<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>API Access Archives - Password RBL</title>
	<atom:link href="https://www.passwordrbl.com/blog/tag/apiaccess/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.passwordrbl.com/blog/tag/apiaccess/</link>
	<description>Real-time Password Blacklist</description>
	<lastBuildDate>Thu, 21 Dec 2023 04:14:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://www.passwordrbl.com/wp-content/uploads/2020/05/cropped-Special_SmallRes_White_Circle_cropped-32x32.png</url>
	<title>API Access Archives - Password RBL</title>
	<link>https://www.passwordrbl.com/blog/tag/apiaccess/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cybersecurity Attitudes and Behaviors Report</title>
		<link>https://www.passwordrbl.com/blog/cybersecurity-attitudes-and-behaviors-report-2021/</link>
		
		<dc:creator><![CDATA[PasswordRBL Staff]]></dc:creator>
		<pubDate>Sun, 17 Oct 2021 21:32:28 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Industry News]]></category>
		<category><![CDATA[API Access]]></category>
		<category><![CDATA[Password Firewall for Windows]]></category>
		<category><![CDATA[Tech News]]></category>
		<guid isPermaLink="false">https://www.passwordrbl.com/?p=80107</guid>

					<description><![CDATA[<p>The National Cybersecurity Alliance (NCSA) has released their Attitudes and Behaviors report for 2021, and, honestly, it&#8217;s not great.  Well, [&#8230;]</p>
<p>The post <a href="https://www.passwordrbl.com/blog/cybersecurity-attitudes-and-behaviors-report-2021/">Cybersecurity Attitudes and Behaviors Report</a> appeared first on <a href="https://www.passwordrbl.com">Password RBL</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The <a href="https://staysafeonline.org/" target="_blank" rel="noopener">National Cybersecurity Alliance (NCSA)</a> has released their <a href="https://staysafeonline.org/resource/oh-behave-2021/" target="_blank" rel="noopener">Attitudes and Behaviors report for 2021</a>, and, honestly, it&#8217;s not great.  Well, the reporting is great, and it&#8217;s great that the NCSA conducts and releases this annual report.  But the content of the report contains some not-so-great behaviors among real users.</p>
<h2>MFA</h2>
<p>As we know, Multi-Factor Authentication (MFA) is a great way to combat potential account takeovers or just general bad password hygiene.  Even when MFA is used, <a href="https://www.passwordrbl.com/blog/got-mfa-good-but-you-still-need-password-blacklisting/">Password Blacklisting still makes sense</a>.  But if MFA is not in use, then Password Blacklisting is an absolute must!   Unfortunately, the report found that 52% of people have never heard of MFA.  This makes enforcing strong passwords even more important.  But why is this?  Well, 64% say they have no access to MFA, and another 10% say they do have access MFA, but choose not to use it.</p>
<p>&nbsp;</p>
<h2>Responsibility</h2>
<p>Additionally, the data indicates a significant proportion of people simply do not see themselves as responsible for looking after their workplace’s sensitive information.  Over a third (40%) of the full-time and part-time employees participating in this report considered themselves to be the least responsible agency for their organization’s cybersecurity.  That means that nearly half of your employees don&#8217;t think it&#8217;s their responsibility to choose a strong password!  This statistic is alarming and makes the case for all businesses to deploy Password Blacklisting in order to prevent users from choosing poor passwords.</p>
<p>&nbsp;</p>
<h2>Passwords</h2>
<p>Speaking of passwords, the report also discovered some alarming, but simultaneously not surprising, statistics on real-life password behaviors.  Only 43% of participants reported creating long and unique passwords for their online accounts “very often” or “always”. However, almost a third (28%) stated that they didn’t do so.  A third of real-life users are knowingly choosing weak passwords!  That&#8217;s a big number!</p>
<p>But about the more middle-of-the-road, average password behavior.  It&#8217;s still not great.  A majority (58%) of the respondents say they only &#8220;sometimes&#8221; (30%), &#8220;rarely&#8221; (18%), or &#8220;never&#8221; (10%) create long (12 character) and unique passwords.  This is probably because use of a stand-alone password manager application, which would create these long unique passwords, was uncommon, with almost half (49%) of the participants noting they ‘never’ or ‘rarely’ used one.</p>
<p>&nbsp;</p>
<h2>Not Great.  But What To Do?</h2>
<p>The full Cybersecurity Attitudes and Behaviors report (<a href="https://staysafeonline.org/resource/oh-behave-2021/" target="_blank" rel="noopener">available here</a>) contains lots more information and statistics.  But even with just the few takeaways mentioned above, it&#8217;s clear that more work needs to be done.  Deployment of Multi-Factor Authentication would absolutely help, but by 2021, the reason MFA isn&#8217;t completely pervasive is because of many real-life problems, including end-user adoption woes, cost to the business, supportability, and definitely incomplete deployments since businesses commonly support legacy systems which have no concept of MFA &#8211; or anything other than usernames and passwords, really.</p>
<p>Enter Password Blacklisting &#8211; the incredibly affordable and easy to use solution to the bad password problem.  Password RBL has drop-in support for Microsoft Active Directory (and anything linked to AD) and a dead-simple API that can be incorporated into basically anything else.  The return on investment (ROI) of a subscription to Password RBL makes deployment an easy choice &#8211; for IT and decision makers.  See our <a href="https://www.passwordrbl.com/solutions/">solutions</a> in action and <a href="https://www.passwordrbl.com/request-a-quote/">request a free quote</a> today!</p>
<p>The post <a href="https://www.passwordrbl.com/blog/cybersecurity-attitudes-and-behaviors-report-2021/">Cybersecurity Attitudes and Behaviors Report</a> appeared first on <a href="https://www.passwordrbl.com">Password RBL</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New Versions of API and Password Firewall</title>
		<link>https://www.passwordrbl.com/blog/new-versions-of-api-and-password-firewall/</link>
		
