Re: Mastercard Securecode
- From: Tim Woodall <devnull@xxxxxxxxxxxxx>
- Date: Wed, 27 Aug 2008 22:24:29 +0000 (UTC)
On Thu, 28 Aug 2008 04:48:53 +0800,
Chris Blunt <mail@xxxxxxxxxx> wrote:
On Wed, 27 Aug 2008 17:00:11 +0100, "Tim" <me@xxxxxxx> wrote:Not when I use it. The popup is in a domain called securesite.co.uk (or
David Woolley wrote:"Reece Bythell" wrote
I've deferred registering with VbV and I haven't used Mastercard online,
for a long time, but, does the system authenticate itself to you, and
does that authentication depend on a shared secret, but not pass it over
the wire? If not, it is vulnerable to a man in the middle attack, and
you need to check the SSL certificate and ignore the way it authenticates
itself to you.
Speaking for Securecode only (I don't have a VbV card), the system can be
user-configured to offer you a greeting which only the card owner should
know. The greeting is completely separate from the authentication
credentials.
That's a shared "secret" that *is* passed over-the-wire. So,
as the man said, it is vulnerable to a man-in-the-middle attack.
The personal greeting, as well as the box for entering your SecureCode
password, appears in an entirely separate secure pop-up window that
comes directly from your bank. The merchant (assuming that's what you
meant by man-in-the middle) doesn't see any of the information
contained in that browser window.
possibly securesuite.co.uk, I can't remember for certain) with a
certificate issued to cyota (or something like that).
It would be trivial for a merchant to display a popup that looked
identical (except possibly this personal greeting - but I've never
been asked/told what to expect and so I suspect nor have many other
people), grab three characters of the code and then say "failed" and
send the person to the real site for the second attempt.
I suspect (although I don't know) that if you actually allow the popup
window then you can't even tell what domain you're connecting to - I
block popup windows so it opens in a new tab so I get to see the domain.
Tim.
--
God said, "div D = rho, div B = 0, curl E = - @B/@t, curl H = J + @D/@t,"
and there was light.
http://www.woodall.me.uk/ http://www.locofungus.btinternet.co.uk/
.
- Follow-Ups:
- Re: Mastercard Securecode
- From: Tim Woodall
- Re: Mastercard Securecode
- References:
- Mastercard Securecode
- From: Stephen2
- Re: Mastercard Securecode
- From: David Woolley
- Re: Mastercard Securecode
- From: Tim
- Re: Mastercard Securecode
- From: Chris Blunt
- Mastercard Securecode
- Prev by Date: Do I have to have a buy to let mortgage?
- Next by Date: Re: Mastercard Securecode
- Previous by thread: Re: Mastercard Securecode
- Next by thread: Re: Mastercard Securecode
- Index(es):
Relevant Pages
|