Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: limits of end-user "testing" |
|---|---|
| Date: | Tue, 22 Nov 2005 15:48:36 +0100 |
Andrew van der Stock wrote:
Transaction signing for my point of view is not C/R two factor authentication, which as I said, not that useful. If you pay for trx
(...)
Phish threat model for trx signing / sms (A)
(...)
Now, it may be possible that a user with a trx signing calculator may answer the phone and give these details up, but I doubt it. A user who gets a SMS transfer message when they're not using the system would rightly either ignore it or ring the bank. Honestly, a phisher in Brazil or the former eastern bloc country would have almost zero chance to make an out of band connection with enough users to make this worthwhile, particularly since it would require a lot of access to telephones at the right time and knowledge of a lot of people's numbers. Not impossible, but highly unlikely.
MITM threat model for trx signing (B) / sms (C)
(..)
Scenario B) IB platform asks user for transaction signing for transaction B (usually based upon $, transaction reference and destination account)
(...)
Scenario C is much stronger than no transaction signing, but it has one weakness - that the user's mobile number might be obtainable somehow. I really don't think this is practical on a widespread basis like phishing attacks for non-2FA / non-TS internet banking. For retail IB, SMS is acceptable right now until trx signing calculators are available to all IB users.
Just my 2c
Javier
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: limits of end-user "testing", Javier Fernandez-Sanguino |
|---|---|
| Next by Date: | RE: Web based utility for securely changing AD password, Gary Everekyan |
| Previous by Thread: | Re: limits of end-user "testing", Andrew van der Stock |
| Next by Thread: | Re: limits of end-user "testing", Daniel |
| Indexes: | [Date] [Thread] [Top] [All Lists] |