On mySimon: Holiday Gifts for Her
BNET Business Network:
BNET
TechRepublic
ZDNet

April 12th, 2007

SiteKey phish demonstrated against BofA

Posted by Richard Stiennon @ 3:49 pm

Categories: Bank security, Security blog

Tags:

The use of images to assure a user that they are not being phished has started to become common. Yahoo! uses them. And BankofAmerica has been using Passmark's (RSA) technology in their SiteKey scheme to protect their online banking customers from being phished.  The idea is that a cookie in your browser alerts the BofA server that it is you returning and you see an image that you selected when you first signed up for online banking. If you were at a fake site you would be suspicious because you would not see the familiar image. 

The scheme falls down because there has to be a way to accommodate someone logging in from a different computer when they are on the road, at a conference kiosk, etc.  So Bank of America asks a "secret question" and then installs the cookie on the new machine. This is where an attacker can interject a Man in the Middle attack.  The phishing site gets the secret question from the BofA server, passes it to the user, and passes the answer back to the bank.

Christopher Soghoian, a grad student at Indiana University  school of informatics, has posted some movies of his clever attack on his site as well as the php script for attacking BofA's servers. He points out that RSA also sells activity monitoring solutions (from Cyota) that BofA probably uses so an actual exploitation of a compromised account will probably not work. Until they figure out a way around it, that is. 

Its a war of escalation and banks have to stay ahead.   

 

 

Security blog 

Richard Stiennon is an industry consultant. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 2 Talkback(s)
No -- way!!!
Uh -- geez... I always follow security practices...

No matter how hard you try phishers, you won't get me to open e-mails and click in the links...... (Read the rest)
Posted by: Grayson Peddie Posted on: 04/27/07 You are currently: a Guest | | Terms of Use
Thoughts from a long-term RSA consultant:  VinMcLellan | 04/16/07
No -- way!!!  Grayson Peddie | 04/27/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Top Rated

    Archives

    Favorite Links

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
    • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
    • Smart People The best and worst moves in the management and strategy trenches. Learn More