Home » The Art of Data Protection » Knowledge-Based Authentication: a false sense of security
Knowledge-Based Authentication: a false sense of security
Paul ArdoinAugust 29, 2011, 09:40 am
Whether it’s a self-service system for network password resets or logging into a banking website, chances are you’re familiar with Knowledge-Based Authentication (KBA). This type of authentication asks you questions, and if you answer them correctly, the system lets you in, or lets you reset your password, or lets you transfer $50,000 to an account in the Cayman Islands.
Much like a security gate that people can easily climb, however, KBA makes people feel safe, but doesn’t provide very much real security. Financial institutions, content providers, and IT departments don’t create questions that are secure enough. People often post their favorite restaurants, their birth cities, and their pet names on their blog or Facebook page. (Paris Hilton famously had her account hacked because her security answer was her dog’s name–and the dog had only appeared in the tabloids about 100 times!) Security expert Mike Masnick was able to easily hack Sprint’s KBA on the first try for one of the employees in his office.
The worse news for companies is that these systems are perceived as user-friendly, but they’re really not. IT professional Garry Scoville created KBA guidelines (used by some huge brands, like Delta Airlines, American Express, and others) and ranked some of the best security questions used today, most of which are simple, memorable, hard to guess, and static. But none of these questions are perfect, and worse, users think many of those questions are creepy, overly invasive, or rude. A commenter on one security blog says that all his answers to those security questions are a vulgar rephrasing of “mind your own business.”
So if KBA isn’t secure, and if it’s making users angry, why do 90% of banks use it (according to one security vendor)? Should more strong authentication options make the short list for consideration?
This entry was posted in Authentication, Compliance, Cybersecurity and tagged authentication, banking, compliance, cybersecurity, finance, multi-factor authentication, token by Paul Ardoin. Bookmark the permalink.SafeNet Delivers Industry’s First Licensing and Monetization Solution for Hybrid On-Premise and Cloud-based Software Portfolios
Cheryl Barto Shoults May 9, 2012, 01:51 pm
Say What You See at Infosec! Have We Learnt Nothing about Information Security?
Nicki Wallace May 8, 2012, 11:24 am
SIIA Vision from the Top 2012: Chris Fedde, SafeNet, Inc.
Cheryl Barto Shoults May 7, 2012, 11:05 am
Channel Commitment Pays Off...Again
Cheryl Barto Shoults April 26, 2012, 10:05 am
Roy Walker Plays Catchphrase at Infosec 2012
Cheryl Barto Shoults April 24, 2012, 12:16 pm
At Last: New Guidelines for Online Banking Authenticaiton
Motty Alon July 1, 2011, 06:46 am
Roy Walker Plays Catchphrase at Infosec 2012
Cheryl Barto Shoults April 24, 2012, 12:16 pm
Advanced Malware Protection from Raytheon and SafeNet: RShield
safenet safenet August 1, 2011, 02:32 pm
Knowledge-Based Authentication: a false sense of security
Paul Ardoin August 29, 2011, 09:40 am
How Secure is that Cloud Vendor? 7 Basics
safenet safenet July 19, 2011, 11:05 am
3 Steps to More Reliable PKI Deployments
Cheryl Barto Shoults December 27, 2011, 10:05 am
Cryptocard + SafeNet: Providing Global Cloud, Mobile & Authentication-As-A-Service
Cheryl Barto Shoults March 29, 2012, 02:00 pm
Coming Full Circle: White House Re-sets Cybersecurity Priorities
Chris Ensey April 4, 2012, 10:05 am
How Secure is that Cloud Vendor? 7 Basics
safenet safenet July 19, 2011, 11:05 am
Cloud Security Checklist
Cheryl Barto Shoults December 8, 2011, 10:05 am
0