facebook.com/visabusiness/general/about_network" target="_blank">Visa Business Network</a> for Small Business on Facebook, it is a place for the AuthAnvil community to gather and share their experiences with our product. With the capacity to post videos, write notes and share pictures, I am hoping you will join us in letting the world at large know what AuthAnvil is about. How it helps you. And why you're a fan.</p>

<p>So are you a fan? If so, <a href="http://www.facebook.com/pages/AuthAnvil/30294689928?ref=share" target="_blank">become a fan</a> of AuthAnvil on Facebook! </p>
]]></content:encoded>

</item>
<item>
<title>AuthAnvil RADIUS Server gains Active Directory Awareness</title>
<description><![CDATA[<p>For those customers who are deploying strong authentication with AuthAnvil using RADIUS, today we are excited to release a new version of the AuthAnvil RADIUS Server (v1.5.6.4) which adds a lot more functionality and increases the effective use of our product.</p>

<p>With this release, the AuthAnvil RADIUS Server (AARS) now includes Active Directory integration that allows you to:<br />
<UL><LI>Limit RADIUS access to a specific Active Directory Security Group.<br />
<LI>Offers the ability to fail over to try a Windows authentication if the user is not a member of the RADIUS group.<br />
<LI>Respect if a Windows account is disabled. If it is, it won't allow a user to log on. In this way, even if an administrator forgets to disable the user's token in AuthAnvil, but does delete or disable his account in AD... the user won't get in.<br />
<LI>Check the "Remote Access Permission" dial-in privilege and respect it if it's set in the user's account. <br />
</UL></p>

<p>By making this addition, it is now possible to scale the deployment of AuthAnvil in RADIUS environments and focus on subsets of users who may be at higher risk when remotely connecting to the office, and whom should require two-factor authentication. We have also added the ability to support RADIUS Proxy-State, which means you can further control this in conjunction with other RADIUS servers such as Microsoft's IAS server to provide realm or domain level proxying to the AARS.</p>

<p>This new engineering change also delivers an added benefit. For many entry level firewalls that support RADIUS but not LDAP, it is now possible to provide Active Directory awareness to the device through AARS. This makes it much more cost effective to add the AD awareness without having to reinvest in new network hardware.</p>

<p>Many thanks to Derek Kuhr from <a href="http://www.heartlandtechnologies.com/" target="_blank">Heartland Technology Solutions</a> for the investment of his time to listen to our design decisions and give us feedback on the architectural changes. His input was vital in helping us to determine the most effective way to provide AD integration and support common Sonicwall and Cisco VPN concentrators and firewalls that are used in the SMB market. </p>

<p>You can download the latest version of the agent from our <a href="http://www.authanvil.com/upgradecenter/" target="_blank">Upgrade and Update Center</a> or through our <a href="http://www.authanvil.com/install/" target="_blank">Zero Media Install</a> website. </p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/06/authanvil_radiu.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/06/authanvil_radiu.html</guid>
<category>Product News</category>
<pubDate>Mon, 23 Jun 2008 15:05:09 -0800</pubDate>
<content:encoded><![CDATA[<p>For those customers who are deploying strong authentication with AuthAnvil using RADIUS, today we are excited to release a new version of the AuthAnvil RADIUS Server (v1.5.6.4) which adds a lot more functionality and increases the effective use of our product.</p>

<p>With this release, the AuthAnvil RADIUS Server (AARS) now includes Active Directory integration that allows you to:<br />
<UL><LI>Limit RADIUS access to a specific Active Directory Security Group.<br />
<LI>Offers the ability to fail over to try a Windows authentication if the user is not a member of the RADIUS group.<br />
<LI>Respect if a Windows account is disabled. If it is, it won't allow a user to log on. In this way, even if an administrator forgets to disable the user's token in AuthAnvil, but does delete or disable his account in AD... the user won't get in.<br />
<LI>Check the "Remote Access Permission" dial-in privilege and respect it if it's set in the user's account. <br />
</UL></p>

<p>By making this addition, it is now possible to scale the deployment of AuthAnvil in RADIUS environments and focus on subsets of users who may be at higher risk when remotely connecting to the office, and whom should require two-factor authentication. We have also added the ability to support RADIUS Proxy-State, which means you can further control this in conjunction with other RADIUS servers such as Microsoft's IAS server to provide realm or domain level proxying to the AARS.</p>

<p>This new engineering change also delivers an added benefit. For many entry level firewalls that support RADIUS but not LDAP, it is now possible to provide Active Directory awareness to the device through AARS. This makes it much more cost effective to add the AD awareness without having to reinvest in new network hardware.</p>

<p>Many thanks to Derek Kuhr from <a href="http://www.heartlandtechnologies.com/" target="_blank">Heartland Technology Solutions</a> for the investment of his time to listen to our design decisions and give us feedback on the architectural changes. His input was vital in helping us to determine the most effective way to provide AD integration and support common Sonicwall and Cisco VPN concentrators and firewalls that are used in the SMB market. </p>

<p>You can download the latest version of the agent from our <a href="http://www.authanvil.com/upgradecenter/" target="_blank">Upgrade and Update Center</a> or through our <a href="http://www.authanvil.com/install/" target="_blank">Zero Media Install</a> website. </p>
]]></content:encoded>

</item>
<item>
<title>Update to the AuthAnvil RADIUS Server released</title>
<description><![CDATA[<p>For those customers who are deploying strong authentication with AuthAnvil using RADIUS, today we have released a new version of the AuthAnvil RADIUS Server (v1.5.4.1) which fixes a couple of bugs and resolves a few known issues, including:</p>

<p><UL><LI>You no longer have to remove the domain name in Connection Manager when connecting to SBS servers.<br />
<LI>You no longer receive an async UDP socket error if you send multiple login requests at the same time from the same IP.<br />
<LI>You can now use periods, underscores and underlines in the username.<br />
<LI>The aaradiustest tool exception handling has been refactored to handle more general usage.<br />
<LI>There have been performance improvements in the initial handshaking.<br />
</UL></p>

<p>You can download the latest version of the agent from our <a href="http://www.authanvil.com/upgradecenter/" target="_blank">Upgrade and Update Center</a> or through our <a href="http://www.authanvil.com/install/" target="_blank">Zero Menu Install</a> website. </p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/05/update_to_the_a.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/05/update_to_the_a.html</guid>
<category>Product News</category>
<pubDate>Thu, 29 May 2008 13:53:16 -0800</pubDate>
<content:encoded><![CDATA[<p>For those customers who are deploying strong authentication with AuthAnvil using RADIUS, today we have released a new version of the AuthAnvil RADIUS Server (v1.5.4.1) which fixes a couple of bugs and resolves a few known issues, including:</p>

<p><UL><LI>You no longer have to remove the domain name in Connection Manager when connecting to SBS servers.<br />
<LI>You no longer receive an async UDP socket error if you send multiple login requests at the same time from the same IP.<br />
<LI>You can now use periods, underscores and underlines in the username.<br />
<LI>The aaradiustest tool exception handling has been refactored to handle more general usage.<br />
<LI>There have been performance improvements in the initial handshaking.<br />
</UL></p>

<p>You can download the latest version of the agent from our <a href="http://www.authanvil.com/upgradecenter/" target="_blank">Upgrade and Update Center</a> or through our <a href="http://www.authanvil.com/install/" target="_blank">Zero Menu Install</a> website. </p>
]]></content:encoded>

</item>
<item>
<title>Participate in our AuthAnvil Product Integration Survey</title>
<description><![CDATA[<p>This invitation is to participate in our <B>extremely short</B> product integration survey to enable us to better understand what software you use on a regular basis. The results from this survey will help us to plan product integration strategies with fellow software vendors who are interested in adding more security and value into their own offerings.<br />
 <br />
We cannot promise will we get AuthAnvil authentication integrated into all these products. However, your feedback will help us to communicate your interest with these vendors, and allow us to determine where we should focus our efforts. Imagine using your AuthAnvil token to log into all your LOB applications you use on a regular basis!<br />
 <br />
Your feedback is invaluable to us, and we thank you in advance for your help.  </p>

<p><CENTER><a href="http://survey.constantcontact.com/survey/a07e2aytmt2fgs8y59m/start " target="_blank"><FONT SIZE=+1>Take this survey ></FONT></a></CENTER></p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/05/participate_in.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/05/participate_in.html</guid>
<category>In the Trenches</category>
<pubDate>Wed, 28 May 2008 12:51:21 -0800</pubDate>
<content:encoded><![CDATA[<p>This invitation is to participate in our <B>extremely short</B> product integration survey to enable us to better understand what software you use on a regular basis. The results from this survey will help us to plan product integration strategies with fellow software vendors who are interested in adding more security and value into their own offerings.<br />
 <br />
We cannot promise will we get AuthAnvil authentication integrated into all these products. However, your feedback will help us to communicate your interest with these vendors, and allow us to determine where we should focus our efforts. Imagine using your AuthAnvil token to log into all your LOB applications you use on a regular basis!<br />
 <br />
Your feedback is invaluable to us, and we thank you in advance for your help.  </p>

<p><CENTER><a href="http://survey.constantcontact.com/survey/a07e2aytmt2fgs8y59m/start " target="_blank"><FONT SIZE=+1>Take this survey ></FONT></a></CENTER></p>
]]></content:encoded>

