Multi-Factor Authentication: Security
- r Snake Oil?
Steven Myers Rachna Dhamija Jeffrey Friedberg
Multi-Factor Authentication: Security or Snake Oil? Steven Myers - - PowerPoint PPT Presentation
Multi-Factor Authentication: Security or Snake Oil? Steven Myers Rachna Dhamija Jeffrey Friedberg Phishing & Identity Theft Historically most online banking done with passwords (single-factor authentication) Password communicated
Steven Myers Rachna Dhamija Jeffrey Friedberg
Verification
provided?
breach.
generator
challenge questions.
for MA or Transactions
button push.
usability
certificates and the ability to sign, verify, decrypt and/or encrypt.
username, nonce and password.
make malware worrisome.
Objects installed
identify it later
are presented with identifying image after username is supplied.
challenge questions.
code delivered by choice of
communication
and password places cookie
pervasiveness of mics increasing
templates.
colds, laryngitis.
prevalence is quickly growing.
measurements on face & resilient to daily changes in appearance.
surgery
requirements
keyboards.
typing rates, speed between different keys, etc....
different keyboards.
beginners, distracted, etc...
during account enrollment
corresponding to password
keyboard logger insufficient (unless done repeatedly & in conjunction)
corner (this does not change)
numbers in specified corner, corresponding to password.
attempt randomizes numbers in corners.
between current certs is non-technical: Identity of certificate requested is stringently checked.
different security indicators than previous certs.
being tricked because they are accepting bad certs.