Verified By Visa insecure and pointless
Автор: Steven Whiting
Загружено: 2014-09-21
Просмотров: 6623
Описание:
Verified by Visa is clearly insecure and pointless. I suspect more for the banks to pass blame onto merchants/customers.
For a start to reset your password all you need is a DOB which can easily be obtained.
The worst part is this video. This is in Firefox. Still not worked out if it's Adblock that does this but wherever Verified by Visa is used, it briefly pops up and then disappears and the transaction is approved. Regardless if a password is actually entered or not.
The whole point is, if it's not filled in or an invalid password is entered, then it should fail and alert your card provider. But clearly doesn't work as intended. This transaction has gone through just fine by unofficially skipping the Verified by Visa. Clean browser session with no cookies.
http://www.cl.cam.ac.uk/~rja14/Papers...
Verified by Visa and MasterCard SecureCode:
or, How Not to Design Authentication
Steven J. Murdoch and Ross Anderson
http://www.pcworld.idg.com.au/article...
3D Secure online payment system not secure, researchers say
Liability for fraud said to be unfairly shifted from merchants to customers
http://www.theregister.co.uk/2010/01/...
Verified by Visa bitchslapped by Cambridge researchers
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: