Phishing (Was Re: WashingtonPost computer security stories)

Joel Jaeggli joelja at darkwing.uoregon.edu
Tue Aug 17 15:28:01 UTC 2004


On Tue, 17 Aug 2004 Michael.Dillon at radianz.com wrote:

> Barclays also uses a "memorable word" in addition to
> the PIN code. They repeatedly tell us that no-one
> from Barclays will ever ask us to reveal this
> memorable word. It's only use is for a simple
> challenge-response where the website asks for
> two specific letters from the word and we select
> them from drop-down boxes to defeat keyloggers.
> Nice example of layered security that keeps the
> criminals snapping at the heels of the guy next
> door, i.e. CitiBank et al.

Lots of european banks issue sheets of onetime passwords.

> --Michael Dillon
>

-- 
-------------------------------------------------------------------------- 
Joel Jaeggli  	       Unix Consulting 	       joelja at darkwing.uoregon.edu 
GPG Key Fingerprint:     5C6E 0104 BAF0 40B0 5BD3 C38B F000 35AB B67F 56B2




More information about the NANOG mailing list