Continuing the theme of e-mail/Internet security.
Tonight I wanted to set up a new bill payment. The bank, in response to customer paranoia about Internet security and phishing attacks now require me to carry my bank cards and their calculator like number generator that I now have to take with me on business if I want to set up a bill payment. No thanks. No, I don't want to trail a variety of calculator like devices around with me one for each account or service I might want to use. I think the encryption offered by the bank site together with the random letters and digits from a security password is secure enough.
However, aside from that, let us now look at the two options the bank presents:
1. Log onto the website, have it over a secure encrypted channel, type in a customer number securely, random digits from two separate passwords securely and use the calculator device to randomly generate a number. Pretty secure huh?
2. Alternatively, use a phone, have the conversation in clear text, have the audible key presses recordable by anyone in earshot with a microphone, no need for the card reader calculator device either. Set up bill payment successfully.
Does the analogy of having 50 billion million trillion zillion locks on your front door and only 1 on your back door apply here?
Which way do you think a burglar would want to break in?
Why do banks and other sites continue to believe that the phone is a secure means of communication?
By Craig Cockburn, IT Professional from Scotland. Critical Thinking, Agile Delivery, Politics and Society
Total Pageviews
Subscribe to:
Post Comments (Atom)
Popular Posts
-
I've been having a busy time over on the Cambrian House site lately. Check out my profile and the full set of awards I completed last ...
-
It has always surprised me that in the US, where holidays are valued and children get about 6 weeks more annual holiday than the UK, that ad...
-
Consider this imaginary scenario. You're a bouncer at a nightclub wondering whether to let people in. Two people wait to get in. One in ...
-
The cost of courses - Over priced or justified? Back in 1997 I did a Higher via evening classes of about 2 hours each. The cost of about 1...
-
I thought I would write this to document the ongoing problems I have with my Nokia N97. It seems from the conversation in the phone shop tod...
-
Every time I go to the post office there's a queue. No matter how much they try and keep the queue length down, inevitably you get stuck...
-
I got a note through the letter box earlier this week. "We're sorry, we haven't been able to deliver your phone book, it has be...
-
Introduction You may be wondering the significance of the three Scottish flags in the image. I took this picture a few weeks ago. I...
-
Communication is not only the key to a successful relationship but communication is the key to being a great manager and running a business....
-
When Extreme Programming (XP) began in the late 1990s, it started a revolution in software engineering which through the Agile manifesto i...
No comments:
Post a Comment