Doubts cast over efficacy of two-factor authentication
Doubts cast over efficacy of two-factor authentication

Hackers can beat security tokens

Two-factor authentication 'doesn't solve anything', claims security expert

Written by Iain Thomson

IT security expert Bruce Schneier has warned that plans to move to two-factor authentication will not solve online fraud.

Schneier pointed out that the tokens will not stop the most common types of attacks. Tokens can work well in corporate environments but will be ineffective against much of today's crime since it relies on tricking users rather than beating passwords.

Advertisement

"Two-factor authentication doesn't solve anything. It won't work for remote authentication over the internet," he said.

"I predict that banks and other financial institutions will spend millions fitting their users with two-factor authentication tokens.

"Early adopters of this technology may very well experience a significant drop in fraud for a while as attackers move to easier targets, but in the end there will be a negligible drop in the amount of fraud and identity theft."

He lists two attacks, man-in-the-middle and Trojans, which would not be stopped by the use of tokens. In the first case a hacker sets up a fraudulent phishing website such as a bank log-in page where the victim inputs their log in details anyway, and with Trojans the hacker would log in with the user, token or no token.

Last year online fraudsters stole $1.2bn in the US and there are fears that fraud is harming confidence in e-commerce.

Representatives of the British banking industry, police and the security industry met in January to discuss ways of fighting online fraud, including the introduction of tokens. Last year AOL launched a premium service for customers using the devices.

Microsoft announced yesterday that it is dropping passwords in favour of two-factor authentication.

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Podcast image

16 Oct 2008

15.99 MBComputing podcast - What the politicians plan for IT; and how the credit crunch is affecting outsourcing More...

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Security hack

Security industry falling behind the hackers

Report warns of new threats on the horizon   More...

Laptop

Global PC shipments disappoint

IDC reports sales up 16 per cent, but still lower...  More...

Intel

Intel to buy NetEffect for $8m

Firm will contribute to chip giant's Ethernet projects   More...

Windows 7 screenshot

Microsoft defends choice of 'Windows 7'

But still does not satisfy Windows followers   More...

Primary Navigation