Original URL: http://www.theregister.co.uk/2007/05/01/verisign_twofactor_authentication/
VeriSign has announced plans to integrate two-factor authentication technology into ATM and credit cards, a move that would give customers significantly more protection against scammers without requiring them to go through the hassle or expense of using a stand-alone security token.
The move will allow debit and credit cards to include a small panel that displays a temporary password that regularly changes every 60 seconds or so. Customers logging on to the issuer's website would be required to enter both the temporary and permanent password, a measure that would provide more protection against phishers and other online miscreants. Currently, most financial institutions rely on a single password to authenticate customers.
Criminals employ an impressive arsenal of tricks to intercept online passwords, with phishing emails and keyloggers being among the most popular. Relying on a static password as a sole means of authentication makes it easier for criminals to repeatedly and surreptitiously gain access to a victim's account, often over an extended period of time.
Requiring two-factor authentication, which requires both a static password and the temporary code, can limit this damage, since a criminal would need both physical access to the card and the knowledge of the permanent password to access the account. (The added protection, however, is not immune (http://www.theregister.co.uk/2006/07/13/2-factor_phishing_attack/) to attacks.)
Given the seemingly daily reports of fraud on eBay and other online commerce sites, it's hard to understand why two-factor authentication isn't already common place.
VeriSign isn't saying what financial institutions will adopt the service, but a spokesman said several banks have already signed up and that VeriSign plans to announce them in the near future. Participating financial institutions will be able to share codes so customers won't have to carry multiple cards. VeriSign is teaming with Innovative Card Technologies to deliver the service.
VeriSign's press release can be found here (http://www.verisign.com/press_releases/pr/page_042055.html). ®
VeriSign slims, cuts jobs to focus on security (15 November 2007)
http://www.channelregister.co.uk/2007/11/15/verisign_reorg/
VeriSign takes $160m hit to cover stock option mess up (16 July 2007)
http://www.theregister.co.uk/2007/07/16/verisign_stock_option_charges/
Strange spoofing technique evades anti-phishing filters (25 May 2007)
http://www.theregister.co.uk/2007/05/25/strange_spoofing_technique/
Oyster-Barclaycard hybrid passes first technical trials (4 May 2007)
http://www.theregister.co.uk/2007/05/04/oyster_barclaycard/
Barclays' chip and PIN readers will work for other banks (23 April 2007)
http://www.theregister.co.uk/2007/04/23/barclays_pinsentry/
Phishing attack evades bank's two-factor authentication (19 April 2007)
http://www.theregister.co.uk/2007/04/19/phishing_evades_two-factor_authentication/
Barclays deploys PINsentry to fight fraud (18 April 2007)
http://www.theregister.co.uk/2007/04/18/pinsentry/
RSA unwraps small business authentication appliance (16 March 2007)
http://www.theregister.co.uk/2007/03/16/rsa_sme_appliance/
Fear and Loafing at RSA (9 February 2007)
http://www.theregister.co.uk/2007/02/09/rsa_fear/
Phishers haul in money from Nordic bank (19 January 2007)
http://www.theregister.co.uk/2007/01/19/phishers_attack_nordea/
User convenience versus system security (13 September 2006)
http://www.theregister.co.uk/2006/09/13/mob_auth/
Barclays to launch two-factor authentication (9 August 2006)
http://www.theregister.co.uk/2006/08/09/barclays_launches_cardreaders/
Phishers rip into two-factor authentication (13 July 2006)
http://www.theregister.co.uk/2006/07/13/2-factor_phishing_attack/
Who are you? Can you prove it? (11 July 2006)
http://www.theregister.co.uk/2006/07/11/reader_study_auth/
SecurID takes backseat in Windows Vista (4 May 2006)
http://www.theregister.co.uk/2006/05/04/windows_vista_securid/
© Copyright 2008