Comment on Tutorial - The Failure of 2FA / Two-Factor Authentication By Bruce Schneier



Comment Added by : Joe Bloggs

Comment Added at : 2013-04-22 13:40:24

Comment on Tutorial : The Failure of 2FA / Two-Factor Authentication By Bruce Schneier
All true, but the 2FA that has been implemented for some years by my bank (Barclays) requires transaction details (e.g. amount and destination account number) to be keyed into the authentication token (which has its own keypad) and the signed response to be keyed into the website.

The token uses the crypto module on my bank card's chip, so is a relatively cheap device interchangeable which is between all of the bank's customers.

This mitigates against both trojans and MITM as it prevents the attacker from performing any malicious activity once logged in without somehow getting me to enter their chosen amount and account number into the signing device (albeit they can still view my account statements, which may also be undesirable).

I'm pretty sure that Barclays are not the only bank in the UK to adopt this approach, and would be surprised if other countries had not also followed suit. Of course, the US are still to adopt chips on bank cards, so are many years behind the rest of the world on this one.


View Tutorial



Ask a Question

Subscribe to Tutorials

Related Tutorials

Program using concept of byte long short and int in java

Update contents of a file within a jar file

Tomcat and httpd configured in port 8080 and 80

Java File

Java String

Count number of vowels, consonants and digits in a String in Java

Reverse a number in Java

Student marks calculation program in Java

Handling Fractions in Java

Calculate gross salary in Java

Calculate average sale of the week in Java

Vector in Java - Sample Program

MultiLevel Inheritance sample in Java

Multiple Inheritance sample in Java

Java program using Method Overriding

Archived Comments

1. I didnt get the use of public Sting toString().. I
View Tutorial          By: Pradesh at 2010-05-06 05:38:23

2. left shift output is wrong, for this results so ma
View Tutorial          By: naga sudha at 2011-04-20 04:26:40

3. hello
i have a final studie project that sp

View Tutorial          By: samer at 2011-08-18 07:39:25

4. Can Some body help me??
i want To show date

View Tutorial          By: saif at 2013-04-29 09:22:31

5. hi frnds help me please .javamail program not bee
View Tutorial          By: sella at 2011-10-05 18:33:22

6. Very informative and simple to understand. Thank y
View Tutorial          By: Rosa Vladivord at 2012-12-23 13:00:52

7. Please send me application for sending message on
View Tutorial          By: jigar at 2011-12-21 11:53:48

8. I want to use concept of overriding and i want to
View Tutorial          By: Aniket at 2013-06-20 10:23:10

9. nice
View Tutorial          By: ravi at 2010-11-26 02:46:56

10. error is main fuuction declaration
void mai

View Tutorial          By: T.M.Prakash.MCA. at 2012-09-20 12:26:52