<?xml version="1.0" encoding="iso-8859-1"?><!-- generator="b2evolution/1.10.2" -->
<rss version="0.92">
	<channel>
		<title>Security x.0</title>
					  <link>http://blog.cronto.com/index.php</link>
			  <description>A blog about usability of Internet security in everyday's activities from online banking to Internet shopping</description>
			  <language>en-UK</language>
			  <docs>http://backend.userland.com/rss092</docs>
			  			  <item>
			    <title>The year of Banking Trojan?</title>
			    <description>&lt;p&gt;&quot;Since the records began&quot;, here at Cronto we have been &lt;a href=&quot;http://blog.cronto.com/index.php?title=transaction_verification_can_protect_aga&quot;&gt;talking about AND working on addressing the Banking Trojans and Man-in-the-Browser&lt;/a&gt;. Back then, there were very few public real-world examples of successful attacks and 2FA (Two-Factor Authentication), especially in a form of showing a picture of your dog, was all the rage &lt;img src=&quot;http://blog.cronto.com/rsc/smilies/icon_smile.gif&quot; alt=&quot;&amp;#58;&amp;#41;&quot; class=&quot;middle&quot; /&gt;&lt;/p&gt;

&lt;p&gt;While we &lt;a href=&quot;http://blog.cronto.com/index.php?title=2fa_is_dead&quot;&gt;pronounced 2FA dead&lt;/a&gt; back in the beginning of 2008, it wasn't until Gartner's Avivah Litan, vice president and analyst, stated in December 2009:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&quot;These attacks have been successfully and repeatedly executed against many banks and their customers across the globe in 2009&quot; &amp;#8232;&amp;#8232;&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;publishing the &lt;a href=&quot;http://www.gartner.com/DisplayDocument?ref=clientFriendlyUrl&amp;amp;id=1245013&quot;&gt;report&lt;/a&gt; on shortcomings of 2FA methods to address Trojan-based attacks that the Man-in-the-Browser/Trojan has arrived &lt;img src=&quot;http://blog.cronto.com/rsc/smilies/icon_smile.gif&quot; alt=&quot;&amp;#58;&amp;#41;&quot; class=&quot;middle&quot; /&gt;.&lt;/p&gt;

&lt;p&gt;It's arrived and it's going mainstream judging from the &lt;a href=&quot;http://www.usatoday.com/tech/news/2010-07-29-online-banking-security_N.htm&quot;&gt;recent article by USA Today&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;First, they &lt;em&gt;[criminals]&lt;/em&gt; acquire valid account log-ons, often by purchasing them from specialist data thieves. Next, they quietly access accounts, making note of high cash balances and access to credit lines. They also familiarize themselves with the bank's protocols for authorizing the creation of new online accounts and approving cash transfers.&lt;/p&gt;

&lt;p&gt;They look for coding security holes &amp;#8212; and invariably find them in the Web browser, the tool banks rely on to run programs that serve as a virtual bank teller. But Internet Explorer, Firefox, Opera, Google Chrome and Apple Safari are designed to let users navigate the entire Internet; they weren't meant to execute secure financial transactions &lt;em&gt;[Sounds familiar? See &lt;a href=&quot;http://blog.cronto.com/index.php?title=most_insecure_banking_sales_terminal&amp;amp;more=1&amp;amp;c=1&amp;amp;tb=1&amp;amp;pb=1&quot;&gt;The most insecure banking/sales terminal&lt;/a&gt;&lt;/em&gt;]. Cyberrobbers craft banking Trojans that inject software code into the Web browser, letting the attacker take control of online banking sessions, alter what the account holder sees and make stealthy transactions.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;and talking about the solutions:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;Litan, the Gartner banking security analyst, says banks need to move away from technologies that rely on common Web browsers, which is where banking Trojans thrive. Handheld optical readers, a more advanced technology, are available from Gemalto and Cronto. These devices must be used to take a picture of a visual cryptogram &amp;#8212; a secure image produced by the bank &amp;#8212; as part of authorizing any cash transfers.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;It is absolutely great to see our technology - the Cronto visual cryptogram - mentioned in the article. A bit unfortunate that it only refers to the standalone hardware device - optical reader - whereas in fact our solution offers either a mobile app for your cellphone or a dedicated device. As we strongly believe in the power of choice when it comes to authentication solutions for banks and their customers, offering both options allows us to achieve the most optimal combination of usability, security and cost.&lt;/p&gt;

