Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×

Who Says Money Can't Buy Friends? 345

Courtney5000 writes "It looks like some users of popular networking sites such as MySpace and Facebook have stooped so low as to actually pay real money for friends. These friends aren't even real believe it or not. You can apparently choose from a selection of 'models' to leave you customized comments to look like you have friends and are popular online. This is unbelievable!"
Security

Defeating Virtual Keyboards and Phishing Banks 135

An anonymous reader writes "Noam Rathaus writes on the SecuriTeam Blogs how most Image Click-Me virtual keyboards schemes used by banks to fight phishing trojan horses can be easily broken, even (and especially) when encryption is used. He then discusses how screenshots of the pointer location are over-kill, and describes how to kick these security measures out of the way." From the article: "Instead of sending the remote image and waiting for the key-stroke information to be sent back to the server (the technique which the screenshots for pointer location on-click described above was used) some banks send the PIN number in cleartext, while others encrypt them, one such example is cajamurcia. Even when the encryption is used, banks tend to implement it badly making it easy to recover the PIN number from the encrypted form. I investigated a bit more on how cajamurcia handles such PIN strokes (with virtual keyboards) and I noticed something strange, they take the timestamp of their server (cajamurcia) and send it to you - this already posses a security problem - and this timestamp is then used to encrypt the PIN number you entered"

Slashdot Top Deals

"Remember, extremism in the nondefense of moderation is not a virtue." -- Peter Neumann, about usenet

Working...