ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Security firm U-turns on banking breach

Munir Kotadia ZDNet Australia

Published: 04 May 2007 11:13 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UPDATE: Security firm TrustDefender has this morning withdrawn claims it made last Thursday that seemed to "prove" that the SMS-based two-factor authentication system used by many online banking systems was vulnerable to attack.

In a statement emailed to ZDNet Australia on Monday, the chief executive and co-founder of TrustDefender Ted Egan said: "TrustDefender openly and unreservedly withdraws the suggestion… that the two-factor authentication system operated by the Commonwealth Bank of Australia is or was vulnerable in the manner suggested in those statements."

Egan goes on to apologise to the Commonwealth Bank and its customers for "causing any unnecessary concern".

The story began last Thursday when TrustDefender, in partnership with Dragonfly Technologies, held a "live hacking session", which was supposed to demonstrate weaknesses in the security of online banking systems.

Below we have republished the original story and the full text of TrustDefender's retraction:

White hats break two-factor banking security

Two-factor authentication systems using SMS messages can be exploited by criminals to steal money, according to security experts who demonstrated an attack in Sydney on Thursday.

Australian security firms TrustDefender and Dragonfly Technologies, who specialise in endpoint security and two-factor authentication respectively, broke the security of a Commonwealth Bank account using a specially crafted piece of malware.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

The demonstration showed how malware could be used to not only capture the login credentials of an online banking customer but also how, once the user's system was infected with a Trojan, an attacker could exploit weaknesses in the mobile phone-based authentication system to clean out a victim's account.

TrustDefender's chief technical officer, Andreas Baumhof, said that the hacking demonstration does not mean Commonwealth Bank's systems are any less vulnerable than the other banks — because he said the same attack would work on any online bank's systems.

"Two-factor authentication only forces the bad guys to work in real time. Commonwealth is no less secure than Westpac or any of the other banks.

"It is an industry-wide problem because the banks can only put in security on their end. If the home user's computer is compromised, the whole security chain is compromised — regardless of any security put in place by the bank," added Baumhof.

However, the Commonwealth Bank's chief information security officer, Sarv Girn, was adamant that the bank's security had not been compromised.

"When vendors make these claims, they are only making them on the niche they are looking at. Banks have a wide range of controls, not just in that area. The passwords issued by SMS can only be used by that customer and cannot be used a second time.

"We also have a system called 'Hawkeye', which is a rules-based detection system that analyses all transactions and has proved effective in identifying fraudulent activity.

"A Trojan alone does not compromise all your security. We don’t completely rely on clean PCs around the globe accessing our systems. The system is working as intended," said Girn.

The demonstration was performed on a Windows XP system with the latest updates, IE7, and AVG Antivirus. AVG was unable to recognise the Trojan, which was created specifically for the purpose of the demo.

According to TrustDefender, the Trojan used in the demonstration did not present a threat to other users because it was designed to only function if it was executed on the computer used in the demonstration.

The Commonwealth Bank implemented an SMS-based authentication system just over one month ago. Shortly after, the company's e-commerce general manager Marcus Judge said he expected miscreants to try and convince unsuspecting users to download malware, which allows unauthorised access to a computer.

Below is the full text of TrustDefender’s retraction: "Symbiotic Technologies T/A TrustDefender (TrustDefender) openly and unreservedly withdraws the suggestion in statements it caused to be published in an article on www.zdnet.com.au, www.zdnet.co.uk and www.zdnetasia.com and other sites on 4 May 2007 entitled 'Two-factor authentication proven vulnerable' that the two-factor authentication system operated by the Commonwealth Bank of Australia is or was vulnerable in the manner suggested in those statements. TrustDefender accepts that no vulnerability was demonstrated in the article. TrustDefender apologises to the Commonwealth Bank of Australia and its customers for causing any unnecessary concern."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
14 out of 19 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Senior Project Manager Global Banking and Markets London

The programme is one of the most high profile initiatives within the bank and will fundamentally re-define the bank process and remain a key part of ...

Java Developer - Investment Banking - J2EE - 35,000 Canary Wharf

Working within one of the leading investment banks you will leverage your technical skills and commercial experience to develop your career in a very ...

Java Technical Lead Banking London City

JAVA (SERVER-SIDE), SYBASE, RISK, FRONT OFFICE A great opportunity for a Technical Team Leader with solid banking background (ideally in Risk) to ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment