<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-17540721.post116578617658020395..comments</id><updated>2008-03-16T19:57:46.424+01:00</updated><category term='mobile networks'/><category term='Home Server'/><category term='Smart design'/><category term='wifi'/><category term='Google'/><category term='gadgets'/><category term='security'/><category term='technology trends'/><title type='text'>Comments on Headworx: Your personal pinpad</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://headworx.slupik.com/feeds/116578617658020395/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default'/><link rel='alternate' type='text/html' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html'/><author><name>Szymon Slupik</name><uri>https://profiles.google.com/115855762914475187374</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-cWsnG40GA2A/AAAAAAAAAAI/AAAAAAAAknM/Xu5MCugBpj0/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-17540721.post-4623674930821408675</id><published>2008-03-16T19:57:00.000+01:00</published><updated>2008-03-16T19:57:00.000+01:00</updated><title type='text'>"on screen pin keyboards would have to be randomiz...</title><content type='html'>"on screen pin keyboards would have to be randomized"&lt;BR/&gt;-&gt; they already are; many online banks are doing that&lt;BR/&gt;&lt;BR/&gt;"users are lazy they simply revert to pressing keys"&lt;BR/&gt;-&gt; you can easily prevent them from doing that, it is just a matter of the page design</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default/4623674930821408675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default/4623674930821408675'/><link rel='alternate' type='text/html' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html?showComment=1205693820000#c4623674930821408675' title=''/><author><name>Headworx</name><uri>http://www.blogger.com/profile/11659982647690284677</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://photos1.blogger.com/blogger/757/1693/1600/SzymonSlupik.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html' ref='tag:blogger.com,1999:blog-17540721.post-116578617658020395' source='http://www.blogger.com/feeds/17540721/posts/default/116578617658020395' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1280419423'/></entry><entry><id>tag:blogger.com,1999:blog-17540721.post-6517528675506442855</id><published>2008-03-16T19:09:00.000+01:00</published><updated>2008-03-16T19:09:00.000+01:00</updated><title type='text'>"u cannot solve problem on level that created it" ...</title><content type='html'>"u cannot solve problem on level that created it" (einstein:)&lt;BR/&gt;&lt;BR/&gt;hook the keyboard. hook the mouse. on screen pin keyboards would have to be randomized and then your into "behavioral science" ... users are lazy they simply revert to pressing keys&lt;BR/&gt;&lt;BR/&gt;there are 3 critical components 2authenticity here:&lt;BR/&gt;(1) destination&lt;BR/&gt;(2) source&lt;BR/&gt;(3) "presence"&lt;BR/&gt;&lt;BR/&gt;(2 + 3) = validating the "user rather than the browser" and ensuring that a person is present (rather than a bot)&lt;BR/&gt;&lt;BR/&gt;right now all attempts have focused on "left brain" and computational activity. the solution engages right (non linear emotional).&lt;BR/&gt;&lt;BR/&gt;ussd model proposed is closer however fails on (1) since pushed. any input has 2b "above band" (cellular) and "pushed" since only mobile origination cannot b faked.&lt;BR/&gt;&lt;BR/&gt;ak</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default/6517528675506442855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default/6517528675506442855'/><link rel='alternate' type='text/html' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html?showComment=1205690940000#c6517528675506442855' title=''/><author><name>starscriber</name><uri>http://www.blogger.com/profile/17063191739795105773</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html' ref='tag:blogger.com,1999:blog-17540721.post-116578617658020395' source='http://www.blogger.com/feeds/17540721/posts/default/116578617658020395' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1054065192'/></entry><entry><id>tag:blogger.com,1999:blog-17540721.post-6185948433224274204</id><published>2008-03-16T17:24:00.000+01:00</published><updated>2008-03-16T17:24:00.000+01:00</updated><title type='text'>You're right. But a simple trick with an on-screen...</title><content type='html'>You're right. But a simple trick with an on-screen keyboard (a keyboard displayed as a series of links on a web page) should do. Still OTP seems to be the only sensible way to use your online services on machines you do not trust...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default/6185948433224274204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default/6185948433224274204'/><link rel='alternate' type='text/html' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html?showComment=1205684640000#c6185948433224274204' title=''/><author><name>Headworx</name><uri>http://www.blogger.com/profile/11659982647690284677</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://photos1.blogger.com/blogger/757/1693/1600/SzymonSlupik.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html' ref='tag:blogger.com,1999:blog-17540721.post-116578617658020395' source='http://www.blogger.com/feeds/17540721/posts/default/116578617658020395' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1280419423'/></entry><entry><id>tag:blogger.com,1999:blog-17540721.post-7098154039473033451</id><published>2008-03-15T04:53:00.000+01:00</published><updated>2008-03-15T04:53:00.000+01:00</updated><title type='text'>hi:&lt;br&gt;&lt;br&gt;OTP via sms entered back thru PC keyboa...</title><content type='html'>hi:&lt;BR/&gt;&lt;BR/&gt;OTP via sms entered back thru PC keyboard simply "cat chasing tail". problem with PC is keyboard as u know is zero encryption on keypress. with key logger active entering the sms PIN on the PC simply captured in clear then changed on the fly and invalidating the real session while real PIN has already been submitted on parallel and now hijacked session.&lt;BR/&gt;&lt;BR/&gt;&lt;BR/&gt;ak</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default/7098154039473033451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17540721/116578617658020395/comments/default/7098154039473033451'/><link rel='alternate' type='text/html' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html?showComment=1205553180000#c7098154039473033451' title=''/><author><name>starscriber</name><uri>http://www.blogger.com/profile/17063191739795105773</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://headworx.slupik.com/2006/12/your-personal-pinpad.html' ref='tag:blogger.com,1999:blog-17540721.post-116578617658020395' source='http://www.blogger.com/feeds/17540721/posts/default/116578617658020395' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1054065192'/></entry></feed>
