Security management Toolkit
Story: PayPal fights fraud with password key fob
So a phishing site steals the first code...
... and then uses it to login immediately. In the meantime, it puts a "please wait" sign on the screen to keep the user busy for 30 seconds. And if the system forbids multiple simultaneous logins for the same key fob, does that mean that the fraudsters could login before the real owner and lock the real owner out of his/her own account instead?
Chris Rankin
Applications Development, UK
Member since: October 2006
Site Activity Rating:
This member is ranked #46 in our top 100
Full Talkback thread