&lt;p&gt;Now that the Trojan problem has become mainstream, there will be another &quot;gold rush&quot; of vendors to address it. Also, as usual, there will be some smart solutions and many not so smart &lt;img src=&quot;http://blog.cronto.com/rsc/smilies/icon_smile.gif&quot; alt=&quot;&amp;#58;&amp;#41;&quot; class=&quot;middle&quot; /&gt; Yet, we believe the visual channel is the best way to provide full secure &quot;free-text&quot; transaction signing and as of today the Cronto visual cryptogram is the only mature solution designed specifically to requirements of the online banking security market.&lt;/p&gt;

&lt;p&gt;Want to see it in action? Watch this video, demonstrating the Cronto Blackberry mobile client app used for the visual transaction signing at &lt;a href=&quot;www.commerzbank.com&quot;&gt;Commerzbank AG&lt;/a&gt;, the second largest bank in Germany:&lt;/p&gt;

&lt;div align=center&gt;
&lt;!-- Start of Brightcove Player --&gt; &lt;div style=&quot;DISPLAY: none&quot;&gt;&lt;/div&gt;&lt;p&gt;&lt;!--By use of this code snippet, I agree to the Brightcove Publisher T and C found at &lt;a href=&quot;http://corp.brightcove.com/legal/terms_publisher.cfm&quot;&gt;http://corp.brightcove.com/legal/terms_publisher.cfm&lt;/a&gt;. --&gt; &lt;script language=JavaScript src=&quot;http://admin.brightcove.com/js/BrightcoveExperiences.js&quot; type=text/javascript&gt;&lt;/script&gt;  &lt;object class=BrightcoveExperience id=myExperience42608794001&gt;&lt;param NAME=&quot;bgcolor&quot; VALUE=&quot;#FFFFFF&quot;&gt;&lt;param NAME=&quot;width&quot; VALUE=&quot;486&quot;&gt;&lt;param NAME=&quot;height&quot; VALUE=&quot;412&quot;&gt;&lt;param NAME=&quot;playerID&quot; VALUE=&quot;1873832325&quot;&gt;&lt;param NAME=&quot;publisherID&quot; VALUE=&quot;1155188357&quot;&gt;&lt;param NAME=&quot;isVid&quot; VALUE=&quot;true&quot;&gt;&lt;param NAME=&quot;@videoPlayer&quot; VALUE=&quot;42608794001&quot;&gt;&lt;/param&gt;&lt;/param&gt;&lt;/param&gt;&lt;/param&gt;&lt;/param&gt;&lt;/param&gt;&lt;/param&gt;&lt;/object&gt;&lt;!-- End of Brightcove Player --&gt;&lt;br /&gt;
&lt;/div&gt;&lt;/p&gt;</description>
			    <link>http://blog.cronto.com/index.php?title=year_of_banking_trojan&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
			  </item>
			  			  <item>
			    <title>Facebook Makes you a Living Dead </title>
			    <description>&lt;p&gt;A lot is written on privacy implications of sharing your personal information with different web services. Concerns have been raised about the ownership of information users upload in &quot;the cloud&quot; and it's persistence.&lt;/p&gt;

&lt;p&gt;One &lt;a href=&quot;http://www.lightbluetouchpaper.org/2009/05/20/attack-of-the-zombie-photos/&quot;&gt;recent experiment&lt;/a&gt; demonstrated that once you have used an online service to share your photos it might be problematic to remove them even when you choose:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;My colleagues Jonathan Anderson, Andrew Lewis, Frank Stajano and I ran a small experiment on 16 social-networking, blogging, and photo-sharing web sites and found that most failed to remove image files from their photo servers after they were deleted from the main web site. It&amp;#8217;s often feared that once data is uploaded into &amp;#8220;the cloud,&amp;#8221; it&amp;#8217;s impossible to tell how many backup copies may exist and where, and this provides clear proof that content delivery networks are a major problem for data remanence.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;Well, maybe deleting a single photo is too small of an operation to expect the site to really make sure it's gone forever. Surely, one would hope that once you de-register your whole account, it will be gone for good?&lt;/p&gt;

&lt;p&gt;I have recently tried to close my Facebook account. According to Facebook's &lt;a href=&quot;http://www.facebook.com/policy.php?ref=pf&quot;&gt;privacy policy&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Individuals who wish to deactivate their Facebook account may do so on the My Account page. Removed information may persist in backup copies for a reasonable period of time but will not be generally available to members of Facebook.&lt;/p&gt;&lt;/blockquote&gt;

&lt;p&gt;OK, I understand purging backup copies is probably asking too much for a user. However, I was surprised to receive the following email after deactivating my account:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;You have deactivated your Facebook account. You can reactivate your account at any time by logging into Facebook using your old login email and password. You will be able to use the site like you used to.&lt;/p&gt;

&lt;p&gt;Thanks,&lt;br /&gt;
The Facebook Team&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Indeed, trying to click on the &quot;resurrect&quot; link I found myself back to my profile with all connections and personal information intact.&lt;/p&gt;

&lt;p&gt;OK, maybe having a &quot;grace&quot; period for users deactivating their accounts on the spur of the moment is a good feature. So I deactivated my account again and this time left it for almost a month. Yet, today I was able to successfully login to my surely-by-now-non-existent account and found all my connections and information intact as it was...&lt;/p&gt;

&lt;p&gt;Welcome to the Hotel California 2.0: &lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&quot;You can checkout any time you like, But you can never leave!&quot;&lt;/p&gt;
&lt;/blockquote&gt;</description>
			    <link>http://blog.cronto.com/index.php?title=facebook_makes_you_living_dead&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
			  </item>
			  			  <item>
			    <title>E-crime crowd-sourcing</title>
			    <description>&lt;p&gt;The increasing number of online banking attacks from phishing to trojans has been largely driven by a high &lt;em&gt;Return on Investement&lt;/em&gt; (ROI): buy a toolkit, rent a botnet and get access to a high numbers of compromised accounts. It is all about the Economy of Scale - a single piece of malware can infect millions of computers and attack hundreds of banks.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;http://blog.cronto.com/media/blogs/uos/e-crime_crowd-sourcing.gif&quot; alt=&quot;e-crime_crowd-sourcing&quot; title=&quot;e-crime_crowd-sourcing&quot; width=&quot;350&quot; height=&quot;353&quot; align=&quot;left&quot; /&gt; The malware technology has been rapidly evolving, yet it is a known fact that some tasks are still better done by humans than a machine. Resolving &lt;a href=&quot;http://en.wikipedia.org/wiki/Captcha&quot;&gt;CAPTCHAs&lt;/a&gt; is one of them, hence they are often used to circumvent automated mass scale attacks (e.g. blogs comments spam), hitting e-crime where it hurts - its ROI.&lt;/p&gt;

&lt;p&gt;Unfortunately, these measures are no longer effective &amp;ndash; E-crime crowd-sourcing has arrived! The screenshot on the left advertises &quot;&lt;em&gt;Easy money here!&lt;/em&gt;&quot; and offers a job of &quot;&lt;em&gt;re-typing text from pictures&lt;/em&gt;&quot;. Required skills: &quot;&lt;em&gt;knowledge of English letters&lt;/em&gt;&quot; and &quot;&lt;em&gt;medium proficiency in English keyboard layout&lt;/em&gt;&quot;. Paid for every correctly recognised picture, the site promises rates up to 3 dollars/hour with daily payouts.&lt;/p&gt;

&lt;p&gt;Wondered why would anyone need this? Have a look at this &lt;a href=&quot;http://blog.threatexpert.com/2008/12/how-to-defeat-koobface.html&quot;&gt;in-depth analysis of Koobface&lt;/a&gt; - the Facebook virus that needs to resolve CAPTCHAs in order to propagate itself. &lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;&quot;Every time Koobface runs into CAPTCHA protection at Facebook, it transfers that image to its command-and-control server. From there, the image is relayed to an army of CAPTCHA resolvers, who work day and night ready to pick up a new image from their profile, solve it, submit an answer, and get paid something like 0.5 cent for the answer.&quot;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://blog.threatexpert.com/2008/12/how-to-defeat-koobface.html&quot;&gt;ThreatExpert Blog&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Now, apply the same concept to the &lt;b&gt;Man-in-the-Browser&lt;/b&gt; attack on online banking and it becomes &lt;b&gt;Hu(Man)-in-the-Browser&lt;/b&gt; &amp;ndash; a real-time &lt;b&gt;Trojan+Human&lt;/b&gt; attack. These attacks, already seen in the wild, indicate a shift from the basic &quot;spray and pray&quot; approach to maximising the return value of each compromised account - a human can assess the account balance, overdraft limit, payments patterns (e.g. when does your salary arrive) in a matter of seconds allowing  then to choose the optimal amount and time for the attack.&lt;/p&gt;

&lt;p&gt;With the required technology infrastructure in place: &lt;em&gt;Compromised Computer &amp;ndash; Command &amp;amp; Control centre &amp;ndash; Human Operator&lt;/em&gt;, it is only a matter of time, before the &lt;a href=&quot;http://en.wikipedia.org/wiki/Gold_farming&quot;&gt;virtual gold digging sweatshops&lt;/a&gt; switch to a more lucrative revenue stream.&lt;/p&gt;

</description>
			    <link>http://blog.cronto.com/index.php?title=e_crime_crowd_sourcing&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
			  </item>
			  			  <item>
			    <title>Out of Band Authentication... rethought</title>
			    <description>&lt;p&gt;Since the beginning of the &lt;a href=&quot;http://blog.cronto.com/index.php?title=2fa_is_dead&quot;&gt;2FA&lt;/a&gt; &quot;hype&quot;, many have advocated that the most reliable way of authentication is when it's taken &lt;b&gt;Out of Band&lt;/b&gt;, meaning that authentication happens on a different channel to the one where the action requiring authentication is taking place.&lt;/p&gt;

&lt;p&gt;In the online banking world it means using a different channel to the Internet connection to customer's computer (&lt;a href=&quot;http://blog.cronto.com/index.php?title=most_insecure_banking_sales_terminal&quot;&gt;the most insecure banking terminal&lt;/a&gt;), generally achieved by providing additional authentication codes via SMS messages or phone calls. Overall, this is definitely a better idea than asking the user to e.g. manually re-enter transaction details into a separate device or having them to connect another device to the computer. The issue however is that of &lt;b&gt;cost&lt;/b&gt; and &lt;b&gt;availability&lt;/b&gt;...&lt;/p&gt;

&lt;p&gt;SMS has never been a &lt;i&gt;Quality Assured&lt;/i&gt; channel as it mostly works in &quot;&lt;i&gt;fire and forget&lt;/i&gt;&quot; mode, with delivery speed depending on many factors outside the sender's (bank's) control. The bank also has to maintain the current user phone number and have a secure procedure for changing it. Furthermore, the cost of an SMS is still relatively high. Assuming &lt;b&gt;1m&lt;/b&gt; online users with &lt;b&gt;10&lt;/b&gt; transaction per month, the bank will be sending &lt;b&gt;10m&lt;/b&gt; messages that, at the average SMS cost of &lt;b&gt;5 cents&lt;/b&gt;, will translate into &lt;b&gt;0.5m euro per month&lt;/b&gt; or &lt;b&gt;6m euro per year&lt;/b&gt; (or &lt;b&gt;6 euro per user per year&lt;/b&gt;).&lt;/p&gt;

