Banks and OTP

Banks and OTP
Apparently my bank offers an additional security mechanism on their internet banking facilities where account holders are issued with a device that generates one-time-passwords (OTP) for identification purposes. It appears to be time based, so one would assume that it's time-synchronised to the bank's computers, and also contains an account-specific shared secret. Enter a PIN, push a button, and get a token which is valid for that particular minute of the day.

The use of such a device changes internet banking from depending upon "something you know" (account number) and "something you know" (password), to the much more secure "something you know" (account number/password) and "something you own" (OTP device).

If all the banks moved to such a system then we could expect the incidence of password phishing for bank details to significantly decrease. Scammers could potentially harvest a single, short-lived token for an account, but would be unable to recover the physical device itself. The would significantly reduce the value of an account to an attacker.

It appears the bank hardly mentions this additional security mechanism to standard clients because they charge $99 for the device in question, and most clients are likely to complain and claim they can go to a different bank which doesn't need OTP technology for internet banking.

I'm comforted that banks are providing these facilities to their customers.

(read more...)

Course development

Course development
Work doesn't get much better than this. I'm listening to some superbly remixed tunes (thanks di.fm), drinking a hot cup of english breakfast tea, relaxing comfortably in my bedroom with a cute rabbit to keep me company while I prepare slides and play with Google's image search to find strange and interesting images.
(read more...)

Chickens

Chickens
We rotated some of our chickens this weekend. Two of the older chooks have gone to 'a nice farm' and we have four younger chooks to take their place. They're in the exciting colours of brown and white.
(read more...)

Pain

Pain
If you want a painful experience, then try requesting an Australian Business Number, Tax File Number, and other associated registrations using the on-line forms at the Australian Business Registry. The number of crashes, inconsistant validation, and other glitches meant that I had to make no less than three attempts to complete the forms. In no case did my 'saved' forms actually save. Urgh.

(read more...)

Bitcoin QR code This site is ad-free, and all text, style, and code may be re-used under a Creative Commons Attribution 3.0 license. If like what I do, please consider supporting me on Patreon, or donating via Bitcoin (1P9iGHMiQwRrnZuA6USp5PNSuJrEcH411f).