On App-based Matrix Code Authentication in Online Banking
نویسندگان
چکیده
Since its introduction, German online banking has been following a two-factor authentication procedure marked by a steady increase in its security features. In the recent past, however, app-based authentication schemes have gained in popularity and begun to replace established schemes like chipTAN. Unlike chipTAN, which uses dedicated hardware to securely legitimize transactions, authentication apps run on multi-purpose devices such as smartphones and tablets, and are thus exposed to the threat of malware. This vulnerability becomes particularly damaging if the online banking app and the authentication app are both running on the same device, also known as mobile banking. In order to emphasize the risks that mobile banking poses, we show a transaction manipulation attack for the app-based authentication schemes of Deutsche Bank, Commerzbank, and Norisbank. Furthermore, we evaluate whether the matrix code authentication method that these banks implement— widely known as photoTAN—is compliant with the upcoming payment service directive of the European banking authority.
منابع مشابه
Biometric Authentication of Fingerprint for Banking Users, Using Stream Cipher Algorithm
Providing banking services, especially online banking and electronic payment systems, has always been associated with high concerns about security risks. In this paper, customer authentication for their transactions in electronic banking has been discussed, and a more appropriate way of using biometric fingerprint data, as well as encrypting those data in a different way, has been suggest...
متن کاملMobile Commerce
Growth Factors First of all, the increasing popularity of using smart mobile devices has helped advance wireless technology and computing power. For example, modern smartphones now have four-core CPUs and 2 Gbytes of memory and are communicating through 4G LTE wireless networks. Another driving factor is consumer demand for applications for buying and selling goods and services, as well as for ...
متن کاملOver-the-Air Cross-platform Infection for Breaking mTAN-based Online Banking Authentication
We present a novel stealthy cross-platform infection attack in WiFi networks. Our attack has high impact on two-factor authentication schemes that make use of mobile phones. In particular, we apply our attack to break mTAN authentication, one of the most used scheme for online banking worldwide (Europe, US, China). We present the design and implementation of the online banking Trojan which spre...
متن کاملHow Anywhere Computing Just Killed Your Phone-Based Two-Factor Authentication
Exponential growth in smartphone usage combined with recent advances in mobile technology is causing a shift in (mobile) app behavior: application vendors no longer restrict their apps to a single platform, but rather add synchronization options that allow users to conveniently switch from mobile to PC or vice versa in order to access their services. This process of integrating apps among multi...
متن کاملExploiting Natwest and RBS online banking systems for profit
The Natwest and Royal Bank of Scotland (RBS) online banking systems are vulnerable to a remote attack which allows an adversary to steal money from a customer’s account. The vulnerability has arisen as a result of poor software engineering practice which neglected security. More precisely, the authentication mechanisms used by Natwest and RBS are dependent on six pieces of customer data, namely...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016