<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: False-Positive Trust</title>
	<atom:link href="http://securitymusings.com/article/421/false-positive-trust/feed" rel="self" type="application/rss+xml" />
	<link>http://securitymusings.com/article/421/false-positive-trust</link>
	<description>Rants and raves from information security professionals</description>
	<lastBuildDate>Fri, 03 Feb 2012 13:03:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Walt</title>
		<link>http://securitymusings.com/article/421/false-positive-trust/comment-page-1#comment-412</link>
		<dc:creator>Walt</dc:creator>
		<pubDate>Thu, 11 Sep 2008 14:38:26 +0000</pubDate>
		<guid isPermaLink="false">http://securitymusings.com/?p=421#comment-412</guid>
		<description>A proxy-style phishing site could go to the real site and grab the picture as it was fooling the user.  You would only need to know a few similar &quot;something you know&quot; factors, like the account number, and the answers to the flimsy security questions the user had set up.  A phishing site could easily ask the user for this info, and then relay it to the real site to obtain the picture, which it would then display to the user, Alice-Eve-Bob &quot;man in the middle&quot;-style.

I don&#039;t think the SiteKey was really touted as an extra authentication factor (although it may have been).  It&#039;s a server authentication mechanism, not client.</description>
		<content:encoded><![CDATA[<p>A proxy-style phishing site could go to the real site and grab the picture as it was fooling the user.  You would only need to know a few similar &#8220;something you know&#8221; factors, like the account number, and the answers to the flimsy security questions the user had set up.  A phishing site could easily ask the user for this info, and then relay it to the real site to obtain the picture, which it would then display to the user, Alice-Eve-Bob &#8220;man in the middle&#8221;-style.</p>
<p>I don&#8217;t think the SiteKey was really touted as an extra authentication factor (although it may have been).  It&#8217;s a server authentication mechanism, not client.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Hesse</title>
		<link>http://securitymusings.com/article/421/false-positive-trust/comment-page-1#comment-411</link>
		<dc:creator>Peter Hesse</dc:creator>
		<pubDate>Thu, 11 Sep 2008 13:59:14 +0000</pubDate>
		<guid isPermaLink="false">http://securitymusings.com/?p=421#comment-411</guid>
		<description>Reminds me of the article we had written some time ago, &quot;Wish it was two factor&quot;:http://securitymusings.com/article/182/wish-it-was-two-factor based on a DailyWTF article.  For example your bank&#039;s SiteKey.  Is that really helping?  No, it&#039;s the opposite.  If I break into your account, I also now learn your secret picture, which I can share with you next time you think you&#039;re logging in to the bank.</description>
		<content:encoded><![CDATA[<p>Reminds me of the article we had written some time ago, &#8220;Wish it was two factor&#8221;:<a href="http://securitymusings.com/article/182/wish-it-was-two-factor" rel="nofollow">http://securitymusings.com/article/182/wish-it-was-two-factor</a> based on a DailyWTF article.  For example your bank&#8217;s SiteKey.  Is that really helping?  No, it&#8217;s the opposite.  If I break into your account, I also now learn your secret picture, which I can share with you next time you think you&#8217;re logging in to the bank.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

