SC Magazine on whether or not authentication is sufficient
Charles Jeter, myself, and a few others have been having an interesting email discussion over the weekend. The discussion was around whether or not the rumored updates to the FFIEC guidelines will be sufficient.
Many people are saying that the guidelines are going to re-emphasize that financial institutions need to have strong authentication mechanisms in place. While that is necessary, my belief is that because of technology like Zeus, strong authentication is not sufficient.
In the email thread there was some discussion on the definition of “authentication”. The point being made was that authentication can mean verifying identity OR verifying legitimacy. My stance is that most people know the first definition and not the second.
Read more on the first part of the article here.
-
Archives
- May 2012 (5)
- April 2012 (7)
- March 2012 (13)
- February 2012 (6)
- January 2012 (4)
- December 2011 (7)
- November 2011 (8)
- October 2011 (9)
- September 2011 (5)
- August 2011 (7)
- July 2011 (7)
- June 2011 (6)
-
Categories
- behavior analysis
- business logic abuse
- Business Logic Flaw
- Business Process Abuse
- Compliance
- Cost of fraud
- Data Loss
- Detection
- education
- Fraud
- Gaming
- General
- information security
- Investigation
- Man-in-the-Browser
- Online Fraud
- Payment
- Phishing
- predictive analytics
- Prevention
- risk management
- Social engineering
- Social Networks
- Trust
- Uncategorized
- web logic abuse
- Zeus
-
RSS
Entries RSS
Comments RSS

