Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a very good point.

The whole US financial industry has their heads in the sand over this one. In 2005 the FFIEC (a US regulator) declared that single-factor authentication alone wasn't sufficient for high-risk transactions.

What did the industry do? They rushed half-baked solutions out the door. One of the worst offenders is Harland Financial Solutions. They created a "Multi"-Factor authentication product for online banking, which is multi-factor in name only. When you login using a computer without a cookie set, the "MFA" system asks a security question (like, "What was your elementary school?"), then sets a cookie.

Harland considers the computer+cookie combination "something you have", and will claim with a straight face that this system is secure and multi-factor.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: