Greater Than 1. Defeating “Strong” Authentication in Web Applications (for Online Banking)
Posted by: Sergey Chernyshev in UncategorizedThanks to Alex Moskalyuk who posted a link to DEFCON 15 videos - first presentation video (with attack demo and presentation slides) is about attacking web applications that are used in US banking systems. Presented by Brendan O’Connor.
It’s ridiculous how bank’s security specialists are not familiar with web technologies. Brendan makes a good point - let consumer share the cost of hardware tockens, if it means better security, people will use them. Stop marginalizing the business that is about people’s money.
See it on TechPresentations.org: Greater Than 1. Defeating “Strong” Authentication in Web Applications (for Online Banking)
Update: Actual videos were posted by Carsten Cumbrowski AKA Roy/SAC. Here’s his blog entry.

Entries (RSS)
September 6th, 2007 at 2:19 pm
Hi,
FYI. I put up the video and PDF two days ago, together with 46 other session videos (and more to come).
See my post about the DefCon Session Videos at my personal blog.
Cheers!
Carsten
September 8th, 2007 at 11:12 pm
Thanks, Carsten, I’ll probably post more videos here http://www.techpresentations.org/DEFCON_15 if I’ll have time to watch them.
September 12th, 2007 at 10:43 am
I just finished the final batch of DefCon 15 videos. Just FYI :)
September 12th, 2007 at 10:45 am
Ooops, wrong link. Here is the link to the final batch post