Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Banks 'wasting millions' on two-factor authentication
John Leyden, The Register 2005-03-15

Banks are spending millions on two-factor authentication for their customers but the approach no longer provides adequate protection against fraud or identity theft, according to Bruce Schneier, the encryption guru.

Comments Mode:
I'd hardly call even a temporary drop in fraud "wasting millions" 2005-03-15
Bruce K. Marshall (3 replies)
SSL 2005-03-16
Rory Alsop
Sadly SSL is not a cure for MITM attacks. There are easy to use tools available on the Internet which allow the hijacking of SSL sessions, spoofing to redirect communications, and the easiest option - exploitation of the end user's PC (by Trojan or similar): compromise of the end point removes almost all layers of protection. SSL certainly becomes pointless in that scenario.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/10694/30930#30930
There is no solution though 2005-03-15
Anonymous
so called "expert" 2005-03-16
Anonymous (1 replies)
Re: so called "expert" 2005-11-18
twofish
It's too late.... 2005-03-16
en0k







 

Privacy Statement
Copyright 2009, SecurityFocus