Network World
Tuesday, October 7, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Excellent article. Feedback for Cogneto Unomi

0

Your system (Cogneto Unomi) is a step in the right direction; congratulations. But it has a couple of characteristics you can improve, IMHO:

FIRST: To fight phishing, the very *first* step in mutual authentication is Bank/company authentication, not user authentication.

Explanation: in the demo, the user answers / clicks BEFORE he/she knows it is the REAL website and not a FAKE website. So he/she is at risk giving out the secret information.

A phisher has no problems to ask for password, then a sequence of clicks, your SSN, mother maiden name, and so on.

SECOND: To fight phishing, the real website must be dificult to be REPLICATED by a phisher fake website.

Explanation: Given the current personalization is based on pre-selected scenarios (restaurant, etc) the phisher can replicate the scenarios, colors, food, pieces, etc and track all user clicks.

I suggest, at least, to INCLUDE at the beginning (after password), one personal QUESTION selected / written / specified by the user herself, in the enrollment phase. For example,

My QUESTION: Why did you repeat 4th course of school?
My ANSWER: Due to fracture

USER: "I dont see My QUESTION; it's a FAKE website"

And these ideas, can be improved further by your company. Congratulations again!

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Latest software headlines from Network World:

GoDaddy hosts Exchange to offer first desktop mail service

Red Hat undercuts Microsoft on high-performance OS pricing

For Microsoft shops, Silverlight 2.0 trumps Flash

One of the 'big four' management vendors could be acquired in the next few years - Network ...

App Store successful, but shows flaws

  1   2   3   4   5   6   7   8   9  10  next 

Advertisement: