An ideal security solution provided by a partner should offer protection even
after a phishing attack has struck a user and used his email client to send
fictitious mails. As a solution provider, your ultimate goal should be to
protect customers from financial loss.
Phishing attacks are the mass distribution of spoofed e-mail messages with
web-links to fraudulent websites. These e-mails appear to come from banks and
other service providers and are designed to fool the recipients into divulging
personal authentication data such as user names and passwords, credit card
numbers, among other details.
This problem is faced the world over and not a particular continent. Contrary
to popular notions, it is not restricted to western countries where financial
transactions through the Web are more prevalent. Residents of India are as much
plagued by this.
In fact, this problem is very relevant to most corporates in India,
especially private banks that offer Internet banking services. It is for the
same reason that warning notice is posted on the home page of their websites.
THE BIG PICTURE
Phishing attacks not only exploit the vulnerability in the unauthenticated email
systems, but also the loophole that Internet banking logins do not employ strong
authentication. Sufficient measures to curb these attacks are not taken.
The
only measure that Indian banks have taken against phishing attacks is to post a
warning message on their website with some instructions to identify a fake
message from a legitimate one. This just doesn't work. There is no way that
these messages will help millions of innocent users to check the details of
email headers and scrutinize the minutiae of Internet URL links to ensure that
email communications are genuine and not from a Phisher. Why don't banks just
have security guards and their customers to watch for robbers and leave their
vaults open?
Since the cost of launching a phishing attack is next to nothing, even a 1%
success rate for a phisher is profitable for him and he will continue to do his
business. Ergo, a well planned and multi-pronged security strategy has to be
implemented for complete protection from Phishing attacks.
A security solution, which offers protection even after an attack will be the
ideal choice. The ultimate goal is to protect customers from financial loss that
might result from such attacks. But still, one has to secure the channel and the
asset-email and Internet banking, correspondingly.
The best way to secure the channel is to adopt digitally signed emails.
Security experts have arrived at this conclusion after considering the pros and
cons of several other possibilities. But there are solutions for protecting the
Internet banking service and not dwell too much on securing the channel.
POSSIBLE SOLUTIONS
The actual solution would be to implement the two-factor authentication. The
biggest advantage that this technology would provide is that the phisher, even
after harvesting passwords, cannot use them to his own advantage.
The
Internet banking site would force the end-user to provide two factorspassword
and another factor that is available only with the user in order to allow him to
perform a transaction. How good is it if somebody knows your ATM PIN but does
not have your ATM card? Also, the PIN can be changed at any time.
Three candidates qualify for the second factor we are talking about:
1. Token-based one time password solutions like SecurID
2. Biometrics
3. Public key technology
The first two are immediately ruled out because of their high
costs of implementation and complexity, huge migration efforts both from the
banks' end and the customers' end. More importantly the security offered by
them are questionable. For example, SecurID implements a proprietary algorithm
and its offline verification technology is not open for public scrutiny and
review. Biometrics are not fit for online authentication even at a conceptual
level.
THE REAL SOLUTION
The only solution that stands out is public key technology. Its
implementation immediately brings in the protection of two-factor
authentication, which are:
What the user has Private Key
What the user knows Password
Only
passwords can be harvested in a phishing attack, but not the private key
corresponding to the customer's digital certificate. The private key is
generally stored on crypto-tokens/smart cards or in the protected storage of
Windows and can be accessed securely only by using Cryptographic Service
Providers (CSP).
The very idea of public key technology makes CTOs and CIOs
think of complexity and huge costs, but they are actually thinking about Public
Key Infrastructure (PKI). However, it is possible to have PK without the 'I',
which translates into no complexity and no huge costs.
The service providers themselves provide and trust the keys
and use them to authenticate the users and transactions. Well, do you really
need a third party to certify a customer of the bank who is already very well
known to the bank?
CONCLUSION
The real answer to the phishing problem is public key technology without the
hassles of a third party Certification Authority (CA). Solutions adopting ANSI
X9.59 and similar standards are in the right direction and will soon become the
de-facto standard.
Visa 'Chip and PIN' has already started the move towards
the same. Solutions that offer similar technologies for online banking and
provide not just security but also easy migration, ease-of-use and scalability
are likely to stand out as the killer applications. No doubt, phishers will soon
have look out for another job!
R Lakshmikanth is a security consultant
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us