<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Who is Hahleq? &#187; Security</title>
	<atom:link href="http://www.timrenshaw.com/blog/archives/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.timrenshaw.com/blog</link>
	<description>Tim Renshaw, that's who!</description>
	<lastBuildDate>Wed, 28 Jul 2010 07:06:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Product Watch: New Microsoft Identity Technology Aims To Protect Online Privacy &#8211; DarkReading</title>
		<link>http://www.timrenshaw.com/blog/archives/345</link>
		<comments>http://www.timrenshaw.com/blog/archives/345#comments</comments>
		<pubDate>Tue, 13 Jul 2010 21:54:30 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=345</guid>
		<description><![CDATA[Product Watch: New Microsoft Identity Technology Aims To Protect Online Privacy &#8211; DarkReading. All the way back from March.  Can&#8217;t believe I missed this for so long.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darkreading.com/security/privacy/showArticle.jhtml?articleID=223101456">Product Watch: New Microsoft Identity Technology Aims To Protect Online Privacy &#8211; DarkReading</a>.</p>
<p>All the way back from March.  Can&#8217;t believe I missed this for so long.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/345/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Chrome Extension Powers Android-Based Payments &#8212; InformationWeek</title>
		<link>http://www.timrenshaw.com/blog/archives/342</link>
		<comments>http://www.timrenshaw.com/blog/archives/342#comments</comments>
		<pubDate>Sun, 11 Jul 2010 05:22:17 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Gear]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=342</guid>
		<description><![CDATA[Google Chrome Extension Powers Android-Based Payments &#8212; InformationWeek. Interesting.  I&#8217;m going to try and see an implementation of this and see how it works with my new Android-based phone.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.informationweek.com/news/infrastructure/management/showArticle.jhtml?articleID=225702442&amp;cid=nl_tw_security_2010-07-07_t">Google Chrome Extension Powers Android-Based Payments &#8212; InformationWeek</a>.</p>
<p>Interesting.  I&#8217;m going to try and see an implementation of this and see how it works with my new Android-based phone.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/342/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another man in the middle attack verified</title>
		<link>http://www.timrenshaw.com/blog/archives/330</link>
		<comments>http://www.timrenshaw.com/blog/archives/330#comments</comments>
		<pubDate>Tue, 02 Mar 2010 17:44:15 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=330</guid>
		<description><![CDATA[Blizzard has admitted that there is an active and successful attack against their Blizzard Authenticators. Man in the middle attacks circumventing authenticators This makes perfect sense as: OTP tokens such as the Authenticator are obviously susceptible to a live man-in-the-middle (MITM) attack as has been demonstrated as something well beyond &#8220;theoritical&#8221; a decade ago.  The [...]]]></description>
			<content:encoded><![CDATA[<p>Blizzard has admitted that there is an active and successful attack against their Blizzard Authenticators.</p>
<p><a href="http://www.wow.com/2010/02/28/man-in-the-middle-attacks-circumventing-authenticators/">Man in the middle attacks circumventing authenticators</a></p>
<p>This makes perfect sense as:</p>
<ol>
<li>OTP tokens such as the Authenticator are obviously susceptible to a live man-in-the-middle (MITM) attack as has been demonstrated as something well beyond &#8220;theoritical&#8221; a decade ago.  The issue isn&#8217;t with the token vendor or type, it is with the entire scheme of a short-lived, shared secret in an increasingly real-time, share-it-and-lose-it networked world.</li>
<li>Blizzard is likely the largest OTP deployment on the planet.  They haven&#8217;t released any numbers, but if even 10% of users use it, that&#8217;s roughly 1.2 million users.  i.e. Big ROI.</li>
<li>There&#8217;s money in &#8220;them thar accounts&#8221;.</li>
</ol>
<p><strong>What can you do?</strong></p>
<ul>
<li>All the normal things, run anti-virus, anti-spyware, etc.</li>
<li>Log into WoW from as few PCs as possible and only those you absolutely control.</li>
<li>Try to log into any web page that requires authenticator authentication as little as possible, as a man-in-the-middle attack in a browser doesn&#8217;t require a local keylogger file as is being used in this current attack</li>
</ul>
<p><strong>What can Blizzard do?</strong></p>
<ul>
<li>The obvious:
<ul>
<li>I believe their thick client already scans for a large number of known attack libraries, files, etc. at the time of launch.  This will be added to the list.</li>
<li>I also suspect they are looking for suspicious behavior to the extent that they can with the client.  This type of behavior should be added to the list for that.  Also, they may want to consider increasing the terms and conditions of what we allow them to do in the client with regard to looking for vulnerabilities and suspicious behavior.</li>
</ul>
</li>
<li>Less Obvious:  Blizzard should seriously consider having a separate authentication mechanism for getting into the game client than for logging into the various portions of Battle.Net / WorldofWarcraft.com / etc.  Why?
<ul>
<li>The more times you use the Authenticator, the more opportunities you have to be compromised.</li>
<li>Blizzard has more controls and capabilities to protect the login through their seriously &#8220;thick&#8221; client to provide additional protections to the authenticator login.</li>
<li>Blizzard has much less control over the login environment and ability to monitor what is happening in a web-based authentication with an authenticator.  This current attack is heavy-weight in regards to payload necessary to pull it off.  A successful MITM attack in a web login requires much less work and no payload (client software installed) to execute.</li>
<li>What does the attacker want access to, my WoW account details or the stuff on my various characters, in my banks or my guild&#8217;s banks?  Go look at what is on file in your &#8220;My Account&#8221; section. Ask yourself:
<ul>
<li>What is there that an attacker couldn&#8217;t get more readily and simply somewhere else given Blizzard is following good practices with regard to what details are shown, masked, etc.?</li>
<li>What can the attacker do to you there?  Change your password?  Why bother when I can steal both your static password and dynamic password in a simple web-based MITM attack?  As you now realize, an attacker only need to compromise you one time.  They don&#8217;t need to have a reusable password.</li>
<li>How about turn off your authenticator?  Hopefully you would stop and think seriously about providing the serial number of your Authenticator if asked outside of your specifically intending to turn it off.</li>
</ul>
</li>
</ul>
</li>
<li>My suggestion to Blizzard is to consequently move authenticator management and use completely into the WoW client and only ever ask for the Authenticator code from within the client for game session login.  Enable the ability and strongly suggest to users that they use a separate password for Battle.Net web page logins (sans Authenticator) and another separate password to use in the game client with your Authenticator).</li>
<li>Lastly, and I know from first-hand experience in discussing this with Blizzard devs that this probably won&#8217;t fly, but seriously consider offering additional forms of authentication that aren&#8217;t susceptible to MITM attacks.  I know the alternatives aren&#8217;t as globally friendly for all our WoW brethren that login from shared network cafe PCs, but that&#8217;s not the whole market and those of us not constrained in that fashion would like something better if you offered it.  More work for you, yes.  Better security for us and retention of us as customers, yes.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/330/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FBI Investigating Web Spycam</title>
		<link>http://www.timrenshaw.com/blog/archives/324</link>
		<comments>http://www.timrenshaw.com/blog/archives/324#comments</comments>
		<pubDate>Wed, 24 Feb 2010 19:20:06 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=324</guid>
		<description><![CDATA[FBI Investigating Web SpycamAs a federal investigation begins, a security researcher has uncovered evidence related to the case and provided a way to identify the surveillance software via FBI Investigating Web Spycam &#8212; InformationWeek. This is a case and investigation to keep an eye on.]]></description>
			<content:encoded><![CDATA[<p>FBI Investigating Web SpycamAs a federal investigation begins, a security researcher has uncovered evidence related to the case and provided a way to identify the surveillance software</p>
<p>via <a href="http://www.informationweek.com/news/security/privacy/showArticle.jhtml?articleID=223100403&amp;cid=nl_tw_security_2010-02-24_t">FBI Investigating Web Spycam &#8212; InformationWeek</a>.</p>
<p>This is a case and investigation to keep an eye on.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/324/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Engineering Scammers Offer Live Support</title>
		<link>http://www.timrenshaw.com/blog/archives/305</link>
		<comments>http://www.timrenshaw.com/blog/archives/305#comments</comments>
		<pubDate>Wed, 17 Feb 2010 23:13:14 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=305</guid>
		<description><![CDATA[Social Engineering Scammers Offer Live Support &#8212; InformationWeek. Can&#8217;t be too careful out there.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=222900276&amp;cid=nl_tw_security_2010-02-17_t">Social Engineering Scammers Offer Live Support &#8212; InformationWeek</a>.</p>
<p>Can&#8217;t be too careful out there.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/305/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security chip that does encryption in PCs hacked</title>
		<link>http://www.timrenshaw.com/blog/archives/303</link>
		<comments>http://www.timrenshaw.com/blog/archives/303#comments</comments>
		<pubDate>Wed, 17 Feb 2010 22:35:00 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=303</guid>
		<description><![CDATA[Tarnovsky figured out a way to break chips that carry a &#8220;Trusted Platform Module,&#8221; or TPM, designation by essentially spying on them like a phone conversation. Such chips are billed as the industrys most secure and are estimated to be in as many as 100 million personal computers and servers, according to market research firm [...]]]></description>
			<content:encoded><![CDATA[<p>Tarnovsky figured out a way to break chips that carry a &#8220;Trusted Platform Module,&#8221; or TPM, designation by essentially spying on them like a phone conversation. Such chips are billed as the industrys most secure and are estimated to be in as many as 100 million personal computers and servers, according to market research firm IDC.</p>
<p>via <a href="http://www.google.com/hostednews/ap/article/ALeqM5j-OodvoFRhEcpfvnK5C7YL6JWJBQD9DO79A81">The Associated Press: Security chip that does encryption in PCs hacked</a>.</p>
<p><strong>Now for the really cool &#8220;how&#8217;d he do it?&#8221; part:</strong></p>
<p><span style="font-family: Arial, sans-serif; line-height: 18px;"></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;">Tarnovsky needed six months to figure out his attack, which requires skill in modifying the tiny parts of the chip without destroying it.</p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;">Using off-the-shelf chemicals, Tarnovsky soaked chips in acid to dissolve their hard outer shells. Then he applied rust remover to help take off layers of mesh wiring, to expose the chips&#8217; cores. From there, he had to find the right communication channels to tap into using a very small needle.</p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;">The needle allowed him to set up a wiretap and eavesdrop on all the programming instructions as they are sent back and forth between the chip and the computer&#8217;s memory. Those instructions hold the secrets to the computer&#8217;s encryption, and he didn&#8217;t find them encrypted because he was physically inside the chip.</p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;">Even once he had done all that, he said he still had to crack the &#8220;huge problem&#8221; of figuring out how to avoid traps programmed into the chip&#8217;s software as an extra layer of defense.</p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;">&#8220;This chip is mean, man — it&#8217;s like a ticking time bomb if you don&#8217;t do something right,&#8221; Tarnovsky said.</p>
<p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/303/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Texas Bank Sues Customer After $800,000 Scam</title>
		<link>http://www.timrenshaw.com/blog/archives/299</link>
		<comments>http://www.timrenshaw.com/blog/archives/299#comments</comments>
		<pubDate>Wed, 03 Feb 2010 01:24:56 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Economics]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=299</guid>
		<description><![CDATA[Texas Bank Sues Customer After $800,000 Scam. So either the bank&#8217;s supposed &#8220;two-factor&#8221; solution flat out failed (seriously arguable that an IP address is a legitimate &#8220;what you have&#8221; factor, IMHO) or they processed it anyway?  It will be interesting to see how this plays out. Looks like another case of sacrificing security at a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.bankinfosecurity.com/articles.php?art_id=2132">Texas Bank Sues Customer After $800,000 Scam</a>.</p>
<p>So either the bank&#8217;s supposed &#8220;two-factor&#8221; solution flat out failed (seriously arguable that an IP address is a legitimate &#8220;what you have&#8221; factor, IMHO) or they processed it anyway?  It will be interesting to see how this plays out.</p>
<p>Looks like another case of sacrificing security at a real world cost for ease-of-use roughly tied into my most recent previous post.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/299/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Passwords remain weakest link in Web security &#124; Service-Oriented Architecture &#124; ZDNet.com</title>
		<link>http://www.timrenshaw.com/blog/archives/297</link>
		<comments>http://www.timrenshaw.com/blog/archives/297#comments</comments>
		<pubDate>Wed, 03 Feb 2010 01:18:00 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=297</guid>
		<description><![CDATA[From the Department of Duh, really? Passwords remain weakest link in Web security &#124; Service-Oriented Architecture &#124; ZDNet.com. Frustrating that with all the focus on SSO without security (I&#8217;m talking to you OpenID folks) and all the security technologies available to grant both security and SSO (or Reduced Sign-On for you &#8220;SSO is impossible&#8221; folks) [...]]]></description>
			<content:encoded><![CDATA[<p>From the Department of Duh, really?</p>
<p><a href="http://blogs.zdnet.com/service-oriented/?p=3990&amp;tag=nl.e540">Passwords remain weakest link in Web security | Service-Oriented Architecture  		| ZDNet.com</a>.</p>
<p>Frustrating that with all the focus on SSO without security (I&#8217;m talking to you OpenID folks) and all the security technologies available to grant both security and SSO (or Reduced Sign-On for you &#8220;SSO is impossible&#8221; folks) this hasn&#8217;t been addressed.  I chalk it up to a lack of vision on certain IP holders and cowardice of those in a position to implement something real  vs. never-ending &#8220;play projects&#8221;.  Time for these folks to create some momentum (banks, huge portals, OS providers, large retailers, etc.).  Time to get serious about providing real security starting at the point of authentication at which point a huge amount of powerful innovation in services could begin (emergence of the mythical semantic web).</p>
<p>Of course, till the current governmental economic dithering ends (reduce taxes and quit spending us into slavery), who wants to make an admittedly large entrepreneurial bet right now?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/297/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Strong Authentication Not Strong Enough, says Gartner</title>
		<link>http://www.timrenshaw.com/blog/archives/277</link>
		<comments>http://www.timrenshaw.com/blog/archives/277#comments</comments>
		<pubDate>Wed, 16 Dec 2009 21:24:00 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[Digital Life]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=277</guid>
		<description><![CDATA[Strong Authentication Not Strong Enough &#8212; InformationWeek. December 14, 2009 05:05 PM]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=222001977&amp;cid=nl_tw_security_2009-12-16_h">Strong Authentication Not Strong Enough &#8212; InformationWeek</a>.</p>
<p><span class="storyDate" style="line-height: 20px; margin-left: 2px;">December 14, 2009 05:05 PM </span><br />
<!--body--></p>
<p><span id="articleBody"></span></p>
<div class="IntelliTXT"><!-- droplet bean="/cmp/shared/apps/search/droplets/HighlightKeywords"></p>
<param name="str" value="param:element.body">
<param name="keywords" value="param:queryText">
<param name="startTag" value="`"<B style=\""+"color:black;background-color:#ffff66"+"\">&#8220;`&#8221;></p>
<param name="closeTag" value="</B>&#8220;> <oparam name="output" -->Two-factor authentication &#8212; used to protect online bank accounts with both a password and a computer-generated one-time passcode &#8212; is supposed to be more secure than relying on a single password.But Gartner Research VP Avivah Litan warns that cyber criminals have had success defeating two-factor authentication systems in Web browsing sessions using Trojan-based man-in-the-middle attacks.</p>
<p><script type="text/javascript"></script><!-- mSpokeSection: [recommendations?channels=whitepaper:2,webcast:2,report:2,video:3&#038;itemid=222001977&#038;cid=sec] --></p>
<div id="more_security_insights" style="padding-right: 15px;">
<div class="mspoke_widget">
<div class="mspoke_widget_wrapper group2 "><!-- user:? item:222001977 group:2 (session) --></div>
</div>
</div>
<p>A <a href="http://www.gartner.com/it/page.jsp?id=1254413"><span style="color: #0f4692;">Gartner Research note</span></a> written by Litan explains that in the past few months, Gartner has heard from many banks around the world that rely on one-time-password authentication systems. Accounts at these banks have been compromised by man-in-the-middle attacks &#8212; the report uses the term &#8220;man-in-the-browser&#8221; &#8212; despite the use of two-factor security.One technique that the fraudsters have been using to bypass security controls is call forwarding.</p>
<p>&#8220;[B]anks that rely on voice telephony for user transaction verification have seen those systems and processes compromised by thieves who persuade telecom carriers to forward legitimate user phone calls to the thief&#8217;s cell phone,&#8221; the report says. &#8220;These targeted attacks have resulted in theft of money and/or information, if the bank has no other defenses sufficient to prevent unauthorized access to their applications and customer accounts.&#8221;</p>
<p>A man-in-the-middle attack involves using software or hardware to intercept network traffic then send it to its destination so that the information can be used without the knowledge of the sender or the intended recipient.</p>
<p>In an e-mail, Litan said that the attacks have involved the Zeus Trojan and other customized malware.</p>
<p>The malware sometimes uses anti-forensic capabilities that re-write account balances in the user&#8217;s browser, so that the user believes his or her bank account has the funds it should, even through it is empty.</p>
<p>The Gartner report recommends addition defenses to monitor user behavior and/or transaction values, as well as out-of-band transaction verification.</p>
<p>According to the Internet Crime Complaint Center, which issued <a href="http://www.ic3.gov/media/2009/091103.aspx"><span style="color: #0f4692;">a warning</span></a> about attacks on commercial bank accounts in November, total losses as of October amounted to about $100 million so far this year.</div>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/277/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Consumers Accept Device Fingerprinting, Study Finds &#8212; InformationWeek</title>
		<link>http://www.timrenshaw.com/blog/archives/262</link>
		<comments>http://www.timrenshaw.com/blog/archives/262#comments</comments>
		<pubDate>Wed, 23 Sep 2009 22:21:28 +0000</pubDate>
		<dc:creator>Tim</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.timrenshaw.com/blog/?p=262</guid>
		<description><![CDATA[Consumers Accept Device Fingerprinting, Study Finds &#8212; InformationWeek. Much as I&#8217;d like to say that consumers aren&#8217;t so much against &#8220;working for&#8221; strong authentication as they are at recognizing that KBA isn&#8217;t actually providing any security, at least the results are the same.  KBA is being rejected.  KBA doesn&#8217;t protect against even phishing and is [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=220000765&amp;cid=nl_tw_security_txt">Consumers Accept Device Fingerprinting, Study Finds &#8212; InformationWeek</a>.</p>
<p>Much as I&#8217;d like to say that consumers aren&#8217;t so much against &#8220;working for&#8221; strong authentication as they are at recognizing that KBA isn&#8217;t actually providing any security, at least the results are the same.  KBA is being rejected.  KBA doesn&#8217;t protect against even phishing and is just another set of hard to remember and manage passwords.</p>
<p>I still contend that users will definitely work for and even pay for strong authentication if they believe it is effective and if they believe what they are protecting has value to them.  Why should I worry about my credit card being compromised when I know my liability is limited to $50 or some such manageable number.  Heck, my credit card has been stolen a couple times via physical POS situations and it has never cost me any out of pocket money and at worst a couple minutes on the phone with my credit card company.  Of course, it does cost me something as the losses to merchants and banks end up reflected back to me in increased fees, rates, etc., but all that disappears into the great &#8220;cost of doing business&#8221; economic effect.</p>
<p>Which then brings up the question as to why financial institutions, merchants, etc. aren&#8217;t looking to reduce their costs and increase their margins by offering strong authentication to:</p>
<ul>
<li>Give themselves a competitive edge over their competitors on margin</li>
<li>Give themselves a competitive edge in customer loyalty by taking better care of their customers</li>
<li>Offer price breaks and other incentives for customers that use offered strong authentication mechanisms</li>
</ul>
<p>One of the online communities I spend time in has actually begun to self-regulate itself along the lines of those that use strong authentication and those that don&#8217;t.  Want to participate with a group in that community?  You have to use strong authentication offered in the context of that community.  You don&#8217;t have to, but if you don&#8217;t you are precluded from interactions with the &#8220;better elements&#8221; of that community.</p>
<p>Just something to consider.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.timrenshaw.com/blog/archives/262/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
