Two-factor authentication could still be overcome by phishing scams
Advanced phishing techniques could be used to breach two-factor authentication

Next-gen banking security still not safe

Two-factor authentication has major phishing flaw

Written by Matt Chapman

Two-factor authentication, where banks add one-time passwords and payment confirmation codes to the usual password-based security measures, could still be overcome by phishing scams, a security vendor at Infosec 2006 has warned.

F-Secure said that advanced phishing techniques could be used to breach the system by setting up a fake banking site, contacting the real site and waiting for the password, then getting the user to type in the one-time password that is supposed to protect them. 

"The next logical step for phishing sites is to ask people to authenticate themselves, then keep them waiting while the data is entered into the real site, " said Mikko Hyppönen, chief research officer at F-Secure. "This is seen by internet criminals as just another hurdle to overcome." 

F-Secure also pointed to a breakdown in the two-factor system because vulnerable users could be persuaded to divulge their passwords.

"There's a fishing scam already that asks you for your next five passwords and this is an example of where two points of authentication is not going to help," said Richard Hales, F-Secure's country manager for UK and Ireland.

"The intermediary device collects all the authentication information and passes it through to the bank so you [log in as normal and] don't notice that you've been scammed. But it has caught all five keys and your log-in details."

Hales explained that the scam works because people actually log on to the real site and carry out their business as normal, without being alerted to the scam.

"How many people log on to their bank more than every couple of days? Because you log on, it all works, it's familiar and you log off again. You don't notice that anything has happened," he said.

"In a week's time you go back on again and wonder why there's no money in your bank account."

F-Secure also pointed out that in many cases phishing sites display images from the real banking website, and that banks should make every effort to detect that the images are being downloaded for use elsewhere.

Tags:

Further reading

First mobile banking services go live

HSBC and First Direct go mobile   More...

Phishers ring changes with phone scam

Scammers use new bait to fleece Chase Bank customers   More...

Research finds no way to beat phishing

People are stupid it seems   More...

Surfers failing to spot phishing sites

Encryption focus ignores the user, study shows   More...

Related articles

Infosec: Surfers wary of using credit cards online

Confidence plummets as attacks soar   More...

Storm botnet connected to phishing ring

Experts fear hackers selling time on botnet   More...

Mutant Trojans threaten Mac users

Malware authors tweaking payload, say researchers   More...

Lottery scam targets smartphone owners

Text messages promise €170,000 prize   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement