• On MovieTome: See the villain of IRON MAN 2!
May 27, 2005 4:43 PM PDT

Bank of America's SiteKey scrutinized

by Joris Evers
  • Font size
  • Print
  • Post a comment
It's impossible to introduce a security product without having it scrutinized. Bank of America's SiteKey, designed to protect its online banking customers, is no exception.

SiteKey's image and text checks are designed to let people know they are on an authentic Bank of America Web site and also to verify the identity of the customer. The system, announced Thursday, is being introduced state by state and should be nationwide year's end.

Worried that SiteKey may be vulnerable to a so-called man-in-the-middle attack or leak information, readers commented on Thursday's story on the News.com Web site and on Full Disclosure, a security mailing list.

Mark Goines, chief marketer for PassMark Security, supplier of the technology behind SiteKey to Bank of America, said a man-in-the-middle attack is not possible. SiteKey uses a "secure cookie" to link a user's PC to the Bank of America Web site. The cookie can only be read by a server with a specific security certificate and not by a malicious Web site set up by an attacker in such an attack, Goines said.

The other reader concern was that SiteKey would make it easy to confirm whether a user ID is registered with the bank. The service displays a security question selected by the user after entering a valid user name.

That in fact is possible, Goines said. But all the attacker would have is a user name, that alone does not give access to the account, he pointed out. The next step in the sign-on procedure is answering the security question. After that the system will ask the user for his passcode.

Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
advertisement
Click Here

A CNET Conversation with Eric Schmidt

CNET's Tom Krazit and Molly Wood sit down with Google CEO Eric Schmidt to discuss the future of Android, the Chrome OS, the problem of real-time search indexing, and more.

Verizon tests sending RIAA copyright notices

The No. 2 phone company, known for its reluctance to intervene in antipiracy cases, strikes an agreement to forward copyright notices on behalf of the music industry.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right