Security experts have detected a new type of phishing attack that could render two-factor authentication useless
A new phishing attack attempts to steal user name, password and temporary password

Phishers crack two-factor authentication

Next-generation attack spells doom for security system

Written by Tom Sanders in California

Security experts have detected a new type of phishing attack that could render two-factor authentication useless.

A dual-factor security system typically uses a password and some kind of hardware security device such as a smartcard or token that issues temporary passwords.

Smartcards are commonly used within corporations, while online transaction systems and banks opt for tokens.

The Security Fix blog reported that researchers at Secure Science Corporation spotted a phishing website targetting Citibank's Citibusiness service that attempted to steal both the user name and password as well as the temporary password issued by the security token.

The site furthermore acted as a middleman that relayed the information to the Citibank server for authentication. It prompted users if the information they entered was incorrect.

"Exactly the same kind of attacks can be used to target other types of two-factor authentication, including one-time password sheets," noted Mikko Hyppönen, chief research officer with F-Secure.

Two-factor authentication systems are considered to be safer than services that rely solely on a user name and password because the temporary passwords expire after a short time. Owners also notice when their tokens or key cards are lost.

But security researchers have warned that attackers could still use the temporary passwords in a real-time attack where they do not wait for the temporary password to expire.

"These days, typical attacks do not engage in this level of sophistication. Usernames and passwords are still collected, but it is usually some time before they are used. Two-factor authentication tokens work well for these very simple-minded attacks," commented Zulfikar Ramzan, a senior principal researcher with Symantec.

"However, if an attack is more sophisticated and the phisher can use the credentials in real time, we are the ones out of luck.

"I believe that two-factor authentication security will be almost futile when we tackle the next generation of phishing attacks."

Tags:

reader comments

related articles

 

Infosec: Surfers wary of using credit cards online

Confidence plummets as attacks soar 24 Apr 2008

Industry off guard for Mebroot attack

Current security software can't detect if a PC is infected 15 Jan 2008

UK firm touts 'digital DNA' security

Individual devices can act at fingerprints, claims ToroTech 07 Jul 2008

today's top stories

Analysis: Will IE8 cause more problems than it solves?

Microsoft's new browser may lead to compatibility issues and affect online advertising 29 Aug 2008

CIO morale plummets as crunch hits

Fewer opportunities and less responsibility depress IT managers 27 Aug 2008

The pIT stop Q&A: Should packaged software users adopt SOA?

Our expert panel answer readers' questions 29 Aug 2008

Computing podcast 28 August 2008

CIO job satisfaction plummets, and why schools' IT spending is set to top £1bn 28 Aug 2008

The definitive guide to collaboration

Five key technologies and five best practice tips to improve your collaborative IT 28 Aug 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Job of the week

Job alerts

Sign up here

Find your next job here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you recruit a student with an IT degree?

Would you recruit a student with an IT degree?

As IT student numbers plummet - would you recruit an IT graduate?

Previous poll results

Latest audio and video articles

A stressed CIOAudio

Computing podcast 28 August 2008

CIO job satisfaction plummets, and why schools' IT spending is set to top £1bn 28 Aug 2008

Bryan Glick video whiteboardVideo

The definitive guide to collaboration

Five key technologies and five best practice tips to improve your collaborative IT 28 Aug 2008

Latest in-depth articles

Myron HrycykAnalysis

General management skills are now as important as technical ability

A selection of leading chief information officers talk about what they see as the most important aspects of the role 28 Aug 2008

Internet Explorer logoAnalysis

Analysis: Will IE8 cause more problems than it solves?

Microsoft's new browser may lead to compatibility issues and affect online advertising 29 Aug 2008

Primary Navigation