&lt;p&gt;A phone call is a better option since it establishes a real-time independent connection with the user and has, in principal, unlimited bandwidth (subject to cost and usability). It does come at the price of a higher overhead in managing multiple user's phone numbers and the cost of the call varies depending on a particular implementation and user location (wouldn't want to use this method on a mobile phone during a holiday abroad where a missed call can cost 5 euro, thanks to hidden operator's charges!).&lt;/p&gt;

&lt;p&gt;The SMS/phone call Out of Band approach works as a relatively simple to roll-out &lt;b&gt;complimentary&lt;/b&gt; method of authentication suitable for &lt;b&gt;small size&lt;/b&gt; deployments. It &lt;b&gt;does not scale&lt;/b&gt;. When having just &lt;b&gt;0.1%&lt;/b&gt; failed/delayed delivery rate for the SMS would mean &lt;b&gt;1m failed transactions per month&lt;/b&gt; for a bank with &lt;b&gt;1m&lt;/b&gt; online customers &amp;ndash; this will have a significant impact both on &lt;b&gt;customer retention&lt;/b&gt; levels and the &lt;b&gt;support calls volume&lt;/b&gt; (and associated costs).&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.cronto.com&quot;&gt;&lt;img src=&quot;http://www.cronto.com/images/home_image_left.gif&quot; alt=&quot;visual transaction signing&quot; align=&quot;right&quot; border=&quot;0&quot;/&gt;&lt;/a&gt;If only there was a way of establishing an independent secure communications channel between the user and the bank that will have &lt;b&gt;high availability and no operational cost&lt;/b&gt; &lt;img src=&quot;http://blog.cronto.com/rsc/smilies/icon_smile.gif&quot; alt=&quot;&amp;#58;&amp;#41;&quot; class=&quot;middle&quot; /&gt;&lt;/p&gt;

&lt;p&gt;At &lt;a href=&quot;http://www.cronto.com&quot;&gt;Cronto&lt;/a&gt;, we believe the &lt;b&gt;visual channel&lt;/b&gt; meets these requirements. The bank can generate a special image &amp;ndash; e.g. the &lt;a href=&quot;http://www.cronto.com/visual_cryptogram.htm&quot;&gt;Cronto visual cryptogram&lt;/a&gt; &amp;ndash; that could be displayed in any browser just as any other image (&lt;i&gt;= no cost and availability issues&lt;/i&gt;) and the user can decode it using an independent device: a cameraphone or a standalone optical token, ensuring &lt;b&gt;channel separation&lt;/b&gt;.&lt;/p&gt;

&lt;p&gt;The use of visual channel is definitely gaining momentum; &lt;a href=&quot;http://www.cronto.com/commerzbank_cronto_launch_secure_online_banking_photoTAN.htm&quot;&gt;Cronto has recently launched the deployment with Commerzbank AG&lt;/a&gt;, a number of vendors are announcing optically capable devices, and academic researchers are designing cameraphone-based solutions:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;http://www.gemalto.com/php/pr_view.php?id=426&quot;&gt;Gemalto Unveils World&amp;#8217;s First Optical Reader for Online Banking that Fits in a Wallet&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;http://www.reiner-sct.com/index.php?option=content&amp;amp;task=view&amp;amp;id=162&quot;&gt;Die neue Messlatte im mobilen Onlinebanking: chipTAN comfort &lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;http://www.vasco.com/about/press/fullstory.html?press=634&quot;&gt;Digipass 835, VASCO&amp;#8217;s new card reader with optical interface&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;http://www-fs.informatik.uni-tuebingen.de/studdipl/Fotohandy-PIN/&quot;&gt;Fotohandy-PIN: Trojanersichere PIN- und TAN-Eingabe via Fotohandy&lt;/a&gt;&lt;/li&gt;

&lt;/ul&gt;

&lt;p&gt;This month &lt;a href=&quot;http://www.finextra.com&quot;&gt;Finextra&lt;/a&gt; has launched &lt;a href=&quot;http://www.finextra.com/fullstory.asp?id=19630&quot;&gt;the Innovation Showcase&lt;/a&gt; &amp;ndash; &quot;a new feature on Finextra.com highlighting the most innovative financial technology developments over the past 12 months&quot;. &lt;a href=&quot;http://www.cronto.com/cronto_recognised_financial_technology_innovator_by_finexra.htm&quot;&gt;Cronto&lt;/a&gt; is pleased to be named as one of &lt;a href=&quot;http://www.finextra.com/fullfeature.asp?id=1118&quot;&gt;the leading innovators in Authentication and Security&lt;/a&gt; category. &lt;br /&gt;
 &lt;br /&gt;
Using innovation to improve processes and focusing on retaining the customer is vital in the current economic environment, and the visual channel offers the optimal Out of Band-type solution for banks looking to reduce/prevent fraud damages in a cost-effective and scalable way, while delivering better customer experience.&lt;br /&gt;
 &lt;/p&gt;

&lt;p&gt; &lt;/p&gt;

</description>
			    <link>http://blog.cronto.com/index.php?title=out_of_band_authentication_rethought&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
			  </item>
			  			  <item>
			    <title>The most insecure banking/sales terminal</title>
			    <description>&lt;p&gt;Can you imagine an &lt;a href=&quot;http://www.youtube.com/watch?v=FAnmuRHYamc&quot;&gt;ATM running Windows&lt;/a&gt; XP Home Edition and being connected to the Internet or a Point of Sale &lt;a href=&quot;http://www.youtube.com/watch?v=wWTzkD9M0sU&quot;&gt;terminal running Tetris&lt;/a&gt;? &amp;ndash; Unlikely! Why then is allowing a customer to use any computer on the Internet to connect to the banking system, and transfer much more money than you can take out of a cash machine, a good idea? Why did arguably the most conservative organisations in the world &amp;ndash; the banks &amp;ndash; agree to lower their defenses so low that they practically invited the criminals in?&lt;/p&gt;

&lt;p&gt;The answer is simple &amp;ndash; the same reasons why even risk-averse investors were chasing after every Internet company in the late 90s  &amp;ndash; the attractiveness of the global scale and reduced costs of e-channels. &lt;/p&gt;

&lt;p&gt;Over the years, payments and savings have always been a subject of the most advanced protection:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Banknotes have watermarks and other security features to resist counterfeiting&lt;/li&gt;


  &lt;li&gt;Cheques require the account holder's signature&lt;/li&gt;


  &lt;li&gt;ATMs require both your card and your PIN, run secure software, and are physically tamper-resistant&lt;/li&gt;


  &lt;li&gt;Point of Sale terminals in your favourite supermarket are protected from tampering and use dedicated secure connections to the payment processing network&lt;/li&gt;


&lt;/ul&gt;


&lt;p&gt;These are all very sensible measures that work (to one degree or another) to protect customers' and banks' money.&lt;/p&gt;

&lt;p&gt;Today, however, there is a huge imbalance between the value of electronically accessible funds and their security. This is being very effectively exploited by criminals and the banks are looking for a solution. Personal computers are not tamper proof sales terminals, therefore it is unfeasible to rely on the customer to keep them 100% secure. No one can take away online banking but banks can deploy new security measures, and  solving this problem requires a new innovative approach that can equally address security, ease of use, and cost.&lt;/p&gt;

&lt;p&gt;At Cronto, we identified this imbalance years ago. We also correctly predicted that the only &lt;a href=&quot;http://blog.cronto.com/index.php?title=transaction_verification_can_protect_aga&quot;&gt;solution to address this problem is transaction authentication&lt;/a&gt; (where the customer confirms each banking instruction). We then developed an innovative visual transaction signing solution. Based on our unique &lt;a href=&quot;http://www.cronto.com/visual_cryptogram.htm&quot;&gt;Visual Cryptogram&lt;/a&gt;, the Cronto solution supports multiple end user options allowing the bank to choose what is right for their customers whilst maintaining consistency in their backend systems.&lt;/p&gt;</description>
			    <link>http://blog.cronto.com/index.php?title=most_insecure_banking_sales_terminal&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1</link>
			  </item>
			  	</channel>
</rss>
