All the latest UK technology news, reviews and analysis

Hackers can beat security tokens

by Iain Thomson

More from this author

15 Mar 2005

Be the first to comment

  • Tweet this

IT security expert Bruce Schneier has warned that plans to move to two-factor authentication will not solve online fraud.

Schneier pointed out that the tokens will not stop the most common types of attacks. Tokens can work well in corporate environments but will be ineffective against much of today's crime since it relies on tricking users rather than beating passwords.

"Two-factor authentication doesn't solve anything. It won't work for remote authentication over the internet," he said.

"I predict that banks and other financial institutions will spend millions fitting their users with two-factor authentication tokens.

"Early adopters of this technology may very well experience a significant drop in fraud for a while as attackers move to easier targets, but in the end there will be a negligible drop in the amount of fraud and identity theft."

He lists two attacks, man-in-the-middle and Trojans, which would not be stopped by the use of tokens. In the first case a hacker sets up a fraudulent phishing website such as a bank log-in page where the victim inputs their log in details anyway, and with Trojans the hacker would log in with the user, token or no token.

Last year online fraudsters stole $1.2bn in the US and there are fears that fraud is harming confidence in e-commerce.

Representatives of the British banking industry, police and the security industry met in January to discuss ways of fighting online fraud, including the introduction of tokens. Last year AOL launched a premium service for customers using the devices.

Microsoft announced yesterday that it is dropping passwords in favour of two-factor authentication.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Project Manager -Commodities,Oil,Gas,Agriculture,Power- £90,000

Project Manager, London - Software Solutions (Project...

Project Manager - Hampshire - up to £32K FTC

Project Manager - Hampshire - up to £32K - Fixed Term...

Senior Customer Support Consultant - 2nd/3rd Line Support - SAS

Senior Customer Support Consultant - 2nd/3rd Line Support...

Front Office Application Developer - Investment Banking - Londo

C++/C#/Java developer for a global investment bank within...

To send to more than one email address, simply separate each address with a comma.