The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > News, Links, Events and Announcements > Complex Event Processing RSS News
Google UNIX.COM


Complex Event Processing RSS News Aggregated RSS news on CEP, ESP and EP.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
prtdiag and memory banks kumar27 SUN Solaris 1 02-13-2008 01:16 PM
The X Factor: Economic Recession Is the IT Innovator's Ally - IT Jungle iBot UNIX and Linux RSS News 0 08-22-2007 11:10 AM
chvg -t (factor size) - risk? spattson AIX 2 08-15-2006 07:01 PM
My partition disappeared!!!! URGENT!! (newbie factor) riwa UNIX for Dummies Questions & Answers 2 01-04-2006 12:40 PM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-14-2008
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,302
Stumble this Post!
Keyloggers: Why Banks Need Two-Factor Authentication

Tim Bass
Mon, 14 Jan 2008 11:55:21 +0000

Recently I briefed banking executives*in Bangkok on how easy it is to steal userIDs and passwords from their on-line banking customers and why they*must have two-factor authentication.** To illustrate*my key*points, I showed*the captive audience*various pictures of hardware keyloggers, for example the small black keylogger circled in the figure below.
There are PS2 keyloggers (illustrated above)*and USB keyloggers. There are even keyboards with the keyloggers built into normal looking keyboards, so you have no idea a keylogger is there.*** Don’t believe me?** You can search the net and find so many!
Today I was reminded about my recent meeting in this Network World article, Two-factor authentication: Hot technology for 2008.* This article mentions numerous token-based two-factor authentication (2FA) solutions.* However, it misses a popular and inexpensive two-factor authentication used here in Thailand and APAC:* SMS-based 2FA.
In a nutshell, SMS-based 2FA involves having your on-line banking system send an SMS message with a one-time password (OTP) to your cell phone.** You then must enter the OTP to complete your transaction.
Is this a perfect solution?
No.
But, it is much better than than just passwords!
A*ten year old child can easily steal your userID and password, really.
So, the next time you are at an Internet cafe, trusting your SSL link to your bank, don’t forget to take a peek at the computer and look for a small keylogger.***
Well, on the other hand, also don’t forget to bring your own keyboard



Source...
Reply With Quote
Google The UNIX and Linux Forums
Forum Sponsor
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 02:04 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0