kottke.org

...is a weblog about the liberal arts 2.0 edited by Jason Kottke since March 1998 (archives). You can read about me and kottke.org here. If you've got questions, concerns, or interesting links, send them along.

SiteKey sucks

I've used Bank of America to do my online banking in the past and their SiteKey "technology" always irritated the hell out of me because it led me to believe that Bank of America thought I was:

a) a criminal

and/or:

b) an idiot

instead of:

c) a customer

The basic idea behind SiteKey is that when you log in to your account, you're shown a photo of, say, an orange kitten before you enter your password so that you know you're not on the site of a phisher who knows nothing about your orange kitten but wants to collect your login info. In addition, the site makes you verify your identity with a security question -- like "what's your favorite food?" -- before using the site from a new IP address, which means if you're on a cable or DSL connection, this happens every couple weeks when your current IP expires...or whenever BofA feels like they should throw up another virtual pane of bulletproof glass between you and your account information. For those who don't fall for phishing scams -- by accessing sites directly through bookmarks or by typing URLs into the location bar -- SiteKey is nothing but an irritant and a deterrent and there's no way to switch it off.

On Tuesday, Christopher Soghoian and Markus Jakobsson published a clever method by which password phishers could get around SiteKey. The method takes advantage of a simple hole in the logic concerning SiteKey...that anyone who knows your account's login name and state of residence can see both your SiteKey image and any challenge questions, no password required. All the phisher has to do is ask for the login name and state of residence, send that info to the BofA site (via a script running on the phisher's machine), get back a security question, display that, send the answer to the BofA site, get back the correct SiteKey image, display that, and collect the person's password, all while presenting a nearly seamless Bank of America-like experience to the user.

Hopefully this gaping monster of a security hole will convince BofA that not only does SiteKey security not work, it's not even security and they'll soon be rid of it.

By Jason Kottke    Apr 12, 2007 at 03:04 pm    bankofamerica   phishing   security

kottke.org, quickly...

The best way to get a sense of what kottke.org is all about is to head to the front page or check out some random entries from the archives. Follow kottke.org via RSS or Twitter.

Want to share your something special with kottke.org's readers? Sponsor the RSS feed for a week!

Looking for work?

Recommended sites

evhead    Vulture    Omit Needless Words    Morning News    Q Daily News    FlickrBlog    tecznotes    nickbaum.com    scoboco    I did not know that yesterday!    Typographica    Play with the Machine    onfocus.com    Heavy Backpack    plasticbag.org    Cynical-C Blog    Capn Design    gladwell.com    Blackbeltjones/work    NYT Science