<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Comerica Phish Foiled 2-Factor Protection</title> <atom:link href="http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/feed/" rel="self" type="application/rss+xml" /><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/</link> <description>In-depth security news and investigation</description> <lastBuildDate>Fri, 30 Jul 2010 04:29:12 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.0</generator> <item><title>By: kwan</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-4911</link> <dc:creator>kwan</dc:creator> <pubDate>Sat, 10 Apr 2010 04:43:15 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-4911</guid> <description>I have to concur with the last comment.  Suppose banks issued a fairly user friendly, bootable , password protected, Open BSD keychain stick to their assigned customer&#039;s representative that was unwrite-able, and linked to a static secure sockets IP? AKA a hardware key for the money, in addition passphrase and whatever human based verification routines they might care to invoke?  Couldn&#039;t spoof the website that way, and might autoverify all the connections.  Only question is, would people use it?Oughtta have the same thing for votin&#039; , durn gummuh and big bidner anyway.</description> <content:encoded><![CDATA[<p>I have to concur with the last comment.  Suppose banks issued a fairly user friendly, bootable , password protected, Open BSD keychain stick to their assigned customer&#8217;s representative that was unwrite-able, and linked to a static secure sockets IP? AKA a hardware key for the money, in addition passphrase and whatever human based verification routines they might care to invoke?  Couldn&#8217;t spoof the website that way, and might autoverify all the connections.  Only question is, would people use it?</p><p>Oughtta have the same thing for votin&#8217; , durn gummuh and big bidner anyway.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4911" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4911', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-4911-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4911" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4911', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-4911-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Sean</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-4785</link> <dc:creator>Sean</dc:creator> <pubDate>Mon, 05 Apr 2010 22:34:41 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-4785</guid> <description>We&#039;ll check back with you in about 10 years, and then see how smart you feel then ;)</description> <content:encoded><![CDATA[<p>We&#8217;ll check back with you in about 10 years, and then see how smart you feel then <img
src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4785" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4785', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-4785-up" style="font-size:12px; color:#009933;">1</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4785" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4785', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-4785-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: gluetube</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-3493</link> <dc:creator>gluetube</dc:creator> <pubDate>Tue, 09 Mar 2010 19:29:44 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-3493</guid> <description>there is no excuse for falling for a phishing scam, or getting infected with malware.  i am 25, work in infosec field, do programming, have never once been infected (or godforbid fall for phishing).i think people should be fined for falling for phishing-- a &quot;phishing phee&quot;.i think people should be fined for being infected with malwareuse a secure OS, use common sense, dont be an idiot.  idiots should be forced to paydon&#039;t use insecure software like adobe
patch stuff if neededconclusion:pay a phee for phalling for phishing
don&#039;t be an idiot
i&#039;ve never had a problem, no one else should eitherkthx</description> <content:encoded><![CDATA[<p>there is no excuse for falling for a phishing scam, or getting infected with malware.  i am 25, work in infosec field, do programming, have never once been infected (or godforbid fall for phishing).</p><p>i think people should be fined for falling for phishing&#8211; a &#8220;phishing phee&#8221;.</p><p>i think people should be fined for being infected with malware</p><p>use a secure OS, use common sense, dont be an idiot.  idiots should be forced to pay</p><p>don&#8217;t use insecure software like adobe<br
/> patch stuff if needed</p><p>conclusion:</p><p>pay a phee for phalling for phishing<br
/> don&#8217;t be an idiot<br
/> i&#8217;ve never had a problem, no one else should either</p><p>kthx</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3493" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3493', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3493-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3493" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3493', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3493-down" style="font-size:12px; color:#990033;">4</span></p>]]></content:encoded> </item> <item><title>By: J</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-3114</link> <dc:creator>J</dc:creator> <pubDate>Wed, 03 Mar 2010 21:48:31 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-3114</guid> <description>If I read the complaint right Comerica sent almost 2 million in wires - EMI is claiming a loss of about 560k.My best guess is Comerica contacted EMI when their account balance hit zero - someone dropped the ball at Comerica and didn&#039;t halt the additional wires. Those wires fall on Comerica; after being able to recall a few of them I bet Comerica took about a million dollar loss.Shame on the bank for not recognizing the highly unusual transactions earlier, shame on the EMI employee for being so trusting and shame on the EMI Controller/CFO for accepting the risk on on-line wires when the apparently had no need for them.</description> <content:encoded><![CDATA[<p>If I read the complaint right Comerica sent almost 2 million in wires &#8211; EMI is claiming a loss of about 560k.</p><p>My best guess is Comerica contacted EMI when their account balance hit zero &#8211; someone dropped the ball at Comerica and didn&#8217;t halt the additional wires. Those wires fall on Comerica; after being able to recall a few of them I bet Comerica took about a million dollar loss.</p><p>Shame on the bank for not recognizing the highly unusual transactions earlier, shame on the EMI employee for being so trusting and shame on the EMI Controller/CFO for accepting the risk on on-line wires when the apparently had no need for them.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3114" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3114', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-3114-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3114" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3114', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-3114-down" style="font-size:12px; color:#990033;">1</span></p>]]></content:encoded> </item> <item><title>By: Harry Stoner</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-2322</link> <dc:creator>Harry Stoner</dc:creator> <pubDate>Thu, 18 Feb 2010 16:54:15 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-2322</guid> <description>I have written some banking software. For wire transfers an RSA SecurID token was required for every transfer as I recall. If that had been implemented here, the MITM would not have been able to perform even one transfer without continued contact with the &quot;mark.&quot;Behavioral checks or policy should have alerted the bank to the fact that the wire transfer rate on that day was perhaps 20,000 times higher than the rate established over the previous two years.Comerica also established a bad pattern by using emails to update the certs for 8 years.SSL client-auth also only validates sessions, not transactions.Shame on the client for not catching the phishing attack but the bank is guilty guilty guilty IMO.</description> <content:encoded><![CDATA[<p>I have written some banking software. For wire transfers an RSA SecurID token was required for every transfer as I recall. If that had been implemented here, the MITM would not have been able to perform even one transfer without continued contact with the &#8220;mark.&#8221;</p><p>Behavioral checks or policy should have alerted the bank to the fact that the wire transfer rate on that day was perhaps 20,000 times higher than the rate established over the previous two years.</p><p>Comerica also established a bad pattern by using emails to update the certs for 8 years.</p><p>SSL client-auth also only validates sessions, not transactions.</p><p>Shame on the client for not catching the phishing attack but the bank is guilty guilty guilty IMO.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2322" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2322', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-2322-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2322" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2322', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-2322-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: antihacker101</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-2027</link> <dc:creator>antihacker101</dc:creator> <pubDate>Sun, 14 Feb 2010 18:50:29 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-2027</guid> <description>since i seen your name more and need someone to respond so i know i got out, it would be awesome.  i been the target since aug 2008  and havnt got any help yet.  i got a hold of someone who claims to be microsoft&#039;s chief engineer, and i showed him and his group the  proof and evidence of just some of what i know, and was told to get a hold of ed gibson. i wrote some comments asking for help, andi got a response from him with his hotmail email address.  i responded but 5 or 6 days i think, and no response.    i was intercepted many ways.  my phone affect everyone.  i see these hackers through my machines  hacking everyone.  i still have no control over my machines to this day and know what im doing.    right now, i get the impression of the worm rebuilding itself and at the same time, someone yesterday and today removed part of the worm that that was in place to hide anything from reaching your terminal that could help you fight the worm.whats really going on is sorta scary.  all the community sites along others were being hacked years without notice.  even microsoft and msft and verison.
the hacker is using a smartphone and a tower to insert radio packets into a chip in the motherboard of every system.  he then inserts the well dug in backdoor part of the bot and programmed it to have highest priority.
that backdoor and hacker use both sides of the connetion to go down a list of exploits form any open port(mostly 80).   first is adobe popup from hell.  no matter what setup you have, he gets in.   one system he uses is creating any certificate of choice of any site that would be used to create a cookie.  the cookie has an option of blocik/allow/view info.  no matter what you choose, the backdoor intercepts all packets and can be ginven commands of any choice.the backdoor/bot  in return uses smft to send email back to thew hacke and using a code in the subject for direction of which computer its form.  the code has a dollar sign before and after every word.    mine was $chicago$ and $danielle$   one for computer and the other for phone.    this is how i got their number which is now disconnected.another thing a bout the worm that was never mentioned yet is string insertions to any text i type.  it starts eating letters and twisting them.         since yesterday, that speeded up due to someone removing the layer that hid parts of the worm in kernel.the lag noticed is linked to a 2nd machine infected being turned on in a local area and is somehow using signals that is used to monitor the hardrives...im sure there is more to it now, but that was the pattern i seenanyways, how can i get a return so i know that i successfully sent a message unintercepted</description> <content:encoded><![CDATA[<p>since i seen your name more and need someone to respond so i know i got out, it would be awesome.  i been the target since aug 2008  and havnt got any help yet.  i got a hold of someone who claims to be microsoft&#8217;s chief engineer, and i showed him and his group the  proof and evidence of just some of what i know, and was told to get a hold of ed gibson. i wrote some comments asking for help, andi got a response from him with his hotmail email address.  i responded but 5 or 6 days i think, and no response.    i was intercepted many ways.  my phone affect everyone.  i see these hackers through my machines  hacking everyone.  i still have no control over my machines to this day and know what im doing.    right now, i get the impression of the worm rebuilding itself and at the same time, someone yesterday and today removed part of the worm that that was in place to hide anything from reaching your terminal that could help you fight the worm.</p><p>whats really going on is sorta scary.  all the community sites along others were being hacked years without notice.  even microsoft and msft and verison.<br
/> the hacker is using a smartphone and a tower to insert radio packets into a chip in the motherboard of every system.  he then inserts the well dug in backdoor part of the bot and programmed it to have highest priority.<br
/> that backdoor and hacker use both sides of the connetion to go down a list of exploits form any open port(mostly 80).   first is adobe popup from hell.  no matter what setup you have, he gets in.   one system he uses is creating any certificate of choice of any site that would be used to create a cookie.  the cookie has an option of blocik/allow/view info.  no matter what you choose, the backdoor intercepts all packets and can be ginven commands of any choice.</p><p>the backdoor/bot  in return uses smft to send email back to thew hacke and using a code in the subject for direction of which computer its form.  the code has a dollar sign before and after every word.    mine was $chicago$ and $danielle$   one for computer and the other for phone.    this is how i got their number which is now disconnected.</p><p>another thing a bout the worm that was never mentioned yet is string insertions to any text i type.  it starts eating letters and twisting them.         since yesterday, that speeded up due to someone removing the layer that hid parts of the worm in kernel.</p><p>the lag noticed is linked to a 2nd machine infected being turned on in a local area and is somehow using signals that is used to monitor the hardrives&#8230;</p><p>im sure there is more to it now, but that was the pattern i seen</p><p>anyways, how can i get a return so i know that i successfully sent a message unintercepted</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2027" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2027', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-2027-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2027" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2027', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-2027-down" style="font-size:12px; color:#990033;">3</span></p>]]></content:encoded> </item> <item><title>By: M Henri Day</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-2015</link> <dc:creator>M Henri Day</dc:creator> <pubDate>Sun, 14 Feb 2010 11:36:11 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-2015</guid> <description>Thanks for replying, AlphaCentauri ! After first logging in, I can order a transaction without any further authentication, but in order to carry it out, I have to sign in - a process similar to but distinct from - the initial authentication. I&#039;m not certain whether a man-in-the-middle attack would be able to intercept and modify both the initial order and the confirmation necessary to complete it....Henri</description> <content:encoded><![CDATA[<p>Thanks for replying, AlphaCentauri ! After first logging in, I can order a transaction without any further authentication, but in order to carry it out, I have to sign in &#8211; a process similar to but distinct from &#8211; the initial authentication. I&#8217;m not certain whether a man-in-the-middle attack would be able to intercept and modify both the initial order and the confirmation necessary to complete it&#8230;.