</item>
<item>
<title>Preventing administrator access to RWW with AuthAnvil RWWProtect</title>
<description><![CDATA[<p>For those people that didn't tune into the <a href="http://www.scorpionsoft.com/blog/archives/2008/05/tune_in_to_my_i.html" target="_blank">radio broadcast</a> last week, Scorpion Software released a FREE tool to the community called "AuthAnvil RWWProtect" that allows better control of administrative logon behaviour for Small Business Server's Remote Web Workplace (RWW). Included in this is easier to understand logging for RWW, and the ability to also add two-factor authentication (2FA) to RWW for administrators if you wish to.</p>

<p>My favorite quote from the community comes from Kerry Brown, who after hearing about RWWProtect sent an email to me that simply said:</p>

<blockquote>
Thank you Dana! I have a couple of servers that are being hammered on RWW
very early every morning for a couple of hours. Every morning I have to
figure out where it's coming from and block the IP. Now I don't have to wade
through firewall logs to find the IP and I can block admin access. Thank
you, thank you.
</BLOCKQUOTE>

<p>So if you want to prevent administrators from logging into your network via RWW, then feel free to download your own copy today. It is absolutely free. Of course, if you also want to add 2FA, you might want to check out our AuthAnvil product at <a href="http://www.authanvil.com" target="_blank">www.authanvil.com</a>. (In case you aren't a customer already :-) )</p>

<p>You can check out <a href="http://www.authanvil.com/rwwprotect/" target="_blank">AuthAnvil RWWProtect here</a>.</p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/05/preventing_admi.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/05/preventing_admi.html</guid>
<category>Product News</category>
<pubDate>Tue, 27 May 2008 17:25:05 -0800</pubDate>
<content:encoded><![CDATA[<p>For those people that didn't tune into the <a href="http://www.scorpionsoft.com/blog/archives/2008/05/tune_in_to_my_i.html" target="_blank">radio broadcast</a> last week, Scorpion Software released a FREE tool to the community called "AuthAnvil RWWProtect" that allows better control of administrative logon behaviour for Small Business Server's Remote Web Workplace (RWW). Included in this is easier to understand logging for RWW, and the ability to also add two-factor authentication (2FA) to RWW for administrators if you wish to.</p>

<p>My favorite quote from the community comes from Kerry Brown, who after hearing about RWWProtect sent an email to me that simply said:</p>

<blockquote>
Thank you Dana! I have a couple of servers that are being hammered on RWW
very early every morning for a couple of hours. Every morning I have to
figure out where it's coming from and block the IP. Now I don't have to wade
through firewall logs to find the IP and I can block admin access. Thank
you, thank you.
</BLOCKQUOTE>

<p>So if you want to prevent administrators from logging into your network via RWW, then feel free to download your own copy today. It is absolutely free. Of course, if you also want to add 2FA, you might want to check out our AuthAnvil product at <a href="http://www.authanvil.com" target="_blank">www.authanvil.com</a>. (In case you aren't a customer already :-) )</p>

<p>You can check out <a href="http://www.authanvil.com/rwwprotect/" target="_blank">AuthAnvil RWWProtect here</a>.</p>
]]></content:encoded>

</item>
<item>
<title>Tune in to my interview on BlogTalk Radio tomorrow</title>
<description><![CDATA[<p>Stuart Crawford of IT Matters and host of the <a href="http://www.blogtalkradio.com/smb" target="_blank">SMB BlogTalk radio show</a> has invited me to come on his show tomorrow and talk about managing business risks in a remotely connected world. You can visit the <a href="http://www.blogtalkradio.com/smb/2008/05/23/managing-business-risk-in-a-remotely-connected-world" target="_blank">show site here</a> and set a reminder in your calendar. </p>

<p>This is going to be an interesting interview. On top of talking about remote access risk and how to reduce it with solutions like AuthAnvil, we are going to be making a special announcement that we believe many in the SMB community will really appreciate. You have to be tuned in to find out what it is :-)</p>
]]></description>
<link>http://www.scorpionsoft.com/blog/archives/2008/05/tune_in_to_my_i.html</link>
<guid>http://www.scorpionsoft.com/blog/archives/2008/05/tune_in_to_my_i.html</guid>
<category>Events</category>
<pubDate>Thu, 22 May 2008 09:09:18 -0800</pubDate>
<content:encoded><![CDATA[<p>Stuart Crawford of IT Matters and host of the <a href="http://www.blogtalkradio.com/smb" target="_blank">SMB BlogTalk radio show</a> has invited me to come on his show tomorrow and talk about managing business risks in a remotely connected world. You can visit the <a href="http://www.blogtalkradio.com/smb/2008/05/23/managing-business-risk-in-a-remotely-connected-world" target="_blank">show site here</a> and set a reminder in your calendar. </p>

<p>This is going to be an interesting interview. On top of talking about remote access risk and how to reduce it with solutions like AuthAnvil, we are going to be making a special announcement that we believe many in the SMB community will really appreciate. You have to be tuned in to find out what it is :-)</p>
]]></content:encoded>

</item>


</channel>
</rss>