18 ms·
Worse Than Useless: Personal Security Images
- dfc 14y agoThe article fails to recognize the value of the "security images" to the banks. The banks have used these images to satisfy the requirements of the FFIEC guidance "Authentication in an Internet Banking Environment"[1]. Any complaints about the value of the security images should not be addressed to banks. You should direct your complaints to the FFIEC and/or to your banks regulator (OTS, OCC or NCUA). [1] http://www.ffiec.gov/pdf/Auth-ITS-Final%206-22-11%20%28FFIEC%20Formated%29.pdf http://www.ffiec.gov/pdf/Auth-ITS-Final%206-22-11%20%28FFIEC...
- latimer 14y agoInteresting, I've always wondered why so many banks use this system online instead of something more robust like two-step auth.
- dfc 14y agoThe only reason the banks use these systems to begin with is the FFIEC guidance. These "improvements" were not voluntarily put in place by forward thinking bankers, they had to because their regulators told them to. So it is all about the cost of the system. Before anyone says Chase/HSBC makes X billion dollars profit keep in mind that these regulations also apply to smaller community banks with 5 Billion in holdings. Keep this in mind when you assess any of these systems; the authentication systems are not put in place to manage customer risk, they are put into place to manage regulatory risk.
- mortehu 14y agoWhen I signed up for USAA, by default they had a silly authentication system based on "security questions". I was very disappointed until I found out that they support several mechanisms, and allow you to disable the ones you won't use. Hence, I use the one where I combine my password with a token generated by a mobile app. Maybe other banks have alternate authentication mechanisms stashed away as well?
- snowwrestler 14y agoThey do. Bank of America, which to my knowledge is the largest bank that still uses the "security image", also allows users to enable 2-factor authentication via SMS.
- yourapostasy 14y agoNot just via SMS, but you can also purchase a token card called a SafePass.
- svachalek 14y agoI've only seen two step used to validate the user to the server. Are there sites that use two step to verify the server to the client?
- gojomo 14y agoAre they the people to blame for the 15-minute bank login timeouts everywhere, too? Because I can't think of a more frustrating and anti-security policy that claims to be "for your security". (By requiring many more repeated logins, the risk rises that I'll slip one time and not carefully check that the DNS/SSL info is correct.)
- Firehed 14y agoIt's a trade off between that and allowing some random stranger to transfer your money if you get up and forget to lock your computer. Our first alpha didn't have the auto-logout and by far the most common piece of feedback we got was that we needed it.
- nikcub 14y agoIt isn't just if you step away from a computer. A session token that never expires is as good as a password, but with weaker protection. If I intercept a session token via a proxy, network dump, XSS or browser bug I can use it and replay it at any time in the form it was intercepted. Passwords get sent once and are usually protected and encrypted or hashed on the server. Session tokens are not, hence why they need to be temporary.
- gojomo 14y agoHolding everything else constant, shorter session tokens reduce one avenue of exploitation, yes. But everything else isn't constant: shorter sessions mean more password-typing-transactions, and especially into older tabs that have a "logout successful for your protection" message. That increases the risk of a successful phish, including by the same vulnerabilities you fear could compromise a session token. And practically, the problem with a password compromise is that it gives access to a indefinite stream of new session tokens. So there's a balance between session-token-risks and login-transaction-risks. I doubt 15 minutes is the optimal tradeoff time -- I'm sure it isn't for me, with my habits on my own computers, and I haven't seen any rigorous evidence it's the right level for the banking masses. Its maddening uniformity across the industry "smells like" an arbitrary check-box from some regulatory document somewhere.
- nwh 14y agoGreat, they're probably responsible for this too. Every time you try and use a new tab or navigation (back, forward, refresh) on my banks website, you get kicked out to the main page. It's like someone has never heard of form keys. http://i.imgur.com/erm0faA.png http://i.imgur.com/erm0faA.png
- Firehed 14y agoI skimmed the PDF and didn't see what you're referring to; however, I did see it explicitly point out the ineffectiveness of "security" questions.
- dfc 14y agoThis all started with the first supplement the FFIEC put out regarding authentication in an internet environment in 2005[1]. This initial supplement was put out to clarify what was expected of banks especially with regards to the FFIEC examination handbooks regarding e-banking[2] and information security[3]. (This all began with 12CFR30B[4][5]) Are you familiar with reading federal regulator-ese? They do not ever come out and make blanket statements such as use XYZ, ensure X bit keys and so on. The entire process is based on the banks and the examiner's interpretation of the bank's risk profile. If you are interested in learning more about this reading some of the banking industry press coverage at the time may be easier to digest. [1] http://www.ffiec.gov/bsa_aml_infobase/documents/new_5_2007/OCC/BL_2005_35.pdf http://www.ffiec.gov/bsa_aml_infobase/documents/new_5_2007/O... [2] http://ithandbook.ffiec.gov/it-booklets/e-banking.aspx http://ithandbook.ffiec.gov/it-booklets/e-banking.aspx [3] http://ithandbook.ffiec.gov/it-booklets/information-security.aspx http://ithandbook.ffiec.gov/it-booklets/information-security... [4] http://ithandbook.ffiec.gov/media/21989/occ-12cfr30-safe_sound_standards.pdf http://ithandbook.ffiec.gov/media/21989/occ-12cfr30-safe_sou... [5] I say 12cfr30b because that is what got the ball rolling for OCC regulated banks and at the time I worked for an OCC regulated bank. Depending on who the regulator (OTS, NCUA, etc) is the "ball rolling document" will be different.
- ryen 14y agoNot a lot of information regarding security images in there and not all banks use them. BofA does, but not Chase. Therefore I have to assume its some lame compliance committee within the bank determining usage.
- dfc 14y agoYou are safe assuming that risk managment at banks is not implemented uniformly across the industry. Were you expecting it to say "security images are required"?
- deleted 14y ago[deleted]
- mrslx 14y agoPasswords ID you to the entity. Images ID the entity to you. While not a perfect system, it works to some degree IMO. I still prefer two-fold auth.
- DenisM 14y agoThe image does not ID the system to you, that's the whole point of the article! A spoofer site would simply go to the spoofed site, fetch the image, and give it to you.
- derefr 14y agoTheoretically, the image could be stored as a blob in your localStorage, encrypted with the server's public key. When you go to the bank's site, a bit of AJAX pops it up to them, they decrypt it server-side, then serve it back to you as an image (all over SSL, please.) The phisher can try to do all the same steps, but without the originator's private key, they'll be left with a useless encrypted blob that can't be turned into a servable image.
- cookiecaper 14y agoWill never happen because it would make it way too hard to access your account on other computers.
- Gigablah 14y agoThe way this mechanism works, you're supposed to go through the image personalization step on each computer you access the account with anyway. (And if you use localStorage, that makes it per-browser).
- cookiecaper 14y agoRight, it doesn't verify the entity with 100% certainty, but it's still probably a good thing to have, because it should be a relatively simple change in the bank's code and it creates a lot of extra work for an attacker. It's just another safeguard, and I think it does a fine job being that. It's not meant as an iron-clad, utterly impenetrable phishing prevention mechanism. If OP believed that, perhaps he is the gullible one.
- tghw 14y agoSecurity is not about guaranteeing anything, it's about making it more difficult to break in. The lock on your front door does nothing to guarantee a burglar won't enter your home, it just makes it more difficult to do so. The examples he gives either have the potential of alerting the user to the spoof (via the missing image) or require significantly more work to spoof the user (via a complex proxy at the router level or obtaining a homographic URL). Either way, the barrier to stealing users credentials has gone up, which is exactly what security measures are intended to do. Hardly useless, and definitely not "worse than useless".
- yid 14y agoComplex proxy?? You mean a headless browser like phantomjs and a slightly higher latency apparent to the client. Hardly difficult, which leads to the false sense of security these images provide. It's made slightly harder on the order of minutes to write a few extra lines of code.
- nmcfarl 14y agoI'm always surprised when I write a scraper/proxy (usually in perl) at how little added latency is involved. If I host the thing on a fat pipe (say an EC2 instance), it's not even noticeable at home.
- pbreit 14y agoIt would probably need to be more complex than that if the bank is watching for unexpected activity from individual IP addresses.
- tghw 14y agoThe code for the proxy itself isn't that complex, no. But it would have to be tailored to the target's banking site. Again, not extremely complex, but more difficult. And actually implementing the attack, including getting a homographic URL or rouge router, is quite a bit more difficult. Again, the point is that the security image makes the attackers' lives more difficult. The image lends no "false sense of security" because without the image, you'd have the same sense of security.
- Hello71 14y agoUnless, of course, a reasonable implementation were used, tying the image to a cookie and using the browser security to prevent it being sent to different domains; if you're on a subdomain of a bank already, there are far more effective ways to execute an attack.
- krallin 14y agoExactly. Any proper implementation of this kind of security should not depend on the username, this would entirely break the purpose.
- mortehu 14y agoBank of America ties it to your user name, which is one of the reasons I quit using them.
- boydster2 14y agoThis is exactly how Yahoo implemented this. The downside is that you have to select a new "sign in seal" for each browser/computer that you use.
- jtokoph 14y agoAll an attacker has to do is present the "we don't remember this computer" screen and ask them to setup a new image once they "log in".
- schabernakk 14y agoBMO, Bank of Montreal uses these along with a security phrase. Its absolutely ridiculous that this is mandated by some standard, but there is no guidance on password strength itself. BMO has a strict only 6 characters (no more, no less) policy. Oh yeah, before anyone asks: No numbers, no special characters. Choosable by the customer when opening the account.
- cookiecaper 14y agoI find password restrictions often prohibit good but unconventional password models, like the "actual phrase for a passphrase" crowd. I think the possibility of an online brute force should already be near-zero for banking apps, and if an offline brute force attack can be conducted, it's likely that a) your password isn't going to matter much anymore and b) the typically arbitrary password requirements set up by the site aren't going to do much to stop any significant GPU-based hash attack. The issue is that most people rely on memory to store passwords. Any term that is memorable and meets most online password "standards" is short enough for an offline brute force to break pretty quickly, especially if the attacker has some decent resources. The answer to this is "real phrase" passphrases, but many sites with password rules won't allow these.
- politician 14y agoAlso, per xkcd, et. al., rate limiting login attempts on a per-user and global basis significantly increases the difficulty of brute-forcing access even given password frequency lists.
- duaneb 14y ago> BMO has a strict only 6 characters (no more, no less) policy. At what point can you start suing for negligence of proper precautions protecting your money?
- cbhl 14y agoIIRC, most of these banks have insurance to cover that case, so in theory you shouldn't lose any money provided you notify them in a timely manner of unauthorized transactions.
- Havoc 14y agoI kinda like my bank's implementation of it: Social security number equivalent for username, then you get the security phrase on the same page where you type in the password, then you get a two factor auth page (cellphone). So it helps for when you fuck up the username or something else is weird, but security doesn't really rely on it. Though I don't think there are any banks in my country that don't use 2 factor, so its a bit of a moot point anyway.
- KMag 14y agoCount yourself lucky for living in a country where your national ID number isn't assumed to be some kind of non-revokable terrible 9-digit pencil-and-paper OAuth token that's shared with half the world. I'm told that Norway's tax IDs are considered no less secret than phone numbers. Coming from the US, I mis-parsed your post as (Social Security number) (equivalent for username) on first read and thought "That's so backwards! They're treating SSNs as less important than passwords". It's probably better to say "national ID number" or "national tax ID" rather than "Social security number equivalent".
- Joe_Knapp 14y agoIt may not be a high-security system, but it is an effective way to limit tech-support calls. All too often a user will enter the wrong username, or worse for a old style bank uses account numbers, they'll type in the wrong account number. Then when their password doesn't work, they contact tech support, normally by telephone. So by showing them in image, they can easily spot that they've made a mistake. I suspect this image cuts their tech-support calls by at least 50%. So it's not useless. It's quite useful.
- san86 14y agoThis could work if security questions (not the best form of security by itself) are asked if the request comes from a "not previously used" computer. So that way, if the phishing site is sending a request on my behalf, they would have to answer my challenge questions (w/o human intervention i.e.) before getting to the image... that kinda makes life harder for an attacker.. of course the logic of identifying the "first time you are using this machine" thing needs to be non-stupid (for lack of a better word)
- Spooky23 14y agoThe blog post is worse than useless. The images give you as a user a sense of situational awareness -- I know based on the picture which of a half dozen accounts I have (personal, Ira, business, etc) I'm logging into. They also make it more difficult to misdirect people to a lookalike site via phishing. Even old people recognize that their login picture, normally prominently displayed, is missing.
- deleted 14y ago[deleted]
- no_more_death 14y agoRight. It's not correct that people will blithely accept an error like "Error: this image failed to load." These people don't think about errors the same way we do. To them all errors are the same and mean there's a catastrophic failure. Developers understand that some errors are minor, but a user faced with an error, where he expects a reassuring "security image," will probably become fearful and bail from that page. Of course, he might still type in his password even if he decides not to go through and submit the form, in which case his data is still compromised.
- peeters 14y agoFine, so just omit the area for the image completely. Showing an error in place of the image is obviously a stupid choice over just asking for the password up front, and just omitting it (by pretending there shouldn't be one) will not trigger panic in non-savvy or forgetful users.
- ncallaway 14y agoThis makes me wonder how sophisticated phishing setups are. This seems like something that they would want to A/B test to determine which "converts" more "users".
- svachalek 14y agoThis is true for a frequent user but honestly I log into so many different web sites that I'm pretty certain I'd not think much of anything if one of the login pages was redesigned without notice. Fortunately I'm also pretty sure I'd never fall for phishing links, but I'm sure the list of people who'd fall for both is sufficiently long that it doesn't matter.
- nathanhammond 14y agoThis is part of a system called Passmark which was acquired by RSA many years ago. As part of the newest releases of RSA's security approach it has been deprecated. In a few years you won't see this anywhere on the web (or, if you do, you'll know that the login and security portion of that site hasn't been looked at in years... also scary). The banking industry is moving toward one-time passwords sent out-of-band and/or Google Authenticator for "something you have."
- chmike 14y agoThe image is a way for the user to "manually" authenticate the server. It's a weak authentication because an attacker could easily get a copy of this image once he knows the user identifier and forge a apparently valid page. The most secure authentication is the one using security cards/key with a challenge code sent by the bank and the response returned by the key using bi-key cryptography. The one with usb connections would be most efficient, convenient and secure. Nfc on phones may look more attractive, but phones are insecure.
- phantomcircuit 14y agoI will admit that when I first saw these I had the same reaction as the author. But then I thought about it longer and I realized that to acquire the image the phisher now has to go to the bank and ask for a specific users image. The bank can now analyze the logs and determine that an account is likely being phished. It's not as stupid as it seems. (At least I hope they're going that).
- subpixel 14y agoExactly: http://ryandeussing.com/blog/2011/11/14/corn-on-the-cob-security/ http://ryandeussing.com/blog/2011/11/14/corn-on-the-cob-secu...