What is the benefit of security images, like on bank website logins? -
several sites (i remember yahoo did too, when used yahoo account) such bank of america show sitekey or similar image user chooses after enter username, before enter password. ostensibly, ensures login page unique each user, , therefore phisher can't show static login page looks bank's site, what's stopping them hitting bank's site in background , forwarding image (or other security challenge) right user? i'll grant, makes phisher's job harder, doesn't seem valuable me. what's rationale behavior?
if single server keeps hitting site requesting images different userids (especially 1 users haven't logged in before), pretty suspicious, it's harder phisher hide.
Comments
Post a Comment