<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>bruce-schneier on S Anand</title>
    <link>https://www.s-anand.net/blog/tag/bruce-schneier/</link>
    <description>Recent content in bruce-schneier on S Anand</description>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 17 Mar 2005 12:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.s-anand.net/blog/tag/bruce-schneier/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Two Factor Authentication</title>
      <link>https://www.s-anand.net/blog/two-factor-authentication/</link>
      <pubDate>Thu, 17 Mar 2005 12:00:00 +0000</pubDate>
      <guid>https://www.s-anand.net/blog/two-factor-authentication/</guid>
      <description>&lt;p&gt;Bruce Schneier on &lt;a href=&#34;http://www.schneier.com/blog/archives/2005/03/the_failure_of.html&#34;&gt;The Failure of Two-Factor Authentication&lt;/a&gt;. &lt;a href=&#34;http://www.itsecurity.com/papers/rainbow2.htm&#34;&gt;Two factor authentication&lt;/a&gt; replaces passwords with two things: something you have (e.g. a security token that changes numbers every minute) and something you know (e.g. password). Bruce says this won&amp;rsquo;t help against two new kinds of attacks we&amp;rsquo;re seeing:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Man-in-the-Middle attack&lt;/strong&gt;. An attacker puts up a fake bank website and entices user to that website. User types in his password, and the attacker in turn uses it to access the bank&amp;rsquo;s real website. Done right, the user will never realize that he isn&amp;rsquo;t at the bank&amp;rsquo;s website. Then the attacker either disconnects the user and makes any fraudulent transactions he wants, or passes along the user&amp;rsquo;s banking transactions while making his own transactions at the same time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Trojan attack&lt;/strong&gt;. Attacker gets Trojan installed on user&amp;rsquo;s computer. When user logs into his bank&amp;rsquo;s website, the attacker piggybacks on that session via the Trojan to make any fraudulent transaction he wants.&lt;/p&gt;
&lt;/blockquote&gt;
</description>
    </item>
    <item>
      <title>Military history and network security</title>
      <link>https://www.s-anand.net/blog/military-history-and-network-security/</link>
      <pubDate>Tue, 16 Apr 2002 12:00:00 +0000</pubDate>
      <guid>https://www.s-anand.net/blog/military-history-and-network-security/</guid>
      <description>&lt;p&gt;What can &lt;a href=&#34;http://www.counterpane.com/crypto-gram-0104.html#1&#34;&gt;military history teach us about network security&lt;/a&gt;?&lt;/p&gt;
</description>
    </item>
    <item>
      <title>Knee-jerk reactions to Sep 11</title>
      <link>https://www.s-anand.net/blog/knee-jerk-reactions-to-sep-11/</link>
      <pubDate>Thu, 11 Oct 2001 12:00:00 +0000</pubDate>
      <guid>https://www.s-anand.net/blog/knee-jerk-reactions-to-sep-11/</guid>
      <description>&lt;p&gt;A good report on the &lt;a href=&#34;http://www.counterpane.com/crypto-gram-0109a.html&#34;&gt;knee-jerk reactions&lt;/a&gt; to the WTC attack.&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>
