NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


Online Banking Services Increasingly Vulnerable

Even with token-based authenticity

By Marius Oiaga, Technology News Editor

15th of July 2006, 10:34 GMT

Adjust text size:


35 phishing sites were set up in the time of a few weeks targeting users of online banking services, revealed Rich Miller, an analyst with Internet research company Netcraft Ltd. Some US banks have implemented what
is known as token-based authentication security system to comply with federal regulations that ask for multiple authentications for all online transactions. Through token devices, banking customers are emitted a secondary, temporary password that can used only once and that comes with a short life period.

Circumventing the token security measures is a man-in-the-middle technique. And such attacks are on the rise as proven by the 35 phishing sites posted to harvest temporary passwords that will ultimately lead to the access of the banking accounts from financial institutions such as Citigroup Inc.

"These attacks are worrisome because they took advantage, fairly early on, of a system that's seen as enhancing security for banking customers," Miller said. This is getting organized. It is not just an isolated incident of somebody coming up with a proof of concept or an exploit that's unique to them."

When a user is tricked in divulging his bank account confidential information on a phishing site, the data is instantaneously forwarded to the bank and the account is accessed. In most cases the actual bank customers have no time to react, they become instantaneous victims.
Read by 1,315 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.8/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


EBay Bans Google Checkout

Three South African Banks Hit by Hackers

The High-Tech Modern Piggy Bank

Gmail Phishing Scam Promises $500 Cash Prize

Phishing on PayPal

PayPal Phishing over the Phone

Firefox 2.0 Beta 1 Applauded for Anti-phishing Features

A Fistful of Tools to Bulletproof Firefox

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM