Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Banks 'wasting millions' on two-factor authentication
John Leyden, The Register 2005-03-15

Banks are spending millions on two-factor authentication for their customers but the approach no longer provides adequate protection against fraud or identity theft, according to Bruce Schneier, the encryption guru.

Comments Mode:
I'd hardly call even a temporary drop in fraud "wasting millions" 2005-03-15
Bruce K. Marshall (3 replies)
I'd hardly call even a temporary drop in fraud "wasting millions" 2005-03-15
bwatson_at_nettracers.com
I disagree with a previous reply that there are solutions to MITM attacks. There are not!

Joe User has no idea how to authenticate the site that he is connecting to. Joe Geek does, and can use the available tools, but until you can have a computer independent method to authenticate the site that you have connected to, there is a big security hole.

Put another way, the bank can authenticate the user, but the user can't reliably authenticate the bank.

The bank needs to provide a security code that can only come from it. That code must go to a trusted secure and independent device (pretty GUI's can be easily faked, but a dongle in your pocket can't) that can authenticate the site in an obvious and foolproof way to a non-technical user.

Like a ward in a mental hospital, a computer system can't be relied upon to prove its own sanity/security.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/10694/30911#30911
SSL 2005-03-16
Rory Alsop
There is no solution though 2005-03-15
Anonymous
so called "expert" 2005-03-16
Anonymous (1 replies)
Re: so called "expert" 2005-11-18
twofish
It's too late.... 2005-03-16
en0k







 

Privacy Statement
Copyright 2009, SecurityFocus