View Single Post
  #7  
Old August 28th 08, 12:10 AM posted to uk.finance
Mike Barnes
external usenet poster
 
Posts: 23
Default Mastercard Securecode

In uk.finance, Chris Blunt wrote:
On Wed, 27 Aug 2008 17:00:11 +0100, "Tim" wrote:

"Reece Bythell" wrote
Speaking for Securecode only (I don't have a VbV card), the system can be
user-configured to offer you a greeting which only the card owner should
know. The greeting is completely separate from the authentication
credentials.


That's a shared "secret" that *is* passed over-the-wire. So,
as the man said, it is vulnerable to a man-in-the-middle attack.


The personal greeting, as well as the box for entering your SecureCode
password, appears in an entirely separate secure pop-up window that
comes directly from your bank. The merchant (assuming that's what you
meant by man-in-the middle) doesn't see any of the information
contained in that browser window.


AAMOI, when you see it, how do you know it came directly from your bank?

--
Mike Barnes
Ads
 

Debt Consolidation - Loans - Personal Finance - Online Loans - Debt Consolidation