The Channel logo

* Posts by Nick Leach

1 post • joined Thursday 29th November 2007 09:32 GMT

Nick Leach

Seen this before..

This is pretty standard stuff. I'd guess that this 'vulnerability' is designed-in.

The problem with any hardware based 2 factor authentication is that you need a back-up mechanism in case the user loses, breaks or forgets their hardware token. Using memorable data as the back up is pretty typical of companies that shy away from (heaven forbid) putting a real, expensive, human in the loop.

Several large banks I could name use exactly the same kind of back up for their '2 factor' systems. There are plenty of better (but more expensive) alternatives, but Paypal aren't the first and won't be the last to use this particular method. A security method is only as strong as it's weakest link, and this is poor.

Forums

Forgotten password

Opinion

euros_channel_money

Tim Worstall

Time to take a sniff at the coffee, perhaps
joe_tucci_emc_channel

Chris Mellor

Will they have to drag him back like last time?
chain_relationship_channel

Features

cloud_accounting
Playing the SLA long game
channel_teaser_money_top
cloud computing Fight
Applications must work for the cloud to float
Paul Cormier, Red Hat
How a Unix killer crawled from the dot-com bust