July 14, 2006

I told you so - two factor does nothing for phishing.

Apparently, a phishing site has been found that allows phishers to take advantage of users even when two factor authentication is employed. Here's what happens - you get an email telling you to follow a link to "your bank" (really a bogus site.) You connect to it and enter your two-factor authentication data. The site then opens a connection and uses your credentials to log in. The result: your bank account gets drained even though you used a second authentication factor. It's a little more complicated than a regular phishing scenario, but not rocket science.

This proves the point that I've been trying to make for the past two years - namely, that the reason that phishing works is not because we don't have sufficiently robust user authentication. No, the reason that phishing works is that we don't have sufficient authentication of the server. Mark my words - you could use as many user authentication vehicles as you want and phishing is still a possibility.

Man I love being right.

Posted by Ed at July 14, 2006 09:49 AM | TrackBack
Comments
Post a comment









Remember personal info?