Gartner: Hackers Defeating Tough Authentication

Status
Not open for further replies.

JofaMang

Distinguished
Jun 14, 2009
56
0
18,580
"Any society that would give up a little liberty to gain a little security will deserve neither and lose both"

Bank teller asking for a waiver signature:
"Well, if you want to be protected against fraud, we will need to track absolutely everything you do so that we know it is you when you log in. Sign on the bottom please."
 

micr0be

Distinguished
Sep 26, 2009
201
0
18,830
man-in-the-browser attack .... not in the middle attack ... 2 very different attacks .... MITM intercepts outgoing traffic ... MITB intercepts data submitted directly by the user to his browser, and then re-routes traffic accordingly. (this happens before ssl is even active)
 
G

Guest

Guest
[citation][nom]bjforte2007[/nom]How do you do a man in the middle attack with ssl active?[/citation]
This has been going on for awhile now and it works like this:

Worm on your system, possibly protected by a RootKit to evade detection.

It waits till you log into your account, the worm then gets immediate access to your account without the need to bypass security as you just let it in the door.

While you are logged in, the worm transfers money out of your account without your knowledge as the bank will think it's you doing the transfer.
 
G

Guest

Guest
So you would not install locks on your front and back door if you lived in a high crime area to just keep a little liberty instead of gain a little security.

The point is you work hard for your money. Would having to sign a little piece of paper saying you understand they will do more to help protect your hard earned money really hurt. Unless your receiving dirty money what are you really giving up by protecting yourself.

"The definition of stupidity is doing the same thing over and over again and expecting different results." — Albert Einstein ...
 
[citation][nom]TheBFG[/nom]So you would not install locks on your front and back door if you lived in a high crime area to just keep a little liberty instead of gain a little security.[/citation]
Umm, keeping a little liberty instead of gaining a little security was highly touted by one of the Founding Fathers of America. To quote Benjamin Franklin, "They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
 

elel

Distinguished
Jun 18, 2009
103
0
18,640
[citation][nom]TheBFG[/nom]So you would not install locks on your front and back door if you lived in a high crime area to just keep a little liberty instead of gain a little security.[/citation]
lol. how do you gain liberty by leaving the locks off the doors?
 

theblackbird

Distinguished
Dec 13, 2005
10
0
18,560
It's not the bank's security that's compromised, it's YOURS. People need to stick to their AV and firewall solutions, and be careful with what they do online. Making banks scan customer behavior is just asking for commercial abuse.
 

anamaniac

Distinguished
Jan 7, 2009
1,035
0
19,230
Well, I had my account robbed, but it was the good ole' skimmers, not the hackers...
I can imagine if a hacker took my account though, seeing orders on the transcripts for mountain dew, blow up dolls, lube, hot pockets, and a 5970 (or atleast what I'd use someone else's money for).
 
Status
Not open for further replies.