Personal tools
You are here: Home wikidblog Short-sighted critiques of two-factor authentication
« November 2008 »
Mo Tu We Th Fr Sa Su
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
 

Short-sighted critiques of two-factor authentication

There are two things to keep in mind when discussing two-factor authentication:

First, it is possible to use any one-time password system to authenticate transactions!. All you have to do is ask for an additional one-time passcode before you process the transaction. This is incredibly simple and would stop a good number of MITM attacks.

Second, don't think that all one-time password systems operate in an enclosed hardware case and will never be capable of cryptographically secure mutual authentication.

Cryptographers seem to think that if a solution fails one time it isn't worth using even though it stops 9 other attacks. You don't need to wipe out online fraud. What you need to do is maintain minimize the risks to an acceptable level and maintain the public's faith in the banking industry. If people start putting their money under their mattresses again, we're in for a big recession.



The URL to Trackback this entry is:
http://www.wikidsystems.com/WiKIDBlog/68/tbping

Re: Short-sighted critiques of two-factor authentication

Posted by Mitch Wagner at Oct 26, 2005 04:30 PM

Hmmm.... hard to see how that could be beaten.

What would be some examples of two-level authentication systems that don't require separate hardware that can be lost or can malfunction?

Re: Short-sighted critiques of two-factor authentication

Posted by Nick Owen at Oct 27, 2005 12:24 PM


As for examples of authentication systems that don't require hardware, look no further ;). WiKID can run on a Windows, Mac, Linux, Palm, PocketPC, J2ME, Blackberry etc. You can run it on a USB drive if you like.

The interesting thing about using a PC-based token that is network aware, such as WiKID, is that you can tackle the second problem mutual authentication. Expect some news on this front soon.

Re: Short-sighted critiques of two-factor authentication

Posted by Adam at Oct 29, 2005 10:47 AM
"Cryptographers seem to think that if a solution fails one time it isn't worth using even though it stops 9 other attacks."

The trouble is not that OTP stop 9 other attacks, its that they stop 9 other attacks by people who ignore the yellow tape. The most obvious attack is to present a "login failed, please try again in 60 seconds" message, and use the second time token to authenticate not the login, but the transaction.



Re: Short-sighted critiques of two-factor authentication

Posted by Nick at Nov 03, 2005 05:11 PM
Excellent free hint! Just so you know, we can solve this issue today.

With WiKID a bank can set up more than one WiKID 'domain' and a the token client can support more than one domain as well, even across servers. The bank sets up one domain for session authentication and another for transactions.

When the user logs in they are asked for a passcode from the "Bank Login" domain. When they try to process a risky transaction, they are asked for a passcode from the "Transactions" domain.
Add comment

You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

(Required)
(Required)
(Required)
(Required)
This helps us prevent automated spamming.