06 July 2012

Consistency in Multi-Channel Access

All types of functionality should provide be as similar as possible across all delivery channels (e.g. phone, web e-commerce, mobile) and also when there are alternative versions for accessibility reasons (e.g. device constraints, user ability, environmental conditions). This is especially true for security controls where a weakness in one channel could undermine the security of all channels.

Two technicians working on a high-street standalone ATM which has the words 'Free cash Withdrawals' prominently displayed- the ATM's enclosure  is unlocked and open, and one of the technicians is leaning in to work on it while the other looks on

For example in authentication, either utilising passwords or some other method of validating identity such as certificates or one-time tokens, it must not be possible to bypass the controls altogether. Nor should it be possible to circumvent a security control in one channel, or mode, that is required in another. All channels should have an equal degree of protection.

This was recently highlighted in a description of how the well-used reCAPTCHA could be broken by a weakness in the alternative audio version. Many sites use the service to help prevent automated submissions of data such as for user registration, feedback, enquiries, and even limit higher-rate usage of a site.

The attack against the audio version, which output six spoken words and masked them with background noise from static-laden radio broadcasts backwards, relied on the finding that the background noise did not include high sound frequencies, and thus it was possible to extract the words for analysis. The attacker's clever analysis was made slightly easier in that they found reCAPTCHA accepted multiple spellings of the solutions for some phonetically-similar words, making the problem easier to solve. The issue has since been addressed.

So check those web sites, alternative versions, administrative interfaces, mobile apps and anything else that shares the same users.

Posted on: 06 July 2012 at 08:45 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Consistency in Multi-Channel Access
http://www.clerkendweller.com/2012/7/6/Consistency-in-MultiChannel-Access
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2012/7/6/Consistency-in-MultiChannel-Access
Requested by 107.22.25.119 on Wednesday, 19 June 2013 at 00:03 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2012-2013 clerkendweller.com