Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

E-commerce in crisis: When SSL isn't safe

A secure connection between browser and back end underlies Internet commerce. But what if it’s already compromised?


Bank officials concur. One regulator said, “Most banks, because of their customers, would probably not accept such an extreme form of authentication. How often would the out-of-band device fail or not be available? Requiring users to confirm every banking transaction out-of-band would not be accepted by today’s consumers.”

Return to special report

DOWNLOAD PDF

Click here to download InfoWorld's special report When SSL isn't safe


The regulator speculated that a better solution might be for the bank to offer out-of-band confirmations as an option and allow the consumer to pick the dollar amount at which the transaction would require additional confirmation measures.

Other bank security officers thought implementing added intelligence on the back end would provide more value. “How about not allowing online transfers to banks and countries with strong ties to crime?” offered one officer. “We could deny any transaction that the bank deemed highly suspicious, like your credit card company does now, and require a second confirmation.”

Close observation of consumer behavior can also help. In one case, nearly 100 customers of one large bank were infected with an SSL-evading Trojan. As usual, the phishing e-mail used mostly legitimate links to the real bank’s Web site. After noticing outside requests to links, most of which were normally referenced from other internal links, the bank’s IT staff realized a Trojan was to blame.

The solution was to rename one of the requested links. If any user went to the real bank’s Web site, the renamed link was now referenced by the legitimate Web site. Only the phishing customers would request the link’s old name, enabling the bank to tell how many of its customers were compromised.

Yunus Emre Alpözen, a consultant for one of the world’s largest banks, says, “Every customer requesting the old Web page link was redirected to a new page that notified them that they were the victims of a phish attack, and how to proceed. We used the phisher’s e-mail against them.”

Self-defense for consumers
Sadly, infection can’t be stopped merely by convincing users not to execute untrusted software. No consumer knowingly installs malicious software, and SSL-evading Trojans can easily go unnoticed by the most careful user.

One of the best defenses is simply to convince consumers to check their online balances frequently. Beyond this, consumers need to lobby financial institutions and move their accounts from institutions that keep their head in the sand.

Banks that require stronger authentication and transactional authorization should be rewarded. Those institutions should also encourage customers to report phishing attacks to the site’s security reporting e-mail address so they can take down fake Web sites or otherwise minimize risk.

Currently, log-on-stealing Trojans are still the No. 1 threat to the banking industry, but SSL-evading Trojans that can bypass any authentication scheme are emerging as a particularly frightening challenge. They need to be dealt with now before consumer confidence in e-commerce goes into serious decline.

Roger A. Grimes is contributing editor of the InfoWorld Test Center.
« PREVIOUS PAGE | 1 | 2 | 3 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Are you ready for event-driven business?
"Faster than a speeding bullet" doesn't just refer to superheroes anymore, it's the velocity your business needs to compete. In this webcast you will learn strategies you can implement today that will keep your systems ahead of the increased business velocity. Sponsor: Progress Sonic

»  Click here to view this Webcast
  Virtualization Solutions Guide
This comprehensive IT Strategy Guide covers Virtualization and puts you at the forefront of the discussion. You'll learn all you need to know from the cost of virtualization, how to implement it for your business, how to back it up safely and which products are best. Sponsored by Riverbed

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 08/29/2008

Microsoft will focus on performance issues in Windows 7 and IE8, Qualcomm...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist