Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Proposal to anti-phishing |
|---|---|
| Date: | Mon, 24 Jan 2005 13:22:18 +0100 |
And then there are other issues, like which smartcard + pki + message format must be supported by the PC, OS, and user's software. And do all these factors interoperate smoothly with all the other software a banking customer
may have.
Finally, there is the need to re-authenicate ever customer in order to issue a new identifier in the form of the card.
So long as the smartcard supports PKCS#11, there should be no problem interacting with it.
The PKI software chosen by the bank should be irrelevant, as it still produces certificates in the standard X.509 formats.
The selected CA, cert issuing process, extensions and or cert constrainst fields, CA policy statement and the fields/structure in the messages generally give all the PKCS 11 and X.509 a strong flavour of 'proprietary' implmentations.
Worse, many CA approachs will provide an assertion about a person (lyal
collins) not theat person's accounts, or conversely, with accounts. In the
former case, I have to register my cert with each account I have with each
(so the banks can update their account profiles with my cert details) while
the latter case means a new cert for each account I have.
If this isn't a case of inplementing new 1:1 security relationships just to replaice existing solutions with new technology, without saving costs, I don't know what is.
Message format can be specified by the online application, as it does not have to interact with anyone else, other than that single online application.
This = proprietary solutuion., What about my other financial/bank relationships?
Technically, a good idea. Practically, and commercially,
very hard and
expensive to do. Requiring every on-line banking customer
to buy a new
computer in order to use on-line banking is probably worse
than giving
customers a new computer, something that does happen for high worth individuals in a few rare cases.
I'm not suggesting for a second that people will HAVE to buy a new computer. You can buy a smart-card reader for les than USD30. No need for a new computer, if you already have one.
Smartcard readers are like sterilising bullets - the benefit (germ free) is far outweighed by other effects (the bullet kills you).
My point was that IF manufacturers start shipping computers with a smart-card reader already part of the PC, and with drivers already installed as part of the OS installation, then we start approaching the "zero-setup" that was originally posited as the "Holy Grail".
We can but hope - one day, Oh one day
Lyal
Rogan -- Rogan Dawes
*ALL* messages to discard@dawes.za.net will be dropped, and added to my blacklist. Please respond to "lists AT dawes DOT za DOT net"
| Previous by Date: | Re: (secure email) Proposal to anti-phishing, Michael Silk |
|---|---|
| Next by Date: | Re: (not really a) Proposal to anti-phishing, Rishi Pande |
| Previous by Thread: | RE: Proposal to anti-phishing, Lyal Collins |
| Next by Thread: | Re: Proposal to anti-phishing, Griffiths, Ian |
| Indexes: | [Date] [Thread] [Top] [All Lists] |