Guide to the TechWeb Network






 




Two-Factor Authentication? Only on paper...
By Ivan Schneider
Nov 4, 2005 at 06:17 PM ET

Security firm F-Secure has the details of the phishing attack on Swedish bank Nordea, as well as several other informative entries in their security blog.

But in the debate about whether two-factor authentication, as mandated by the FFIEC in its recent guidance, will prove at all effective in actually stopping phishing, I believe that the Nordea example is a weak example of the vulnerability of the approach. Yes, there are ways to defeat two-factor authentication. But one of the least secure approaches to two-factor authentication is with a paper scratch-off ticket.

Compared with a token device that generates a changing code every 30 seconds, the Nordea solution was not particularly hard to beat, as it's just another password (albeit one that's hidden until use). To defeat the VASCO approach, for example, the hacker has to ride shotgun on the transaction through a Trojan horse or some kind of man-in-the-middle attack.

Just wanted to point that out for those of you evaluating which security vendors to use in order to comply with the FFIEC deadline.



Topics: What We're Reading
»  Weblog Main   |   »  View Entries By Topic   |   »  View Entries By Date



COMMENTS




This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in the message center do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this forum becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: The Message Center is NOT intended for commercial messages or solicitations of business.






















techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
Ed Cals  |  Contact Us  |  Reprints  |  Ad Info  |  Media Kit  |  Send Us Your Feedback  |  RSS