Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Two-factor banking
Kelly Martin, 2005-10-18

People who lived through the Second World War, like my grandparents, had a very different view of money than those of us who grew up in the Information Age. Many of us still remember being told how foolish it is to keep one's life savings under a bed mattress, because the banks were known as trusted entities that will always do a better job of looking after your money. Even my grandparents, albeit reluctantly, came to realize that putting trust in financial institutions was the only way to go.

Comments Mode:
Two-factor banking 2005-10-18
Anonymous (3 replies)
Re: Two-factor banking 2005-10-19
Anonymous
Re: Two-factor banking 2005-10-20
Anonymous
Re: Two-factor banking 2006-04-13
Anonymous
Two-factor banking 2005-10-19
Todd Knarr (2 replies)
I have to disagree with your article. Two-factor authentication will, in my judgement, do nothing to significantly slow down phishing. People aren't caught by phishing because of weak authentication of them to their bank, they're caught because of non-existent authentication of their bank to them. Two-factor authentication does nothing to prove to me that the Web site accepting my authentication is really the bank I think I'm giving it to.

On the other hand, if I have strong authentication of the bank (say because SSL in the browser is set to demand the server authenticate itself and limited only to those certificates I got from my bank while setting up my account) then it becomes much safer to authenticate myself to the bank.

In the real world, demanding drivers' licenses of every customer in a physical bank branch doesn't help if the problem is criminals setting up fake branches. Why should it work any better on the Internet?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/363/32533#32533
Re: Two-factor banking 2005-10-19
Anonymous (1 replies)
Re: Re: Two-factor banking 2005-10-19
Todd Knarr (1 replies)
Re: Re: Re: Two-factor banking 2005-10-19
Anonymous (2 replies)
Re: Re: Re: Re: Two-factor banking 2005-10-22
Anonymous2
Re: Two-factor banking 2006-04-05
Anonymous
Two-factor banking 2005-10-19
Theuns (1 replies)
Re: Two-factor banking 2005-10-23
Anonymous
Two-factor banking 2005-10-19
tarun_the_nut
Two-factor banking 2005-10-19
Anonymous
Two-factor banking 2005-10-19
Anonymous (1 replies)
Re: Two-factor banking 2005-10-20
Anonymous (1 replies)
Re: Re: Two-factor banking 2005-10-31
Anonymous
Two-factor banking 2005-10-19
Anonymous (1 replies)
Re: Two-factor banking 2005-10-22
Anonymous
Two-factor banking 2005-10-19
Anonymous (1 replies)
Re: Two-factor banking 2005-10-20
Mitch F.
Two-factor banking 2005-10-19
HumbleOpinion
Two-factor banking 2005-10-19
Anonymous2 (1 replies)
Re: Two-factor banking 2005-10-19
Thor
Open source Two-factor banking 2005-10-19
Anonymous
Two-factor banking 2005-10-20
Anonymous
Two-factor banking 2005-10-20
Anonymous (1 replies)
Re: Two-factor banking 2005-10-23
Anonymous
Two-factor banking 2005-10-20
Anonymous (1 replies)
Re: Two-factor banking 2005-10-23
Anonymous
Two-factor banking 2005-10-20
Anonymous (3 replies)
Re: Two-factor banking 2005-10-21
Anonymous
Re: Two-factor banking 2005-10-21
Anonymous (1 replies)
Re: Re: Two-factor banking 2005-10-25
Anonymous
Re: Two-factor banking 2005-10-23
Anonymous (1 replies)
Re: Re: Two-factor banking 2005-10-26
Anonymous
Two-factor banking 2005-10-21
AP (1 replies)
Re: Two-factor banking 2005-11-01
Kelly Martin (author)
Two-factor banking 2005-10-22
Anonymous
Two-factor banking 2005-10-23
vmmello
Two-factor banking 2005-10-26
Alexey Vesnin
Two-factor banking 2006-03-20
Anonymous
Two-factor banking 2006-04-11
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus