Aardvark Daily aardvark (ard'-vark) a controversial animal with a long probing nose used for sniffing out the facts and stimulating thought and discussion.

NZ's leading source of Net-Industry news and commentary since 1995
PAYBACK TIME! | WebStats | XML feed | Contact | New Sites | Archives | Forums | About
Note: This column represents the opinions of the writer and as such, is not purported as fact
How to crack two-factor authentication 18 January 2005 Edition
Previous Edition | Archives

Please visit the sponsor!
Sponsor's Message
It looks as if work continues on creating a universal authentication system designed to facilitate the interaction between citizens and governments through the Net.

According to this story on Stuff, Datacom has secured the almost $15m contract to develop and implement the necessary systems.

What does this mean to the average Kiwi and Kiwi businesses?

It looks as if you'll have yet another login ID and password to remember, which means yet another opportunity for identity theft amongst those who engage in such practices.

The "two factor" system discussed in the story is a reasonable approach to providing stronger authentication and has been used by some banks for a while -- but it's not as bullet-proof as you might think.

Now have your say
Got something to say about today's column, or want to see what others think?  Visit The Forums

While you're here, why not visit the Aardvark Hall of Shame and perhaps make your own nomination.

The goal of this "two factor" system is to provide the legitimate user with information that would not be available to a phisher or would-be ID thief -- but the "SMS to your cellphone" method is too simplistic to be truly effective in the longer term.

It will may work more effectively when each transaction is assigned a special second-factor key, but not if it's simply used as a login-authenticator.

How can such a system be circumvented?

Quite simply actually...

The thief needs only install a trojan keylogger as normal, which sends all keystrokes and data sent too/from selected banking/financial sites back to the villain's system.

After reviewing this data at their leisure, the thief can then identify which infected PCs have been used to access large amounts of money.

A proxy trojan is then installed on that machine which works as follows...

When the legitimate user keys in the URL of a selected banking/financial site, the keystrokes requests are actually routed (unencrypted and in real-time) to the villain's computer, where they're logged before passing through an SSL layer to the requested site. The actual SSL connection only exists between the villain's PC and the banking site -- the user probably remains unaware that they're not talking directly to that site.

In effect, the user performs the login and authentication process for the thief and simply relays data in both directions *until* the logout command is given. At that stage, the villain returns a fake copy of the site's logout screen but does not pass on the logout command.

This leaves the user thinking they've logged out -- but the villain still has a valid session with the bank's site, allowing them to perform any other transaction they may choose.

What's more -- the thief can perform this slight-of hand from anywhere in the world and through a plethora of relays and proxies -- making it very difficult to track them down.

Even a transaction-based (rather than session-based) system could be thwarted using this realtime proxy system if the thief were to replace the target account number and perhaps even the amount with their own during the transaction entry process.

I wonder how long it will be before we see the first examples of this type of malware and tactic being used to siphon large amounts of money from someone's bank account.

I also wonder what government will do when it's finally demonstrated that the "two factor" authentication is not as bullet-proof as perhaps claimed and the $14.8 million they're spending still doesn't offer quite the levels of protection they may have expected.

Aardvark Forums
The forums are back up at: www.aardvarkforums.co.nz/forums, have your say on today's column

Unfortunately you'll have to re-register because we're starting the new year with a complete reinstall.

Yes, You Can Gift Money
I've published this website for the past nine years as a service to the local internet and IT industry and during all that time it has been 100% free to access. It is my intention to ensure that it remains completely free and free of charge and contains only the most sparse levels of advertising. Aardvark is not a business, it is a free resource.

If you feel that this is a good thing and/or you hold a "geniune affection" for yours truly -- then you are welcome to gift me some money using the buttons provided. In gifting this money you accept that no goods, service or other consideration is offered, provided, accepted or anticipated in return. Just click on the button to gift whatever you can afford. NOTE: PayPal bills in US dollars so don't accidentally gift more than what you were intending :-)

Contacting Aardvark
The Best of Aardvark Daily I'm always happy to hear from readers, whether they're delivering brickbats, bouquets or news tip-offs. If you'd like to contact me directly, please this form. If you're happy for me to republish your comments then please be sure and select For Publication.

Other media organisations seeking more information or republication rights are also invited to contact me.


Add Aardvark To Your Own Website!
Got a moment? Want a little extra fresh content for your own website or page?

Just add a couple of lines of JavaScript to your pages and you can get a free summary of Aardvark's daily commentary -- automatically updated each and every week-day.

Aardvark also makes a summary of this daily column available via XML using the RSS format. More details can be found here.

Contact me if you decide to use either of these feeds and have any problems.

Linking Policy
Want to link to this site? Check out Aardvark's Linking Policy.

Did you tell someone else about Aardvark today? If not then do it now!


Latest
Security Alerts
'Critical' patches released for Windows, IE
(CNet - 13/01/2005)

WinAmp blows another security fuse (Computerworld - 24/11/2004)

Flaw found in older Office versions (CNet - 8/10/2004)

Viral movies possible with RealPlayer flaw (ZDNet - 5/10/2004)

Latest
Virus Alerts
Windows worm travels with Tetris (BBC - 14/01/2005)

Net worm using Google to spread (CNet - 21/10/2004)

Trojan program poses as anti-spam screensaver (NS - 8/12/2004)

Destructive Mac virus spies on Apple users (ZDNet - 25/10/2004)

Bookmark This Page Now!

 

OTHER GREAT TECH SITES
GeekZone (NZL)
SlashDot (USA)

 

MORE NEWS
NZL Sites
IDG.Net.nz
NZ Netguide
NZ Herald Tech
PC World NZ
Scoop
WordWorx

AUS Sites
ZDNet
The Age
Australian IT
AUS Netguide
NineMSN Tech
IT News

USA Sites
Wired.com
CNet
CNNfn Tech
TechWeb
Yahoo Tech
ZDNet Tech
USA Today Tech
7am.com SciTech

UK Sites
The Register
BBC SciTech

 

My Jet Engines
Check Out Me And My Jet Engines

Today's Top News Stories


Open in New Window = open in new window
New Zealand

Open in New Window Kiwis embrace online shopping
If New Zealanders were initially slow to shop online in the early days of the internet, they certainly caught up last year...
NZ Herald

Open in New Window Datacom wins Government ID project
Kiwi IT services firm Datacom is poised to get the job of developing the technology which will let people access government services over the web using a single log-on and password...
Stuff

Other

Open in New Window Amazon founder unveils space center plans
After years of work behind closed doors, Amazon.com founder Jeff Bezos has gone public with a plan to build a suborbital space facility on a sprawling ranch under the wide open skies of West Texas...
MSNBC

Open in New Window EA to take on film and TV giants
Video game giant Electronic Arts says it wants to become the biggest entertainment firm in the world...
BBC

Open in New Window Google wants 'dark fiber'
Job listing spotlights vague plan to develop global fiber backbone. But why?...
CNet

Open in New Window ISP suffers apparent domain hijacking
Panix.com says it is working to recover its domain name and e-mail services after suffering an apparent hijacking...
CNet

Open in New Window Open-Source Biology Evolves
Can a rebel band of scientists pool patented innovation techniques and give them away through the internet...
Wired

Australia

Open in New Window 50,000 bank jobs may go to India
ANZ Bank boosted developer numbers at its Bangalore software facility in India by more than 30 per cent last year as it struggled with staff shortages and an overflow of integration work in Australia...
Australian IT

Open in New Window Austrac beefs up for e-crime fight
INTERNET payment systems such as PayPal and e-gold face extra regulation as part of a legislative package designed to stop terrorists and criminals laundering cash through offshore bank accounts...
Australian IT

Other

Open in New Window When Mice Attack
Assaf Nehoray's online ad campaign bogged down in Germany. The European businessman runs a Web marketplace for cargo firms...
NewsWeek

Open in New Window MyDoom returns
A new version of MyDoom discovered at the weekend appears months after the last iteration of the long-running series of worms...
The Register

Open in New Window Does science make room for aliens?
Decades ago, it was physicist Enrico Fermi who pondered the issue of extraterrestrial civilizations with fellow theorists over lunch, generating the famous quip: "Where are they?"...
MSNBC

Open in New Window Black hole's particle jets trigger star births
A violent jet of particles shot out from a black hole is triggering star birth in a nearby galaxy, reveal the...
CNet

Open in New Window Airbus to Unveil $16 Billion Bet on Biggest Airliner
Airbus SAS, the world's largest plane maker, tomorrow will unveil its 555-seat A380, a 12 billion-euro ($16 billion) wager that airlines will order giant aircraft to ferry passengers between major airports...
Bloomberg


Looking For More News or Information?

Google
Search WWW Search Aardvark

Privacy Policy | Copyright © 2005, Bruce Simpson, republication rights available on request

jet engine page