the limits of crypto and authentication
Nick Owen
nowen at wikidsystems.com
Sat Jul 9 11:34:06 EDT 2005
It would seem simple to thwart such a trojan with strong authentication
simply by requiring a second one-time passcode to validate the
transaction itself in addition to the session.
Steven M. Bellovin wrote:
> There's been a lot of discussion about how to strengthen cryptography
> and authentication, to get away from problems of phishing, pharming,
> etc. But such approaches can take you only so far, as this link
> indicates:
>
> http://www.lurhq.com/grams.html
>
> Briefly, it's a Trojan that waits for you to log int o E-Gold, checks
> your balance, and drains your account except for .004 grams of gold.
>
> --Steven M. Bellovin, http://www.cs.columbia.edu/~smb
>
>
>
> ---------------------------------------------------------------------
> The Cryptography Mailing List
> Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com
>
--
Nick Owen
WiKID Systems, Inc.
404.962.8983 (desk)
404.542.9453 (cell)
http://www.wikidsystems.com
At last, two-factor authentication, without the hassle factor
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com
More information about the cryptography
mailing list