Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
News
SHARE
Is online shopping ever secure?

by Danny Bradbury

Excerpt:

“Sending account credentials over an unprotected network is a bad idea, says Michael Owen, head of security management at security consultancy and penetration tester IRM. ‘I wouldn't recommend any system that mailed back passwords,’ he says. ‘You're assuming that you can trust all of the machines that it will pass through, and that the customer definitely has control of his email at the time you're sending it out’ …

“Even sending a link to a password reset page is insecure unless the page also asks the user a secret question when they arrive there. Only 14% of sites took that approach, Munro explained…

“Tom Kellermann, vice-president of security awareness at security firm Core Security Technologies, goes even further. ‘Passwords themselves are obsolete. It is shocking to me that the standard in e-commerce is pushing people towards stronger passwords,’ he says, arguing that they're notoriously difficult for consumers to manage securely. ‘We should be moving towards two-factor authentication’ …

“Such trust relationships often extend to a third-party web host looking after a company's e-commerce site, says Kellermann. ‘Those who host websites, portals and e-commerce engines are not being effectively tested and forced through contracts to remediate exploitable vulnerabilities before the enemy does,’ he warns.”


Source: The Guardian

View the full article

Related Content