Two-factor authentication is no silver bullet.

The recent push by the government to require two-factor authentication on laptops has made the computing world sit up and take notice. It's also probably boosted two-factor authentication method vendors fortunes a bit, but if it works, why not?

Phishers aren't stupid, and a snazzy new phishing site broke Citibank's two-factor authentication by actually executing a man-in-the-middle attack. By sitting between the user and Citibank's site, they were able to get the token ID that lasts only a minute at a time and execute transfers behind the scenes within the minute.

http://it.slashdot.org/article.pl?sid=06/07/11/0337213&from=rss

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <img> <embed> <object> <param>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text. URLs will automatically be converted to links.

More information about formatting options

CAPTCHA
Be ye bot or be ye not?