The trusty telephone is emerging as one of the key elements in new multifactor authentication schemes designed to protect online banking and other web-based financial transactions from rapidly evolving security threats.

Man-in-the-Browser attacks

One serious threat on the horizon is the man-in-the-browser (MITB) attack. In this example,

1. Alice requests transfer of $1,000 to Bob.

2. MITB alters transfer request to transfer $21,000 to Fred.

3. MITB submits fraudulent request to bank.

4. Bank requests confirmation of transfer of $21,000 to Fred.

5. MITB alters confirmation page to present user with original request.

6. Alice reviews the transaction details and confirms request.

7. Bank transfers $21,000 to Fred.

