Personal tools
You are here: Home wikidblog MITM attacks, tokens vs phishing and mutual authentication
« August 2008 »
Mo Tu We Th Fr Sa Su
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Recent comments
Re:Security and Oil admin Apr 25, 2008
Re:Security and Oil Paul feet Apr 24, 2008
Re:100% open source admin Apr 22, 2008
Re:100% open source Adam Apr 22, 2008
Re:Capital Gains Tax Rates and Entrepreneurs Lance Oct 23, 2007
 

MITM attacks, tokens vs phishing and mutual authentication

Kurt at anti-virus rants has a pair of posts, one on what is man-in-the-middle attack and a follow up on why tokens won't stop phishing, which lead me to an earlier post on why safe site indicators fail.

My comments:

  • If the one-time passcodes are used to authentication transactions instead of sessions, they would stop phishing. Though it would be best to have both session and transaction authentication, especially for accounts that are difficult to analyze for fraudulent transactions such as commercial and brokerage accounts.
  • Good host authentication will probably require software on the client side, but banks are very reluctant to distribute software. This gives an edge to the bad guys who have no problem with distributing software whatsoever.
The URL to Trackback this entry is:
http://www.wikidsystems.com/WiKIDBlog/mitm-attacks-tokens-vs-phishing-and-mutual-authentication/tbping
Add comment

You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

(Required)
(Required)
(Required)
(Required)
This helps us prevent automated spamming.