What is the best way to stop phishing for online banking?

Phishing is a very serious problem that we are facing. However, banks are the biggest goals. What methods can a bank use to protect itself from phishing attacks? What methods should be used to protect yourself. Why does he stop the attacks?

+5
source share
6 answers

The best way to prevent phishing attacks is to rely on technical tools that do not require the user to understand the problem. The target audience will always be large enough to find the one who was deceived.

A good way to prevent attacks is to use an authentication mechanism that does not rely on a simple simple phrase or transaction authentication number ( TAN ) that an attacker could steal.

Existing methods, for example. use indexed TAN (indexed TAN or iTAN ) or TAN transmitted over a separate channel via SMS (mobile TAN or mTAN ), or - the most secure, and also prevents real-time attacks in the middle of a person - requires that the user sign each transaction, for example using DigiPass or a smart card.

, , , , , .

+1

, -. -, - , , -. , , . .

- - , , -.

. IP-, ( -, , ), , , SMS , , .

- , , , , .

+7

, , , - , . , , , , ( ). , , .

+3

EV EV, , EV .

, . , , , .

+2

- , () , (b ) , .

, , , , , .

+1

- : , " " " / ", , : , MITM MitB. 2006 : http://www.bankinfosecurity.com/articles.php?art_id=115&pg=1, doc https: http://www.howtoforge.com/prevent_phishing_with_mutual_authentication. EV , ssl : , , . .

SMS , , . , , . , , snafu iPad, .

Banks should be serious about system design and / or the use of suppliers who base their architecture on strong security principles and follow standard encryption methods, not marketing, to comply with standards of compliance.

+1
source

All Articles