Comments on: Microsoft's answer to phishing: Two IDs
Banks aren't moving fast enough on requiring online customers to provide two forms of ID, the company says.
Banks aren't moving fast enough on requiring online customers to provide two forms of ID, the company says.
December 4, 2009 10:15 AM PST
December 4, 2009 9:36 AM PST
December 4, 2009 9:23 AM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
up their butts (again) but how can a requirement for dual ID's
stop a phishing attack that asks to verify both forms of ID?
If people are dumb enough to respond to current phishing
attacks, they are dumb enough to provide both ID forms to an
expanded phishing attack.
- Two Factor Authentication
- by wbenton November 18, 2004 9:16 AM PST
- Two factor Authentication or only One factor Authentication... it doesn't matter.
- Like this Reply to this comment
-
(3 Comments)As long as the Authentication process(es) one or more can be spoofed... they will continue to be a problem.
The Key to security lies in the keys.
Keys for authentication
Keys for encryption
Method of Key creation
Method of Key storage
Method of Key delivery
Method of Key backup
Method of Key protection
All of these combined make any Authentication (Single, Double, Triple or otherwise) secure or unsecure.
Where are the keys stored?
Is that storage encrypted?
How were the keys created? (is there any pattern?)
Who has access to those keys?
Are those keys backed up? (What backup methods and storage for those backups?)
What encryption method is used, what is the key length, can those keys be retrieved somehow?
It's quite complex and the FIPS 140 Specifications detail a lot of methods to use, but all of them are cumbersome at best.
Bottom line: Good security ain't cheap and cheap security ain't necessarily good.
Likewise, strong keys used with a weak encryption method or weak keys used with a strong encryption method make for more mess than it's worth.
Keys are the KEY to security, from creation, handling, storage & backup to revoking.
FWIW