		<dc:creator><![CDATA[PasswordRBL Staff]]></dc:creator>
		<pubDate>Sun, 04 Oct 2020 16:35:25 +0000</pubDate>
				<category><![CDATA[Password RBL News]]></category>
		<category><![CDATA[API Access]]></category>
		<category><![CDATA[Password Firewall for Windows]]></category>
		<guid isPermaLink="false">https://www.passwordrbl.com/?p=80019</guid>

					<description><![CDATA[<p>Password RBL is pleased to announce the next major versions of our products have been released for 2020-Q4.  This includes [&#8230;]</p>
<p>The post <a href="https://www.passwordrbl.com/blog/new-versions-of-api-and-password-firewall/">New Versions of API and Password Firewall</a> appeared first on <a href="https://www.passwordrbl.com">Password RBL</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Password RBL is pleased to announce the next major versions of our products have been released for 2020-Q4.  This includes API v4.00 and Password Firewall for Windows v7.00 to utilize the latest features available in the new API.</p>
<p>&nbsp;</p>
<h2>New Feature: An Additional Way to Query</h2>
<p>This major release all centers around one new core feature &#8211; an additional API endpoint that utilizes a customer-provided API Key to authorize connections to the API.  Using this API Key allows customers to query the API from anywhere, without first registering their IP address(es) with Password RBL.  Not only is API Key authorization easier for customers (because there is no extra IP address management task), but it also friendly to cloud-based infrastructure and services that do not necessarily maintain static IP addressing.  But just to be clear, this is a new API endpoint and the existing IP-authorized endpoint is still supported.</p>
<p>&nbsp;</p>
<h3>A Little History</h3>
<p>Previously, Password RBL&#8217;s API only authorized customer connections based upon their source IP address.  This was a design decision from the very beginning.  Password RBL has always been very focused on providing password blacklisting services in a zero-trust manner.  A cloud-based password blacklisting solution was new to the world back then, and we really wanted customers to understand that it really is secure.  So we choose to implement customer authorization by IP rather than API key.  API queries entering our service were confirmed to come from customers based on the packet&#8217;s source IP.  With the original architecture, by the time the query got passed network checks and load balancing, the API did not know which customer it was coming from (just that it was an authorized customer).  But once we added the Prefix-Query method (where queries only contain a portion of the password hash, not the entire hash), customers had even more assurance that even Password RBL could never determine the cleartext password from their API submission.  This opened the door to reconsidering a feature requested by many customers &#8211; API Key authorization.</p>
<p>&nbsp;</p>
<h3>A Quick Word on TLS versions</h3>
<p>This new key-based endpoint is a modern, new method of connectivity and thus, requires modern TLS connections &#8211; TLS v1.2 at a minimum.  It is important to note that Windows Server 2008 R2 does not have TLS v1.2 enabled by default.  In order for Password Firewall to run with API Key authorization on Windows 2008 R2, you must update .NET to latest patch release and then manually create some registry entries to enable the use of TLS v1.2.  There are many <a href="https://www.smarterasp.net/support/kb/a1968/how-to-fix-error-underlying-connection-was-closed-an-unexpected-error-occurred-on.aspx">guides</a> that you can follow.  Later versions of Windows supports TLS v1.2 by default.  Windows 2008 R2 is now End of Life so any 2008 R2 servers should be retired anyways (but we still support Password Firewall on Server 2008 R2 because we would rather you have strong passwords and an old server than bad passwords and an old server).</p>
<p>&nbsp;</p>
<h3>Download Today!</h3>
<p>The latest API is in production and the latest version of Password Firewall for Windows available now,  Head over to our <a href="https://www.passwordrbl.com/downloads/">downloads page</a> for the latest software and documentation.</p>
<p>&nbsp;</p>
<p>The post <a href="https://www.passwordrbl.com/blog/new-versions-of-api-and-password-firewall/">New Versions of API and Password Firewall</a> appeared first on <a href="https://www.passwordrbl.com">Password RBL</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
