Tuesday, May 15, 2007

Example of a Man in the Middle attack on One Time Password systems

Here's a great example of an attack focused on Citibank a few months ago, where a Man in the Middle exploit was used to defeat a One Time Password implementation of 2-factor authentication.

http://blog.washingtonpost.com/securityfix/2006/07/citibank_phish_spoofs_2factor_1.html

If it's just data that you type in, it can be stolen, spoofed, or passed through, leaving you no better off than before.

1 comment:

Joel Haspel said...

Good discussion of this exploit here on another blog:

http://www.schneier.com/blog/archives/2006/07/failure_of_twof.html