Personal tools
You are here: Home wikidblog When phishing and stolen customer database information combine
« November 2008 »
Mo Tu We Th Fr Sa Su
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
 

When phishing and stolen customer database information combine

Check out this phish email from Virus List

We fully appreciated not only the expert social engineering and well-written text, but also the fact that the phisher included not only the email of the intended victim, but also the postal address.

While the analyst points out that users should never click on an email from a bank, I think it also points out the need for mutual authentication.

Further, I think that the way WiKID handles mutual authentication is much better than other solutions - beyond just the fact that WiKID uses a cryptographically secure approach. When a users get a WiKID one-time passcode, their default browser is automatically launched to the correct website and the SSL certificate is validated for them. This approach is far more reliable from a user-experience than relying on the user to recognize a change in the website or chrome. (IMHO).

The URL to Trackback this entry is:
http://www.wikidsystems.com/WiKIDBlog/when-phishing-and-stolen-customer-database-information-combine/tbping
Add comment

You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

(Required)
(Required)
(Required)
(Required)
This helps us prevent automated spamming.