Posted by:
admin
15 years, 12 months ago
Clearly, we need to do a better job of promoting WiKID.
The Tower Group just issued new research titled: ONLINE BANKING REQUIRES STRONGER AUTHENTICATION METHODS TO COMBAT MORE ADVANCED FORMS OF FRAUD
Highlights of the research include:
Many desktop computers are highly-vulnerable to attacks from malicious software, which can be downloaded to a PC without the consumer's knowledge. Using these 'malware' payloads, fraudsters can gain access to personal information through a variety of methods - from logging an individual's keystrokes on the computer when they sign in to their online banking site, to remotely taking control of the user's entire PC.
"Single-factor" authentication, typically a username plus password, remains the most widespread approach for accessing online banking sites. While easy to use and administer, it cannot combat more advanced forms of fraud. As usernames and passwords become the weak link, the traditional single-factor approach will become an entirely deficient means of online banking authentication.
"Two-factor" authentication offers a vast improvement in security. One example involves providing consumers with a hardware "token" that generates a random number to be entered along with his or her password. However, most large consumer banks have been fearful that convenience-oriented consumers will reject the additional burden of physical tokens, or will be overwhelmed by devices from multiple institutions.
WiKID solves many of the issues with standard hardware tokens. First, convenience. WiKID runs on the PC (or a wireless device making it easy to cut-and-paste the one-time passcodes. The client can be protected in a PKS12 store for security. Still, because the PIN is stored on the server, stealing the private key is no different than stealing an ATM card - you don't have enough. As a convenience to the administrator, we can automate the initial validation process.
Further, WiKID running on the PC is capable of validating the SSL certificate of the targeted website before getting the one-time passcode. This elimates man-in-the-middle attacks such as DNS-cache poisoning.
WiKID also solves the problem of multiple "devices from multiple institutions". Because we use public key cryptography, a single WiKID client can support multiple WiKID servers across multiple enterprises. Instead of having multiple key fobs, you would have one WiKID client with multiple public keys! (In addition, you can have multiple WiKID client assigned to a single username, so you can have one client running on your Windows, Mac, Linux desktop and another on your Blackberry.
If more people had WiKID clients, then more financial institutions would be interested in securing their online banking systems with WiKID. Yet, people don't need a WiKID client unless they have something to log into using two-factor authentication! Classic chicken and egg. We're planning on doing something about this soon. Keep an eye here.
Share on Twitter Share on Facebook
Recent Posts
- Blast-RADIUS attack
- The latest WiKID version includes an SBOM
- WiKID 6 is released!
- Log4j CVE-2021-44228
- Questions about 2FA for AD admins
Archive
2024
2022
- December (1)
2021
2019
2018
2017
2016
2015
2014
- December (2)
- November (3)
- October (3)
- September (5)
- August (4)
- July (5)
- June (5)
- May (2)
- April (2)
- March (2)
- February (3)
- January (1)
2013
2012
- December (1)
- November (1)
- October (5)
- September (1)
- August (1)
- June (2)
- May (2)
- April (1)
- March (2)
- February (3)
- January (1)
2011
2010
- December (2)
- November (3)
- October (3)
- September (4)
- August (1)
- July (1)
- June (3)
- May (3)
- April (1)
- March (1)
- February (6)
- January (3)
2009
- December (4)
- November (1)
- October (3)
- September (3)
- August (2)
- July (5)
- June (6)
- May (8)
- April (7)
- March (6)
- February (4)
- January (427)
2008
- December (1)
Categories
- PCI-DSS (2)
- Two-factor authentication (3)
Tags
- wireless-cellular-mobile-devices (7)
- Two-factor authentication (10)
- Wireless, cellular, mobile devices (6)
- NPS (1)
- Phishing and Fraud (111)
- Active Directory (1)
- pam-radius (3)
- privileged access (2)
- Cloud Security (10)
- Mutual Authentication (60)
- Web Application Authentication (1)
- Authentication Attacks (99)
- pci (50)
- Security and Economics (97)
- WiKID (133)
- pam (2)
- VPN (1)
- Installation (2)
- RADIUS Server (1)
- Open Source (64)
- Tutorial (2)
- Strong Authentication (35)
- Information Security (137)
- Transaction Authentication (13)
- Miscellaneous (100)
- Linux (2)
- transaction-authentication (6)
- Two Factor Authentication (254)