Time based OTP are not enough!!!

Yesterday, account manager at Ferma - a construction firm), Mountain View, CA. But there was trojan on the computer initiated 27 transactions to various bank accounts, siphoning off $447,000 in a matter of minutes.

These RSA SecureID token were generating OTP based on 30s intervals still the trojan got to bypass it. OTP did what it wass suppose to do but the attack was beyond the protection level provided by the RSA token. In simply words - It was unable to protect in this form of Script in the Middle OR Trojan Attack where the transaction is intercepted and changed. Token is no protection to this form of attacks.

What all is missing -
  1. The transaction did not have any integrity enforced. The transaction did not have "sign what you see" authentication layer.
  2. There is no end to end encryption to protection the OTP or transaction details.
  3. There was no risk based engine monitoring the change in behavior of users pattern. There was no alert or threshold check to tell the user that there is money getting drained out.
To address to above, authentication platform have to provide -
  • what you know? - userid and password
  • what you have? - Time Password (strong will be Challenge based OTP)
  • sign what you see? - Transaction Signing using Token Or Out of band
  • what is user's behavior? - Risk Based Authentication
  • with whom I am communicating? - End to End Encryption make sure only right parties can communicate.
To give a complete authentication platform that will compliment "what you know? - userid and password" comes from EZMCOM in form of EzIdentity platform -
  • 1. EzToken - what you know?
  • 2. EzSign - sign what you see?
  • 3. EzCert - sign what you see with non repudaition enforcement (digital signature)
  • 3. EzWatch - Risk based authentication (coming soon)
  • 4. E2EE - End to End Encryption

We suggest to look more closely to your authentication requirement for your application(s).

We can help you out by our free authentication gap analysis for your application(s). Please get in touch with us -
  • Click here to Request a call
  • Drop me an email - vikram @ ezmcom dot com / skype out @ vikramsareen.
Have a great day.


Powered by Olark