AVONDALE, Ariz. -
So confident is Sestus Data Co. President Taun Willis that its multi-factor authentication tool is the airtight answer that he is predicting the Phishcops solution will "dominate the market" by 2009.
Phishcops uses what it says is the nation's strongest authentication algorithm with a pass-key that cannot be transferred to unknown user devices, he said. Thus, even if a member freely divulges a user name and password, a criminal wouldn't be able to use it.
Unlike most existing Internet banking security tools-which are wearing thin under today's man-in-the-middle attacks and invisible malware-PhishCops doesn't rely on "mother's-maiden-name" challenge questions or familiar images, according to $314-million First Florida CU and $197-million Envision CU, which recently launched Phishcops.
"Originally, we had signed with another vendor that used challenge questions as an authentication factor," said Tim Brown, chief technology officer at First Florida in Jacksonville, Fla., which went live with PhishCops in April.
"But then we realized we didn't want to force our members to give out any personal information that could be phished in the future," Brown said.
In addition, PhishCops doesn't use hardware tokens-or software, for that matter.
Instead, Phishcops uses a mathematic key that, at first glance, may not seem so special. "The key factor isn't unique," Willis agreed. Indeed, many vendors place mathematic keys or software certificates on the member's computing device during enrollment as a first authentication factor. "But the nature of the key is unique," Willis continued.
The PhishCops key is created using the SHA-256 algorithm, the current authentication standard developed by the U.S. Department of Commerce. No other MFA product uses SHA-256, Willis said.
And each time the member logs on with user name and password, the platform generates a fresh key. "It's not just a static key, which is what a lot of our competitors offer," Willis explained. "If we generated a static key, we'd be at risk with malware, which can steal a static key and place it on anybody's machine."
After the credit union's website authenticates the new key, a second authentication factor delivers a virtual token to validate the website to the member. Upon each subsequent log-in, PhishCops also generates a new virtual token.
Both the PhishCops key and virtual token can only be validated from the member's computing device, not stolen and used from a thief's machine, Willis added.
Members can enroll additional computers after e-mail verification or can authenticate via a one-time token at public computers.
PhishCops stands up against current threats, said Shea Lambert, director of IT for United Solutions Company, the Tallahassee, Fla.-based CUSO that provides PhishCops.
"Other products can't protect your members from man-in-the-middle attacks and hostile proxies," asserted Lambert. "PhishCops can. Even with a stolen account number and password, a thief can't get into an account."
PhishCops is stirring up interest, Willis said. "The largest percentage of customers approaching us now are those who signed up with image-based solutions one year ago."
Giant management and technology consultancy BearingPoint, Inc., of McLean, Va., recently told Credit Union Journal it would switch to PhishCops.
more
Read more about strong authentication at cujournal.com and search the following bolded terms in the archive:
* Multi-Face Authentication for a story on Buckeye State CU's cognometric authentication tool, which relies on the idea that you never forget a face.
* MFA: Secure Enough? for a story on vulnerabilities in image- and challenge question-based tools.
* One CU Dials Up A Mature Technology To Deal With A Fresh Challenge for a story on how PSECU is using phone calls as an alternative to challenge questions.
for more on this story
* Envision CU, www.envisioncu.com; First Florida CU, www.firstflorida.org
* PhishCops, www.PhishCops.com; United Solutions Co., at www.unitedsolutions.coop











