Keyloggers: Why Banks Need Two-Factor Authentication


 
Thread Tools Search this Thread
Special Forums News, Links, Events and Announcements Complex Event Processing RSS News Keyloggers: Why Banks Need Two-Factor Authentication
# 1  
Old 01-14-2008
Keyloggers: Why Banks Need Two-Factor Authentication

Tim Bass
Mon, 14 Jan 2008 11:55:21 +0000

Recently I briefed banking executives*in Bangkok on how easy it is to steal userIDs and passwords from their on-line banking customers and why they*must have two-factor authentication.** To illustrate*my key*points, I showed*the captive audience*various pictures of hardware keyloggers, for example the small black keylogger circled in the figure below.
Image
There are PS2 keyloggers (illustrated above)*and USB keyloggers. There are even keyboards with the keyloggers built into normal looking keyboards, so you have no idea a keylogger is there.*** Don’t believe me?** You can search the net and find so many!
Today I was reminded about my recent meeting in this Network World article, Two-factor authentication: Hot technology for 2008.* This article mentions numerous token-based two-factor authentication (2FA) solutions.* However, it misses a popular and inexpensive two-factor authentication used here in Thailand and APAC:* SMS-based 2FA.
In a nutshell, SMS-based 2FA involves having your on-line banking system send an SMS message with a one-time password (OTP) to your cell phone.** You then must enter the OTP to complete your transaction.
Is this a perfect solution?
No.
But, it is much better than than just passwords!
A*ten year old child can easily steal your userID and password, really.
So, the next time you are at an Internet cafe, trusting your SSL link to your bank, don’t forget to take a peek at the computer and look for a small keylogger.***
Well, on the other hand, also don’t forget to bring your own keyboard Image
Image Image Image Image Image Image Image Image


Source...
Login or Register to Ask a Question

Previous Thread | Next Thread

5 More Discussions You Might Find Interesting

1. Cybersecurity

Two Factor Authentication – Best for the UNIX/Linux Server Security

The UNIX/Linux server security is challenging because these servers are at a risk of getting compromised at any point of time by the attackers. In today's enterprise environment, the UNIX and Linux servers are growing popular. With their increased popularity, these servers have become the primary... (1 Reply)
Discussion started by: reve-secure
1 Replies

2. HP-UX

Multi-factor authentication

Is anyone here familiar with implementing multi-factor authentication on HP-UX 11.31? Either with a PIV card, or with an RSA token? We've been tasked with implementing this on our servers, but I'm not finding much in the way of products or information. To complicate matters, our servers are... (6 Replies)
Discussion started by: lupin..the..3rd
6 Replies

3. UNIX for Dummies Questions & Answers

factor [start[stop]

Another question for you guys! This is so fun. So I am playing around with the factor operation. I read in "man factor" that you can actually print a list of primes in between a range, using the syntax factor ] However, every time I enter two values, it just returns the factored value.... (1 Reply)
Discussion started by: statichazard
1 Replies

4. UNIX for Dummies Questions & Answers

Which kind of UNIX to major investment banks use?

Hi, I would like to know what kind of UNIX major investment banks tend to use? I want to try to get a job with one of these places. By major, I mean big companies like Citigroup, JP Morgan Chase, Morgan Stanley, etc. Thanks. (5 Replies)
Discussion started by: rubrubber
5 Replies

5. Solaris

prtdiag and memory banks

hi, we have an e6900 and my sys admin says that the number of processors and memory were reduced to 4 and 8GB. However, a prtdiag |grep Memory returns 16GB of memory. So what is my system's memory? psrinfo returns 4 online and 4 offline CPUs. Thanks. Kumar (1 Reply)
Discussion started by: kumar27
1 Replies
Login or Register to Ask a Question