11 Temmuz 2006 Salı

Two Factor Authentication Doesn't Foil Phishers

One of the major projects this year for all banks is to implement "two factor authentication." This means that a username and password (one factor) will not be enough to log into your financial institution in the future. You will also need either a special passcard/keyfob or need to provide extra proof of who you are. It is designed to make life harder for phishers and other hackers who want to steal your identity.

Unfortunately, it is not 100% effective. Some hackers are setting up sites that act as intermediaries between you and your bank. These sites pass your information to the bank and get your authorization, as you use your second factor to authenticate, and then take over and start siphoning money from your account.

What does this prove? That two-factor authentication is not enough. People still need to be vigilant to potential scams, and to always visit their bank via the approved URL, rather than thru a link someone sends you thru an e-mail. No smart bank will EVER ask you to visit their site via a link in an e-mail.

Hiç yorum yok:

Yorum Gönder