Roland Piquepaille's Technology Trends
How new technologies are modifying our way of life

 
Web www.primidi.com



lundi 4 septembre 2006
 

CyLab researchers at Carnegie Mellon University (CMU) have developed a new anti-phishing tool to protect mobile users. Their Phoolproof Phishing Prevention system can prevent users of cell phones, PDAs or even laptops from network-based attacks, even when they make mistakes. This system is based on a really simple concept. It provides a secure electronic key that the user can access while making online transactions. But the user can't give this key to someone else, especially to a phisher who could have found a way to access his account. Read more...

This system has been developed at CMU's CyLab by a team led by Adrian Perrig who explains why he decided to create this service.

"Essentially, our research indicates that Internet users do not always make correct security decisions, so our new system helps them make the right decision and protects them even if they manage to make a wrong decision," Perrig said.

Here is how this anti-phishing system works.

Phoolproof Phishing Prevention essentially provides a secure electronic key ring that the user can access while making online transactions[...] These special keys are more secure than one-time passwords because the user can't give them away. So phishers can't access the user's accounts, even if they obtain other information about the user, researchers said.

Images are always better than words, so below is a description of what would happen if an hypothetical Alice decided to access her account online after registering with the Phoolproof system. (Credit: CMU)

Using the Phoolproof Phishing Prevention system

It remains to be seen if this tool will be deployed by online vendors. But there are concerns in the industry about online fraud and about new security guidelines for financial institutions.

Complicating the concern for more secure financial sites is a looming deadline for new security guidelines from the Federal Financial Institutions Examination Council (FFIEC), a group of government agencies that sets standards for financial institutions. Last year, the FFIEC set a Dec. 31 deadline for banks to add online security measures beyond just a user name and password. Failure to meet that deadline could result in fines, the FFIEC said.

For more information about this project, you can read this technical paper about Phoolproof Phishing Prevention(PDF format, 16 pages, 181 KB).

Sources: Carnegie Mellon University news release, August 31, 2006; and various web sites

You'll find related stories by following the links below.


6:21:28 PM   Permalink        


Click here to visit the Radio UserLand website. © Copyright 2007 Roland Piquepaille.
Last update: 01/04/2007; 19:44:13.


September 2006
Sun Mon Tue Wed Thu Fri Sat
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
Aug   Oct


Personal Links



Other Links

Ars Technica
Bloglines
Daily Rotation News
Dave Winer
Danger Room
del.icio.us
Engadget
Gizmodo
John Robb
Jon Udell
OhGizmo!
Really Magazine
Robots.net
Slashdot
Smart Mobs
TG Daily
WorldChanging
ZDNet Blogs


Drop me a note via Radio
Click here to send an email to the editor of this weblog.

E-mail me directly at
pique@noos.fr

RSS subscription for Radio users
Subscribe to "Roland Piquepaille's Technology Trends" in Radio UserLand.

RSS feed for others
Click to see the XML version of this web page.