Skip Links

Network World

  • Social Web 
  • Email 
  • Close

The man-in-the-middle gets caught up in ID theft

Trying to stay one step ahead of ID thieves
Security: Identity Management Alert By Dave Kearns , Network World , 10/26/2005
Kearns
Sign up for this newsletter now!

Dave Kearns provides the information you need to evaluate, install and maintain your corporate identity management system.

  • Share/Email
  • Comment
  • Print

As I mentioned in the last issue, the Federal Financial Institutions Examination Council (FFIEC) has issued new guidance for how financial institutions should plan to authenticate customers' online identities by the end of next year. These guidelines, which actually carry the force of mandates, did not recommend specific methods of strong authentication but did review some possibilities. Those included digital certificates, smart cards, one-time passwords, USB plug-ins and biometric identification methods as being more in line with the guidelines than the simple username/password combinations currently in use. In particular, the FFIEC believes that stronger authentication is needed to combat so-called "phishing" attacks.

Security vendors such as RSA are quick to point to European financial institutions as being far ahead of their U.S. counterparts in using tools such as RSA's SecureID one-time password-generation device. But are these really as secure as we think they might be?

Rebecca Bace is the CEO of Infidel, a security consultancy. She's also a venture partner with Trident Capital, specializing in network security. She learned her trade on the front lines, during 16 years at the National Security Agency, where she became one of the world's leading experts on intrusion detection and prevention. She's also a neat lady with a droll sense of humor as I learned when we were panelists at the recent Thor Technology Advisory Council meeting. She's just updated a presentation she gave at the RSA Conference 2005 called "Phishing 2.0". You can read the short article where you'll quickly find out that so-called strong authentication can also be described as weak security in many instances.

The problem Bace outlines is the same problem that Dan Blum, Network World colleague and Burton Group senior vice president, highlighted in his Weblog: One-time password (OTP) solutions are very susceptible to a man-in-the-middle (MITM) attack. Simply put, someone intent on stealing the details of your financial transaction sets up as a proxy between the client and the financial Web site. By capturing and replaying the client's credentials and returning what appears to be legitimate responses the thief has, essentially, unlimited access to the client's account.

Dave Kearns is a consultant and editor of IdM, the Journal of Identity Management.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.