Comments on: Bank of America’s SiteKey System is Useless http://www.tech-talkers.com/2007/07/bank-of-americas-sitekey-system-is-useless/ Let's Talk Tech... Tue, 22 Mar 2011 03:32:43 -0700 http://wordpress.org/?v=2.8.6 hourly 1 By: Steve Dispensa http://www.tech-talkers.com/2007/07/bank-of-americas-sitekey-system-is-useless/comment-page-1/#comment-2485 Steve Dispensa Tue, 31 Jul 2007 01:33:58 +0000 http://www.tech-talkers.com/?p=142#comment-2485 It is truly amazing to me that SiteKey can say with a straight face that a browser cookie counts as a second authentication factor. It's nothing more than a convenience feature that prevents you from having to answer your four security questions on every login. McAfee has a phishing "aptitude test" that's floating around the Internet right now, where users are asked to pick the genuine site from a pair, one of which is an actual phishing site. The truly scary thing is that I only really had grammar bugs to go on for many of the sites. If the phishers ever learn English, we're in trouble. Of course, for non-native speakers of English, the problem is already here, unless they're amazingly good non-native speakers. Related: my company just released a new two-factor authentication system using automated phone calls: http://phonefactor.net. It is truly amazing to me that SiteKey can say with a straight face that a browser cookie counts as a second authentication factor. It’s nothing more than a convenience feature that prevents you from having to answer your four security questions on every login.

McAfee has a phishing “aptitude test” that’s floating around the Internet right now, where users are asked to pick the genuine site from a pair, one of which is an actual phishing site. The truly scary thing is that I only really had grammar bugs to go on for many of the sites. If the phishers ever learn English, we’re in trouble.

Of course, for non-native speakers of English, the problem is already here, unless they’re amazingly good non-native speakers.

Related: my company just released a new two-factor authentication system using automated phone calls: http://phonefactor.net.

]]>