</p><p>Henri</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2015" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2015', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-2015-up" style="font-size:12px; color:#009933;">1</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2015" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2015', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-2015-down" style="font-size:12px; color:#990033;">1</span></p>]]></content:encoded> </item> <item><title>By: antihacker101</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-2013</link> <dc:creator>antihacker101</dc:creator> <pubDate>Sun, 14 Feb 2010 11:22:10 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-2013</guid> <description>i seen signs now for the first time that the main part of the botbnet worm is being addressed.     this global hijack allows the hacker to gain access to any server with highest authority and probably dont really need a connection from what i experienced.   in my situation, they first get in the board of devices such as computers using radio packet injections.  all security i attacked it with failed.    i thank a lot of the security teams for listening to me and be aware of whats going on.    there is still a lot of work to be done, but i seen yesterday for the first time parts of the main worm being stripped allowing me to see what he had hidden.  a lot of hardware was seen that i couldnt see before allowing me to gain for info on the technical info.</description> <content:encoded><![CDATA[<p>i seen signs now for the first time that the main part of the botbnet worm is being addressed.     this global hijack allows the hacker to gain access to any server with highest authority and probably dont really need a connection from what i experienced.   in my situation, they first get in the board of devices such as computers using radio packet injections.  all security i attacked it with failed.    i thank a lot of the security teams for listening to me and be aware of whats going on.    there is still a lot of work to be done, but i seen yesterday for the first time parts of the main worm being stripped allowing me to see what he had hidden.  a lot of hardware was seen that i couldnt see before allowing me to gain for info on the technical info.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2013" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2013', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-2013-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2013" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2013', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-2013-down" style="font-size:12px; color:#990033;">5</span></p>]]></content:encoded> </item> <item><title>By: AlphaCentauri</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-2008</link> <dc:creator>AlphaCentauri</dc:creator> <pubDate>Sun, 14 Feb 2010 07:32:29 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-2008</guid> <description>I&#039;m not sure I&#039;m clear on the steps you&#039;re describing, but the question is whether any authentication must be entered after the initial log in? A man-in-the-middle attack simply waits for you to do all the logging in, then once you have done it shows you a screen that says the site is temporarily unavailable while it accesses your account.</description> <content:encoded><![CDATA[<p>I&#8217;m not sure I&#8217;m clear on the steps you&#8217;re describing, but the question is whether any authentication must be entered after the initial log in? A man-in-the-middle attack simply waits for you to do all the logging in, then once you have done it shows you a screen that says the site is temporarily unavailable while it accesses your account.</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2008" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2008', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-2008-up" style="font-size:12px; color:#009933;">1</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2008" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2008', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-2008-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> <item><title>By: Chip-and-PIN broken, NSA and Google team up, USB fingerprints and more &#171; Zero Knowledge Reflections</title><link>http://krebsonsecurity.com/2010/02/comerica-phish-foiled-2-factor-protection/#comment-1902</link> <dc:creator>Chip-and-PIN broken, NSA and Google team up, USB fingerprints and more &#171; Zero Knowledge Reflections</dc:creator> <pubDate>Fri, 12 Feb 2010 20:11:10 +0000</pubDate> <guid
isPermaLink="false">http://www.krebsonsecurity.com/?p=973#comment-1902</guid> <description>[...] Banks sometimes encourage bad security &#8212; If you train users to click on links in email to update their security information, don&#8217;t be surprised when they fall for phishing scams. [...]</description> <content:encoded><![CDATA[<p>[...] Banks sometimes encourage bad security &#8212; If you train users to click on links in email to update their security information, don&#8217;t be surprised when they fall for phishing scams. [...]</p><p>Like or Dislike: <img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-1902" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('1902', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_');" title="Thumb up" /> <span
id="karma-1902-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img
style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-1902" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('1902', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating/', '1_16_')" title="Thumb down" /> <span
id="karma-1902-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached (user agent is rejected)
Database Caching 4/9 queries in 0.002 seconds using memcached

Served from: krebsonsecurity.com @ 2010-07-30 05:33:15 -->