LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-27-2014, 12:52 PM   #1
jkl123
LQ Newbie
 
Registered: Dec 2014
Posts: 5

Rep: Reputation: Disabled
online banking question


So I was recently reading this article http://www.cnet.com/news/false-secur...its-customers/ about two-factor authentication and although I really didn't understand it, the article was suggesting that hardware tokens weren't secure. So this got me wondering what type of two-factor authentication is currently the safest? This website https://twofactorauth.org/ lists different websites and the methods of two-factor authentication they use. So between SMS, phone call, email, hardware tokens, and software implementation which ones are the most secure?
 
Old 12-27-2014, 03:30 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Especially given your comments on Linux security here I suggest you don't use the fact you don't understand the article as a shortcut to blightely jump to the million dollar question. Basic understanding of the SiteKey implementation, how Man in The Middle (MiTM) attacks subvert it and more importantly: how human behaviour undermines authentication (neglecting to notice any discrepancies), is important. Next to that anybody responding with "product X" (without properly explaining why) should be viewed as utterly suspicious.

Failing to do so would be like setting up a Claymore mine (or better: have some doofus set it up for you) without reading the cover notice and "just hoping you get it right". Well, there is a chance... Now, that you are invited to discuss things here is inherent to how fora like LQ work but the responsibility to read, understand and make an informed decision should be yours and yours alone. So as far as CVE-2006-7199 goes please read these:
https://www.schneier.com/blog/archiv...ailure_of.html
http://blog.washingtonpost.com/secur..._to_break.html

http://paranoia.dubfire.net/2007/04/...le-attack.html
http://paranoia.dubfire.net/2007/03/...s-sitekey.html
http://cr-labs.com/publications/SiteKey-20060718.pdf

and don't forget this one: http://www.usablesecurity.org/emperor/
 
Old 12-28-2014, 05:41 PM   #3
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,649
Blog Entries: 4

Rep: Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934
I think that the bottom line is that "neither personal-computers, nor (especially ...) phones and tablets, qualify as 'secure devices.'" Neither is the Internet a 'secure network.' (No, not even given the fact that individual conversations can, more or less, be secured. You cannot prove that there is not a man somewhere in the middle of the complete exchange.) These devices were designed to be appliances.

The only hardware-plus-software environment that would actually be appropriate for (especially ...) "online banking" does not exist yet. The technology that is required includes a truly-hardened computer, plus a "smart" credit-card with an onboard microprocessor, and a secure reader for that card which is installed into every phone, tablet, or computer. The notion of a "credit card number" must go away completely.

Ironically, I think that some of the novel cryptographic ideas that currently manifest in "bitcoin" just might play a part in all of this. The total requirement for credit-card processing necessarily must include both online and offline acceptance capability, and the exchange must remain secure even though an unscrupulous merchant (or, a data-thief working for him ...) will have access to the stored, not-yet-processed offline data. "Bitcoin" essentially introduces the notion (as I understand it ...) of completely-decentralized authentication. If this notion can be coupled with a cipher exchange protocol that is not computationally intractable ... indeed, that can be partly implemented on-board a smartcard ... then there are millions of dollars in well-deserved patent royalties to be earned by someone.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Using a LiveCD when banking online Mikey555 General 6 08-06-2014 01:38 AM
Online banking security Completely Clueless Linux - Security 11 08-07-2013 04:13 AM
Firefox and online banking salimshahzad General 12 01-11-2010 04:43 AM
online banking? toolshed Linux - Software 7 03-24-2004 12:10 PM
Online Banking / Online Shopping in Linux? JROCK1980 Linux - General 14 02-27-2004 02:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:47 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration